A full, step-by-step GDPR compliance guide for your UK business website—what to do, why it matters, and how to avoid costly mistakes

Data protection isn’t just about ticking boxes—it’s about building trust and avoiding legal headaches. If your business website collects or processes any personal data from visitors, the UK GDPR applies and the stakes are high. This comprehensive, practical checklist walks you through every requirement, from cookies to consent forms, so you can protect your customers, your reputation, and your bottom line.
The General Data Protection Regulation (GDPR) has been enshrined in UK law as the UK GDPR since Brexit. It applies to any business—regardless of size—that collects, processes, or stores personal data of individuals in the UK. For small businesses, this means almost every website is affected, whether you run an online shop, a booking system, or even just a simple contact form.
Personal data is defined very broadly. It covers names, email addresses, IP addresses, cookies, and even indirect identifiers. If your website uses analytics, has a newsletter sign-up, or lets people contact you, you're almost certainly handling personal data. The Information Commissioner’s Office (ICO) is the UK’s data regulator, and it has the power to investigate and fine businesses that fall short.
GDPR compliance isn't just about avoiding fines (which can reach up to £17.5 million or 4% of annual turnover). It's also about demonstrating to customers and partners that you take their privacy seriously. In today's market, data trust is a business advantage—not just a legal requirement.
Most UK businesses processing personal data must pay a data protection fee to the ICO. Fees start at £40 per year for micro-businesses. Check https://ico.org.uk/for-organisations/data-protection-fee/self-assessment/ to see if you need to register.
Before you can comply, you need to know exactly what data your website collects. This includes both obvious forms (like contact or sign-up forms) and less visible data collection, such as cookies, embedded analytics, or social media plugins. Many small business owners are surprised by how much data their site gathers—especially if you use third-party tools like Google Analytics or Facebook Pixel.
Conduct a thorough audit by mapping out every data capture point. List all forms, newsletter subscriptions, e-commerce checkout fields, user registrations, and even live chat widgets. Don’t forget automatic data capture like server logs or security tools. For each point, note what data is collected, for what purpose, and how long it is kept.
You should also identify which third parties process data on your behalf. For example, if you use Mailchimp for email marketing, Stripe for payments, or a web host that logs visitor IPs, these are all data processors under the GDPR. You are responsible for ensuring their compliance too.
| Data Collection Point | Type of Data Collected | Purpose | Third Party Involved? |
|---|---|---|---|
| Contact Form | Name, Email | Customer Enquiry | No |
| Newsletter Signup | Marketing | Mailchimp | |
| E-commerce Checkout | Name, Address, Card Details | Order Fulfilment | Stripe |
| Google Analytics | IP Address, Browsing Data | Website Analytics | |
| Live Chat Widget | Name, Chat Transcript | Customer Support | Tidio |
Use your website as a visitor would. Fill in every form, click every button, and check your browser’s developer tools (Network tab) to see what requests are made and where data is sent. Review your website plugins and integrations for hidden data flows.
Every UK business website collecting personal data must have a privacy policy—or, more precisely, a privacy notice. This document must tell visitors what data you collect, why you collect it, how you use it, who you share it with, and the legal basis for processing. It’s not enough to copy and paste a generic template; your policy must reflect your actual data practices.
Your privacy notice should be written in clear, accessible language. Avoid jargon or legalese. The ICO expects privacy information to be concise and easy to understand, particularly if your site is likely to be used by children. You must also explain how users can exercise their rights under the GDPR (such as accessing, correcting, or deleting their data).
Don’t forget to update your privacy notice whenever your data practices change—say, if you add a new email marketing tool or start using a different analytics provider. Place a prominent link to your privacy policy in your website footer and on any page where you collect personal data.
| Privacy Policy Requirement | What to Include |
|---|---|
| What data you collect | List all personal data types (e.g., name, email, IP address) |
| Why you collect it | Explain the purpose—e.g., order fulfilment, marketing, analytics |
| Legal basis | Consent, contract, legal obligation, or legitimate interest (specify which) |
| Who you share it with | Identify all third-party processors and their locations |
| How long you keep data | State your retention periods for different data types |
| How to exercise rights | Explain how users can access, rectify, or erase their data |
Privacy templates from US providers often lack UK/EU legal references and required details. Your privacy notice must meet UK GDPR standards—otherwise you risk non-compliance.
