The RoadmapSetupSetting Up a Website and Domain

GDPR Checklist for Your Business Website

A full, step-by-step GDPR compliance guide for your UK business website—what to do, why it matters, and how to avoid costly mistakes

11 minute read
Setup — Setting Up a Website and Domain
✓ Verified against GOV.UK
Claire Henderson
Written by Claire Henderson
Finance & Tax Editor · GuideToBusiness
Back to Setup

Data protection isn’t just about ticking boxes—it’s about building trust and avoiding legal headaches. If your business website collects or processes any personal data from visitors, the UK GDPR applies and the stakes are high. This comprehensive, practical checklist walks you through every requirement, from cookies to consent forms, so you can protect your customers, your reputation, and your bottom line.

Understanding GDPR: What It Means for Your Website

The General Data Protection Regulation (GDPR) has been enshrined in UK law as the UK GDPR since Brexit. It applies to any business—regardless of size—that collects, processes, or stores personal data of individuals in the UK. For small businesses, this means almost every website is affected, whether you run an online shop, a booking system, or even just a simple contact form.

Personal data is defined very broadly. It covers names, email addresses, IP addresses, cookies, and even indirect identifiers. If your website uses analytics, has a newsletter sign-up, or lets people contact you, you're almost certainly handling personal data. The Information Commissioner’s Office (ICO) is the UK’s data regulator, and it has the power to investigate and fine businesses that fall short.

GDPR compliance isn't just about avoiding fines (which can reach up to £17.5 million or 4% of annual turnover). It's also about demonstrating to customers and partners that you take their privacy seriously. In today's market, data trust is a business advantage—not just a legal requirement.

ICO Registration

Most UK businesses processing personal data must pay a data protection fee to the ICO. Fees start at £40 per year for micro-businesses. Check https://ico.org.uk/for-organisations/data-protection-fee/self-assessment/ to see if you need to register.

  • GDPR applies to almost all business websites collecting UK visitor data.
  • Personal data includes names, emails, cookies, IP addresses, and more.
  • The ICO enforces the rules and can issue substantial fines.
  • Being compliant builds trust with customers and partners.

Audit: What Data Does Your Website Collect and Why?

Before you can comply, you need to know exactly what data your website collects. This includes both obvious forms (like contact or sign-up forms) and less visible data collection, such as cookies, embedded analytics, or social media plugins. Many small business owners are surprised by how much data their site gathers—especially if you use third-party tools like Google Analytics or Facebook Pixel.

Conduct a thorough audit by mapping out every data capture point. List all forms, newsletter subscriptions, e-commerce checkout fields, user registrations, and even live chat widgets. Don’t forget automatic data capture like server logs or security tools. For each point, note what data is collected, for what purpose, and how long it is kept.

You should also identify which third parties process data on your behalf. For example, if you use Mailchimp for email marketing, Stripe for payments, or a web host that logs visitor IPs, these are all data processors under the GDPR. You are responsible for ensuring their compliance too.

Data Collection PointType of Data CollectedPurposeThird Party Involved?
Contact FormName, EmailCustomer EnquiryNo
Newsletter SignupEmailMarketingMailchimp
E-commerce CheckoutName, Address, Card DetailsOrder FulfilmentStripe
Google AnalyticsIP Address, Browsing DataWebsite AnalyticsGoogle
Live Chat WidgetName, Chat TranscriptCustomer SupportTidio
How to Audit Your Site

Use your website as a visitor would. Fill in every form, click every button, and check your browser’s developer tools (Network tab) to see what requests are made and where data is sent. Review your website plugins and integrations for hidden data flows.

  • List every form and data collection method.
  • Check your analytics and marketing tools.
  • Identify all third-party processors.
  • Document your findings for future reference.

Privacy Policy: Drafting a Clear, Compliant Statement

Every UK business website collecting personal data must have a privacy policy—or, more precisely, a privacy notice. This document must tell visitors what data you collect, why you collect it, how you use it, who you share it with, and the legal basis for processing. It’s not enough to copy and paste a generic template; your policy must reflect your actual data practices.

Your privacy notice should be written in clear, accessible language. Avoid jargon or legalese. The ICO expects privacy information to be concise and easy to understand, particularly if your site is likely to be used by children. You must also explain how users can exercise their rights under the GDPR (such as accessing, correcting, or deleting their data).

Don’t forget to update your privacy notice whenever your data practices change—say, if you add a new email marketing tool or start using a different analytics provider. Place a prominent link to your privacy policy in your website footer and on any page where you collect personal data.

