Start a project
Southampton, UK--:--:--
Blog/Technical

Privacy policies, cookies and GDPR: what your website needs

If your website has a contact form, a newsletter sign-up, analytics or an online shop, it handles personal data — which means data protection rules apply. It sounds daunting, but for most small businesses the essentials are straightforward.

Please noteThis is a general, plain-English overview to help you ask the right questions — not legal advice. The UK regulator, the Information Commissioner's Office (ICO), has excellent free guidance for small businesses, and rules do change over time.

The rules in a nutshell

Two sets of rules matter most for UK websites:

  • UK GDPR and the Data Protection Act 2018 — how you collect, use, store and protect people’s personal information.
  • PECR (the Privacy and Electronic Communications Regulations) — the rules on cookies and on marketing emails and texts.

“Personal data” means anything that can identify someone: a name, email address, phone number, IP address and so on.

1. You need a privacy policy

If you collect any personal data through your website — even just a contact form — you should have a clear privacy notice. In plain language it should explain:

  • Who you are and how to contact you
  • What information you collect and why
  • The legal reason (the “lawful basis”) for using it
  • Who you share it with — for example your email provider or payment processor
  • How long you keep it
  • People’s rights, including accessing or deleting their data, and how to complain to the ICO

Link to it from your website footer and next to any form. Avoid copying someone else’s policy word for word — it needs to describe what you actually do. The ICO publishes guidance and templates to help.

Cookies are small files websites store in visitors’ browsers. The key distinction is:

  • Strictly necessary cookies — needed for the site to work, like a shopping basket or a login — don’t need consent.
  • Non-essential cookies — such as advertising, tracking pixels and many analytics tools — generally need the visitor’s consent before they’re set.

Where consent is needed, it has to be a genuine choice: “Reject” should be as easy as “Accept”, and boxes shouldn’t be pre-ticked. The rules around low-risk analytics have been loosened somewhat recently, so check the ICO’s current guidance for your setup.

The simplest optionUse fewer cookies. Privacy-friendly, cookie-free analytics tools can tell you how many visitors you get without tracking individuals — which often means you can avoid a cookie banner altogether. This is the approach Solent Web recommends where it fits.

3. Contact forms and marketing emails

  • Only ask for the information you actually need.
  • Don’t automatically add people who contact you to a mailing list.
  • If you want to send marketing emails, use a clear, unticked opt-in and include an unsubscribe link in every email.
  • Protect forms from spam and make sure submissions are sent securely.

4. Keep data secure

You’re expected to take sensible steps to protect the data you hold. For a website, that means:

  • HTTPS everywhere — the padlock in the browser bar.
  • Keeping software updated, especially plugins and themes on platforms like WordPress.
  • Strong, unique passwords and two-factor authentication on your website, hosting, domain and email accounts.
  • Regular backups stored somewhere separate.
  • Not keeping data longer than you need it — clear out old form submissions.

5. The ICO data protection fee

Most organisations that process personal data need to pay a small annual data protection fee to the ICO, though some are exempt. The ICO website has a quick self-assessment that tells you whether you need to pay.

Quick checklist

  1. A clear, accurate privacy policy linked in your footer and by forms
  2. Only essential cookies — or proper consent for the rest
  3. Forms that collect the minimum and don’t auto-subscribe people
  4. HTTPS, updates, strong passwords, 2FA and backups in place
  5. ICO fee checked and paid if required

Every Solent Web site is built with privacy in mind: HTTPS, secure forms, minimal cookies and guidance on your privacy policy. If you’d like your current site checked, get in touch.

Want help with this?

Let's buildsomething good

or email

Your details are only used to reply to you. Read the privacy policy.

Southampton--:--:--
Reply timeWithin 24 hours
Coordinates50.9097° N, 1.4044° W