If your website collects any personal data — even just a contact form or website analytics — privacy law applies to you. Here are the basics every small business should get right, in plain English.
Does privacy law even apply to me?
Very often, yes — and it's based on whose data you handle, not just where you're based. The UK and EU GDPR can apply if you offer goods or services to, or track, people in those regions, regardless of your own location. In the US, laws like California's CCPA/CPRA work similarly for residents there. In practice, if members of the public can reach your site and you collect anything about them, assume you have obligations.
The gaps we see most often
Across small-business websites, the same privacy issues come up again and again:
- No privacy policy, or one that doesn't match what the site actually does.
- Analytics and marketing scripts that load before consent, dropping tracking cookies the moment a page opens.
- Forms that collect more than they need, with no explanation of why or how long data is kept.
- Personal data sent to third parties (email tools, ad platforms) without disclosure.
- Insecure handling — data sent or stored without proper protection, which is where privacy meets our security checklist.
The essentials to get right
1. Publish a clear privacy policy
Tell people, in plain language, what you collect, why, who you share it with, how long you keep it, and how they can contact you or exercise their rights. Keep it accurate as your site changes.
2. Handle cookies and tracking properly
Strictly necessary cookies are fine, but non-essential ones — analytics, advertising, embedded media — generally need consent from UK/EU visitors before they load. One clean option is privacy-friendly, cookieless analytics, which can remove the need for a banner entirely.
3. Minimise what you collect
The safest data is the data you never collect. Only ask for what you genuinely need, and delete it when you no longer do.
4. Secure the data you hold
A privacy programme is only as strong as your security. HTTPS, access controls and good hosting hygiene all protect the personal data your site handles.
5. Be ready for data requests
People can ask what data you hold and, in many cases, to correct or delete it. Have a simple process and a contact address ready.
People also ask
Does my small business website need a privacy policy?
Almost always yes. If your site collects any personal data — even a contact form or analytics — laws like the UK/EU GDPR and the CCPA generally require a privacy policy explaining what you collect and why.
Do I need a cookie consent banner?
If you use non-essential cookies or trackers and have UK/EU visitors, you generally need consent before they load. Strictly necessary cookies don't. Cookieless analytics can avoid a banner altogether.
Does GDPR apply if I'm not in the EU?
It can. GDPR applies based on whose data you process — if you offer services to or monitor people in the UK or EU, it can apply wherever you're based.
What is a website privacy audit?
A review of how your site collects and handles personal data — cookies, tracking, forms, third-party sharing and your privacy policy — to flag gaps that create legal or trust risk.
Want your privacy gaps flagged for you?
Our audit includes a plain-English privacy & GDPR risk check alongside the security review.
Get my security audit · $300