Privacy Policy RequirementWhat to Include
What data you collectList all personal data types (e.g., name, email, IP address)
Why you collect itExplain the purpose—e.g., order fulfilment, marketing, analytics
Legal basisConsent, contract, legal obligation, or legitimate interest (specify which)
Who you share it withIdentify all third-party processors and their locations
How long you keep dataState your retention periods for different data types
How to exercise rightsExplain how users can access, rectify, or erase their data
Don't Use a US-Only Template

Privacy templates from US providers often lack UK/EU legal references and required details. Your privacy notice must meet UK GDPR standards—otherwise you risk non-compliance.

  • Describe all data collection activities honestly.
  • State your legal basis for each processing purpose.
  • List all third parties who receive personal data.
  • Explain users’ rights clearly and accessibly.
  • Keep your policy up to date and easy to find.

Cookie Consent: Getting It Right Under UK Law

If your website uses cookies or similar technologies (like pixels or local storage), UK law requires you to obtain informed consent before placing most types of cookies on a user’s device. This is covered by both the UK GDPR and the Privacy and Electronic Communications Regulations (PECR). Only cookies that are 'strictly necessary' for your website to function are exempt from this rule.

The ICO is increasingly strict about cookie compliance. You must display a cookie banner or pop-up on first visit, allowing visitors to accept or reject non-essential cookies. Consent must be granular (users can choose which types of cookies to accept), freely given, and as easy to withdraw as to give. Pre-ticked boxes or implied consent ('By using this site you agree...') are not valid.

You are also required to provide a detailed cookie policy, listing all cookies in use, their purposes, and how long they last. Many UK small businesses use tools like Cookiebot, OneTrust, or CookieYes to manage consent and maintain an up-to-date cookie declaration. Regularly audit your site—plugins and third-party scripts can add new cookies without your knowledge.

Cookie TypeConsent Needed?Example
Strictly necessaryNoShopping basket, login session
AnalyticsYesGoogle Analytics, Hotjar
Marketing/AdvertisingYesFacebook Pixel, Google Ads
PreferenceYesLanguage selection cookies
ICO Enforcement

In 2023, the ICO issued over 30 enforcement notices to UK companies for non-compliant cookie banners. Fines are increasing, and the regulator actively investigates complaints.

  • Show a clear cookie banner before any non-essential cookies are set.
  • Let users reject as well as accept cookies—no pre-ticked boxes.
  • Keep a record of user consent for at least 6 months.
  • List all cookies and their purposes in your cookie policy.
  • Regularly review your site for new or changed cookies.

Legal Bases for Processing: Consent, Contracts, and Legitimate Interests

Every time you process personal data, you must have a lawful basis under the UK GDPR. The six legal bases are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. For most UK small business websites, the relevant bases are consent (e.g., for marketing emails and cookies), contract (e.g., fulfilling orders), and legitimate interests (e.g., basic analytics).

Consent must be explicit, specific, and documented. For example, if you have a newsletter sign-up, the user must actively opt in (unticked checkbox) and you must record their consent. For contracts, collecting customer details for order fulfilment is usually covered, but you can’t use this data for marketing unless you have separate consent.

Legitimate interest is a flexible basis, but you must conduct a Legitimate Interests Assessment (LIA). This involves weighing your business needs against the individual’s privacy rights. The ICO provides guidance and expects you to document your reasoning. Never rely on legitimate interests for high-risk or sensitive data without careful analysis.

Document Your Legal Bases

Keep a record of the legal basis for each processing activity. This is a core GDPR requirement and will be requested if you’re ever audited.

  • Use consent for marketing, cookies, and optional features.
  • Use contract for sales, bookings, or service provision.
  • Use legitimate interests for analytics or basic site security.
  • Don’t bundle consent—get separate opt-ins for different purposes.

Data Subject Rights: Enabling Access, Correction, and Deletion

Under the UK GDPR, individuals (known as data subjects) have the right to access, correct, erase, and restrict the processing of their personal data. Your website must make it easy for users to exercise these rights. This applies even to micro-businesses and sole traders—there are no exemptions for size.

Common rights requests include subject access requests (SARs), where a user asks to see all the data you hold about them, and deletion requests ('the right to be forgotten'). You are legally required to respond to these requests within one month, and you cannot charge a fee unless the request is manifestly unfounded or excessive.

Your privacy notice should explain how users can make a request—usually via email, a contact form, or a postal address. Internally, you must have a process for verifying identity, finding all relevant data (including in backups and third-party tools), and responding promptly. Keep records of requests and your responses for accountability.