If your website uses cookies or similar technologies (like pixels or local storage), UK law requires you to obtain informed consent before placing most types of cookies on a user’s device. This is covered by both the UK GDPR and the Privacy and Electronic Communications Regulations (PECR). Only cookies that are 'strictly necessary' for your website to function are exempt from this rule.
The ICO is increasingly strict about cookie compliance. You must display a cookie banner or pop-up on first visit, allowing visitors to accept or reject non-essential cookies. Consent must be granular (users can choose which types of cookies to accept), freely given, and as easy to withdraw as to give. Pre-ticked boxes or implied consent ('By using this site you agree...') are not valid.
You are also required to provide a detailed cookie policy, listing all cookies in use, their purposes, and how long they last. Many UK small businesses use tools like Cookiebot, OneTrust, or CookieYes to manage consent and maintain an up-to-date cookie declaration. Regularly audit your site—plugins and third-party scripts can add new cookies without your knowledge.
| Cookie Type | Consent Needed? | Example |
|---|---|---|
| Strictly necessary | No | Shopping basket, login session |
| Analytics | Yes | Google Analytics, Hotjar |
| Marketing/Advertising | Yes | Facebook Pixel, Google Ads |
| Preference | Yes | Language selection cookies |
In 2023, the ICO issued over 30 enforcement notices to UK companies for non-compliant cookie banners. Fines are increasing, and the regulator actively investigates complaints.
Every time you process personal data, you must have a lawful basis under the UK GDPR. The six legal bases are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. For most UK small business websites, the relevant bases are consent (e.g., for marketing emails and cookies), contract (e.g., fulfilling orders), and legitimate interests (e.g., basic analytics).
Consent must be explicit, specific, and documented. For example, if you have a newsletter sign-up, the user must actively opt in (unticked checkbox) and you must record their consent. For contracts, collecting customer details for order fulfilment is usually covered, but you can’t use this data for marketing unless you have separate consent.
Legitimate interest is a flexible basis, but you must conduct a Legitimate Interests Assessment (LIA). This involves weighing your business needs against the individual’s privacy rights. The ICO provides guidance and expects you to document your reasoning. Never rely on legitimate interests for high-risk or sensitive data without careful analysis.
Keep a record of the legal basis for each processing activity. This is a core GDPR requirement and will be requested if you’re ever audited.
Under the UK GDPR, individuals (known as data subjects) have the right to access, correct, erase, and restrict the processing of their personal data. Your website must make it easy for users to exercise these rights. This applies even to micro-businesses and sole traders—there are no exemptions for size.
Common rights requests include subject access requests (SARs), where a user asks to see all the data you hold about them, and deletion requests ('the right to be forgotten'). You are legally required to respond to these requests within one month, and you cannot charge a fee unless the request is manifestly unfounded or excessive.
Your privacy notice should explain how users can make a request—usually via email, a contact form, or a postal address. Internally, you must have a process for verifying identity, finding all relevant data (including in backups and third-party tools), and responding promptly. Keep records of requests and your responses for accountability.
| Right | What It Means | Your Obligation |
|---|---|---|
| Access | See all data you hold about them | Respond in 1 month; provide copy of data |
| Rectification | Correct inaccurate data | Update data and confirm to user |
| Erasure | Delete personal data | Remove data unless you have a legal reason to keep it |
| Restriction | Limit how data is used | Stop processing while a complaint is investigated |
| Objection | Object to processing (e.g. marketing) | Cease processing unless you have compelling grounds |
Failing to respond to a subject access or deletion request is a top reason for ICO complaints and can result in enforcement action—even for small businesses.
GDPR requires that you implement 'appropriate technical and organisational measures' to protect personal data. For business websites, this means both cyber-security and practical processes. Even if you’re not a tech expert, you’re expected to take reasonable precautions.
At a minimum, your website should use HTTPS (SSL/TLS encryption)—not just for e-commerce, but for all pages that collect or display personal information. Most browsers now mark non-HTTPS sites as ‘Not Secure’, which undermines trust. Also, keep your content management system (CMS), plugins, and server software up to date to patch security vulnerabilities.
