Privacy policies, cookies and GDPR: what your website needs
If your website has a contact form, a newsletter sign-up, analytics or an online shop, it handles personal data — which means data protection rules apply. It sounds daunting, but for most small businesses the essentials are straightforward.
The rules in a nutshell
Two sets of rules matter most for UK websites:
- UK GDPR and the Data Protection Act 2018 — how you collect, use, store and protect people’s personal information.
- PECR (the Privacy and Electronic Communications Regulations) — the rules on cookies and on marketing emails and texts.
“Personal data” means anything that can identify someone: a name, email address, phone number, IP address and so on.
1. You need a privacy policy
If you collect any personal data through your website — even just a contact form — you should have a clear privacy notice. In plain language it should explain:
- Who you are and how to contact you
- What information you collect and why
- The legal reason (the “lawful basis”) for using it
- Who you share it with — for example your email provider or payment processor
- How long you keep it
- People’s rights, including accessing or deleting their data, and how to complain to the ICO
Link to it from your website footer and next to any form. Avoid copying someone else’s policy word for word — it needs to describe what you actually do. The ICO publishes guidance and templates to help.
2. Cookies and consent
Cookies are small files websites store in visitors’ browsers. The key distinction is:
- Strictly necessary cookies — needed for the site to work, like a shopping basket or a login — don’t need consent.
- Non-essential cookies — such as advertising, tracking pixels and many analytics tools — generally need the visitor’s consent before they’re set.
Where consent is needed, it has to be a genuine choice: “Reject” should be as easy as “Accept”, and boxes shouldn’t be pre-ticked. The rules around low-risk analytics have been loosened somewhat recently, so check the ICO’s current guidance for your setup.
3. Contact forms and marketing emails
- Only ask for the information you actually need.
- Don’t automatically add people who contact you to a mailing list.
- If you want to send marketing emails, use a clear, unticked opt-in and include an unsubscribe link in every email.
- Protect forms from spam and make sure submissions are sent securely.
4. Keep data secure
You’re expected to take sensible steps to protect the data you hold. For a website, that means:
- HTTPS everywhere — the padlock in the browser bar.
- Keeping software updated, especially plugins and themes on platforms like WordPress.
- Strong, unique passwords and two-factor authentication on your website, hosting, domain and email accounts.
- Regular backups stored somewhere separate.
- Not keeping data longer than you need it — clear out old form submissions.
5. The ICO data protection fee
Most organisations that process personal data need to pay a small annual data protection fee to the ICO, though some are exempt. The ICO website has a quick self-assessment that tells you whether you need to pay.
Quick checklist
- A clear, accurate privacy policy linked in your footer and by forms
- Only essential cookies — or proper consent for the rest
- Forms that collect the minimum and don’t auto-subscribe people
- HTTPS, updates, strong passwords, 2FA and backups in place
- ICO fee checked and paid if required
Every Solent Web site is built with privacy in mind: HTTPS, secure forms, minimal cookies and guidance on your privacy policy. If you’d like your current site checked, get in touch.