RightWhat It MeansYour Obligation
AccessSee all data you hold about themRespond in 1 month; provide copy of data
RectificationCorrect inaccurate dataUpdate data and confirm to user
ErasureDelete personal dataRemove data unless you have a legal reason to keep it
RestrictionLimit how data is usedStop processing while a complaint is investigated
ObjectionObject to processing (e.g. marketing)Cease processing unless you have compelling grounds
Don't Ignore Rights Requests

Failing to respond to a subject access or deletion request is a top reason for ICO complaints and can result in enforcement action—even for small businesses.

  • Provide a clear contact method for rights requests.
  • Verify the requester’s identity before sharing data.
  • Keep a log of all requests and your responses.
  • Respond within one month, even if you need more time.
  • Train staff or contractors on how to handle requests.

Data Security: Protecting Personal Data Collected Online

GDPR requires that you implement 'appropriate technical and organisational measures' to protect personal data. For business websites, this means both cyber-security and practical processes. Even if you’re not a tech expert, you’re expected to take reasonable precautions.

At a minimum, your website should use HTTPS (SSL/TLS encryption)—not just for e-commerce, but for all pages that collect or display personal information. Most browsers now mark non-HTTPS sites as ‘Not Secure’, which undermines trust. Also, keep your content management system (CMS), plugins, and server software up to date to patch security vulnerabilities.

Access to personal data (such as form submissions or order details) should be limited to authorised staff only. Use strong passwords, two-factor authentication (2FA), and restrict admin access where possible. Regularly review who has access—especially if you use freelancers or agencies.

Security MeasureWhy It’s ImportantHow to Implement
SSL/TLS (HTTPS)Encrypts data in transitGet a digital certificate from your host; force HTTPS site-wide
CMS UpdatesFixes known vulnerabilitiesApply updates as soon as released
User Access ControlReduces risk of leaksSet up unique logins; remove ex-staff promptly
BackupsProtect against loss or attackAutomate daily backups; encrypt if possible
Strong Passwords & 2FAPrevents unauthorised accessUse a password manager; enable 2FA
Don’t Forget Physical Security

If you store personal data on paper (e.g., printed orders or sign-up sheets), lock it away securely—GDPR covers both digital and physical data.

  • Use HTTPS for your entire site, not just checkout pages.
  • Update all plugins, themes, and scripts regularly.
  • Limit staff access to only what they need.
  • Enable 2FA for admin accounts.
  • Back up data securely and test your backups.

Third Parties: Ensuring Your Processors Are GDPR-Compliant

If your website shares personal data with third parties (such as email marketing services, payment processors, CRM systems, or cloud storage), you must ensure they also comply with the UK GDPR. You are legally responsible for your processors’ actions—if they breach data protection rules, the ICO can hold you accountable.

You must have a written contract (often called a Data Processing Agreement, or DPA) with each processor. This agreement should set out how they handle your data, what security measures they use, and what happens if there’s a data breach. Most reputable UK and EU providers offer GDPR-compliant terms by default, but always check—many US-based services still fall short, especially post-Brexit.

Special care is needed if your data is transferred outside the UK or European Economic Area (EEA). You must ensure 'adequate safeguards' are in place—such as Standard Contractual Clauses (SCCs) or the UK’s International Data Transfer Agreement (IDTA). The ICO provides up-to-date guidance on international data transfers.

Third PartyType of DataGDPR-Compliant?Recommended Action
MailchimpEmail, NameYes (EU servers available)Sign DPA, review transfer safeguards
StripePayment detailsYesUse built-in GDPR features
Google AnalyticsIP, browsing dataPartiallyUse IP anonymisation, review privacy settings
US Hosting ProviderAll site dataVariesCheck for SCCs or switch to UK/EU host
Live Chat ToolChat transcriptsVariesReview DPA and data retention policy
High-Risk: International Transfers

Post-Brexit, UK businesses must check both UK and EU rules for any data sent outside Europe. Transfers to the US are especially complex—get specialist advice if in doubt.

  • List all third-party services with access to your website data.
  • Sign a DPA with each processor—don’t just rely on their word.
  • Check where data is stored and if transfers are covered by safeguards.
  • Audit your suppliers annually for ongoing compliance.
  • Switch providers if you can’t get GDPR assurances.

Data Breaches: Preparing for and Responding to Incidents

Even with the best precautions, data breaches can happen—whether it’s a lost laptop, a hacked website, or an email sent to the wrong address. Under the UK GDPR, you must notify the ICO within 72 hours of becoming aware of a personal data breach that poses a risk to individuals’ rights and freedoms. You may also have to inform affected individuals.