Access to personal data (such as form submissions or order details) should be limited to authorised staff only. Use strong passwords, two-factor authentication (2FA), and restrict admin access where possible. Regularly review who has access—especially if you use freelancers or agencies.
| Security Measure | Why It’s Important | How to Implement |
|---|---|---|
| SSL/TLS (HTTPS) | Encrypts data in transit | Get a digital certificate from your host; force HTTPS site-wide |
| CMS Updates | Fixes known vulnerabilities | Apply updates as soon as released |
| User Access Control | Reduces risk of leaks | Set up unique logins; remove ex-staff promptly |
| Backups | Protect against loss or attack | Automate daily backups; encrypt if possible |
| Strong Passwords & 2FA | Prevents unauthorised access | Use a password manager; enable 2FA |
If you store personal data on paper (e.g., printed orders or sign-up sheets), lock it away securely—GDPR covers both digital and physical data.
If your website shares personal data with third parties (such as email marketing services, payment processors, CRM systems, or cloud storage), you must ensure they also comply with the UK GDPR. You are legally responsible for your processors’ actions—if they breach data protection rules, the ICO can hold you accountable.
You must have a written contract (often called a Data Processing Agreement, or DPA) with each processor. This agreement should set out how they handle your data, what security measures they use, and what happens if there’s a data breach. Most reputable UK and EU providers offer GDPR-compliant terms by default, but always check—many US-based services still fall short, especially post-Brexit.
Special care is needed if your data is transferred outside the UK or European Economic Area (EEA). You must ensure 'adequate safeguards' are in place—such as Standard Contractual Clauses (SCCs) or the UK’s International Data Transfer Agreement (IDTA). The ICO provides up-to-date guidance on international data transfers.
| Third Party | Type of Data | GDPR-Compliant? | Recommended Action |
|---|---|---|---|
| Mailchimp | Email, Name | Yes (EU servers available) | Sign DPA, review transfer safeguards |
| Stripe | Payment details | Yes | Use built-in GDPR features |
| Google Analytics | IP, browsing data | Partially | Use IP anonymisation, review privacy settings |
| US Hosting Provider | All site data | Varies | Check for SCCs or switch to UK/EU host |
| Live Chat Tool | Chat transcripts | Varies | Review DPA and data retention policy |
Post-Brexit, UK businesses must check both UK and EU rules for any data sent outside Europe. Transfers to the US are especially complex—get specialist advice if in doubt.
Even with the best precautions, data breaches can happen—whether it’s a lost laptop, a hacked website, or an email sent to the wrong address. Under the UK GDPR, you must notify the ICO within 72 hours of becoming aware of a personal data breach that poses a risk to individuals’ rights and freedoms. You may also have to inform affected individuals.
A breach isn’t just a cyber-attack. It includes any unauthorised access, loss, alteration, or destruction of personal data. For example, if your website’s database is compromised, or staff accidentally upload a customer list publicly, it counts as a breach. The ICO expects you to have a plan in place before anything goes wrong.
Your breach response plan should include how you detect and assess incidents, who is responsible for reporting, how you contain the situation, and what information you need to provide to the ICO. Keep a record of all breaches, even minor ones that don’t require notification. This demonstrates accountability and may protect you from harsher penalties.
You can report a breach to the ICO online at https://ico.org.uk/for-organisations/report-a-breach/. Have details ready about what happened, what data was affected, and your mitigation steps.
GDPR compliance isn’t a one-off project—it’s an ongoing responsibility. The ICO expects you to review your policies, data practices, and supplier contracts at least annually, or whenever you introduce new technologies or services. Document everything: audits, risk assessments, staff training, consents, and breach logs. This record-keeping is known as 'accountability' and is a core part of the UK GDPR.
For small businesses, practical steps include setting a calendar reminder to review your privacy notice, cookie policy, and data processing records each year. If you use freelancers, agencies, or new plugins, check their GDPR status before going live. If you change your website platform or hosting provider, revisit your data mapping and contracts.
The ICO offers self-assessment tools and checklists tailored for small businesses: https://ico.org.uk/for-organisations/sme-web-hub/. If you’re ever investigated, the ability to demonstrate your compliance efforts—showing you took data protection seriously—can make the difference between a warning and a fine.

Ready for the next step? Open a business bank account to keep your finances organised.

Get 7,500 free points (worth £75) on your first transaction. No annual fee. Instant decision.
Affiliate disclosure: we may earn a commission via our links. This does not affect our editorial independence.


Affiliate links. We may earn a commission. Editorial independence maintained.