Guide

Website GDPR & privacy compliance basics

If your website collects any personal data — even just a contact form or website analytics — privacy law applies to you. Here are the basics every small business should get right, in plain English.

⚠ Two placeholders to fix before publishing: (1) the author byline and dates here and in the schema; (2) confirm this reflects your actual practices. This guide is general information, not legal advice.
In short: publish a clear privacy policy, get consent before loading non-essential cookies or trackers, collect only the data you need, keep it secure, and be ready to honour people's requests about their data.

Does privacy law even apply to me?

Very often, yes — and it's based on whose data you handle, not just where you're based. The UK and EU GDPR can apply if you offer goods or services to, or track, people in those regions, regardless of your own location. In the US, laws like California's CCPA/CPRA work similarly for residents there. In practice, if members of the public can reach your site and you collect anything about them, assume you have obligations.

The gaps we see most often

Across small-business websites, the same privacy issues come up again and again:

The essentials to get right

1. Publish a clear privacy policy

Tell people, in plain language, what you collect, why, who you share it with, how long you keep it, and how they can contact you or exercise their rights. Keep it accurate as your site changes.

2. Handle cookies and tracking properly

Strictly necessary cookies are fine, but non-essential ones — analytics, advertising, embedded media — generally need consent from UK/EU visitors before they load. One clean option is privacy-friendly, cookieless analytics, which can remove the need for a banner entirely.

3. Minimise what you collect

The safest data is the data you never collect. Only ask for what you genuinely need, and delete it when you no longer do.

4. Secure the data you hold

A privacy programme is only as strong as your security. HTTPS, access controls and good hosting hygiene all protect the personal data your site handles.

5. Be ready for data requests

People can ask what data you hold and, in many cases, to correct or delete it. Have a simple process and a contact address ready.

This guide is general information to help you ask the right questions — it isn't legal advice. For your specific obligations, check your regulator's guidance (for example the ICO in the UK) or a qualified professional.

People also ask

Does my small business website need a privacy policy?

Almost always yes. If your site collects any personal data — even a contact form or analytics — laws like the UK/EU GDPR and the CCPA generally require a privacy policy explaining what you collect and why.

Do I need a cookie consent banner?

If you use non-essential cookies or trackers and have UK/EU visitors, you generally need consent before they load. Strictly necessary cookies don't. Cookieless analytics can avoid a banner altogether.

Does GDPR apply if I'm not in the EU?

It can. GDPR applies based on whose data you process — if you offer services to or monitor people in the UK or EU, it can apply wherever you're based.

What is a website privacy audit?

A review of how your site collects and handles personal data — cookies, tracking, forms, third-party sharing and your privacy policy — to flag gaps that create legal or trust risk.

Want your privacy gaps flagged for you?

Our audit includes a plain-English privacy & GDPR risk check alongside the security review.

Get my security audit · $300