A breach isn’t just a cyber-attack. It includes any unauthorised access, loss, alteration, or destruction of personal data. For example, if your website’s database is compromised, or staff accidentally upload a customer list publicly, it counts as a breach. The ICO expects you to have a plan in place before anything goes wrong.

Your breach response plan should include how you detect and assess incidents, who is responsible for reporting, how you contain the situation, and what information you need to provide to the ICO. Keep a record of all breaches, even minor ones that don’t require notification. This demonstrates accountability and may protect you from harsher penalties.

Responding to a GDPR Data Breach Effectively

1
1. Detect and Identify the Breach
Monitor your site and systems for suspicious activity or alerts. Train staff to recognise signs of a breach—such as unexpected access, missing data, or error messages.
2
2. Contain the Breach
Take immediate steps to limit damage—disable compromised accounts, restore from backups, remove unauthorised files, or take your site offline if needed.
3
3. Assess the Impact
Determine what data was affected, how many people are involved, and whether there is a risk to their rights (e.g., risk of fraud, identity theft, or harm).
4
4. Notify the ICO (if required)
If the breach poses a risk, report it to the ICO within 72 hours using their online form. Include details of what happened, impact, and what you’re doing about it.
5
5. Inform Affected Individuals (if required)
If there is a high risk to individuals, inform them directly—explain what happened, what you’re doing, and how they can protect themselves.
6
6. Document Everything
Keep a detailed log of the breach, your response, communications, and any lessons learned. This is vital for ICO investigations and future prevention.
ICO Data Breach Reporting Tool

You can report a breach to the ICO online at https://ico.org.uk/for-organisations/report-a-breach/. Have details ready about what happened, what data was affected, and your mitigation steps.

  • Have an incident response plan and train staff.
  • Detect breaches early—use monitoring and alerts.
  • Record every breach, even if not reportable.
  • Report serious breaches within 72 hours.
  • Communicate clearly and honestly with affected users.

Maintaining and Demonstrating GDPR Compliance

GDPR compliance isn’t a one-off project—it’s an ongoing responsibility. The ICO expects you to review your policies, data practices, and supplier contracts at least annually, or whenever you introduce new technologies or services. Document everything: audits, risk assessments, staff training, consents, and breach logs. This record-keeping is known as 'accountability' and is a core part of the UK GDPR.

For small businesses, practical steps include setting a calendar reminder to review your privacy notice, cookie policy, and data processing records each year. If you use freelancers, agencies, or new plugins, check their GDPR status before going live. If you change your website platform or hosting provider, revisit your data mapping and contracts.

The ICO offers self-assessment tools and checklists tailored for small businesses: https://ico.org.uk/for-organisations/sme-web-hub/. If you’re ever investigated, the ability to demonstrate your compliance efforts—showing you took data protection seriously—can make the difference between a warning and a fine.

  • Schedule annual reviews of all data protection policies.
  • Log all consents, breaches, and data processing activities.
  • Train all staff and contractors on GDPR basics.
  • Stay updated on changes to ICO guidance and case law.
  • Prepare for spot checks or audits—good records are your best defence.
Key Takeaways
  • GDPR applies to almost every UK business website. If you collect or process any personal data, the law covers you—no matter your size.
  • Map and document all personal data flows. Regularly audit what data you collect, from where, and why, including all third-party tools.
  • Draft a clear, specific privacy notice. Your privacy policy must reflect your real practices, not just generic templates.
  • Cookie consent must be informed and granular. Use a proper banner, allow users to reject cookies, and keep your policy up to date.
  • Choose the right lawful basis for every activity. Don’t use consent as a catch-all—document your reasoning for each process.
  • Enable and respond to data subject rights. Make it easy for users to access, correct, or erase their data, and log all requests.
  • Secure all personal data—digital and physical. Use encryption, strong access controls, and keep your systems updated.
  • Vet and contract with all third-party processors. You’re responsible for their compliance, especially for data sent outside the UK.
  • Have a breach response plan and act fast. Detect, contain, and report serious breaches within 72 hours; keep full records.
  • Maintain records and accountability. Regular reviews, documented policies, and staff training are essential for ongoing compliance.
⭐ Exclusive Partner Offers
Tide
Tide Business Account

Ready for the next step? Open a business bank account to keep your finances organised.

Code: REFER200
Claim £200 Free
Capital on Tap
Capital on Tap Card

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.

Code: SETTINGUP
Claim 7,500 Points

Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.