UK GDPR compliance for small business websites has accumulated more cottage-industry advice than necessary. Here's what you actually need to do, with reference to UK law not the broader EU debate.
The basics every UK small business website needs
- A privacy policy -- Specific to your data flows. Generic templates pulled off the web aren't sufficient. Yours should cover:
- Who you are (Co. No., registered office)
- What data you collect (named fields, with examples)
- Why you collect it (lawful basis under Article 6)
- How long you keep it (retention periods)
- Who you share it with (third-party processors named)
- The visitor's rights and how to exercise them
- ICO complaint route
If yours doesn't address these specifically, it's not compliant. Generic boilerplate that says "we may collect cookies" doesn't pass the test.
- A cookie banner that does what it says -- If you only use strictly-necessary cookies (auth, session, security), you don't legally need a consent banner — though many small business sites still display one. If you use analytics, marketing pixels or other non-essential cookies, you do need granular consent that's actually wired up (not just a banner that displays while your scripts run anyway).
- A contact form that captures consent appropriately -- Tick boxes for marketing, separate from form submission consent. Pre-ticked boxes aren't valid consent under GDPR — they have to be active opt-ins.
- ICO registration -- If you process personal data and aren't exempt (most UK small businesses aren't exempt), you should be registered with the ICO. Fee is £40-£60/year depending on turnover. The number of UK small businesses still unregistered is uncomfortably high.
What you don't strictly need
- A cookie banner if you only use strictly-necessary cookies
- A "data processing agreement" with every visitor (you're not their processor)
- A GDPR-specific privacy contact officer (small businesses are generally exempt from the DPO requirement)
- Complicated consent management platforms if you have a simple cookie footprint
What changes if you handle special category data
Sensitive personal data (health, racial/ethnic origin, religious belief, genetic, biometric) has higher protection. If you process it (healthcare practices, sports clubs handling junior data, faith organisations, education), you need:
- An explicit Article 9 lawful basis (consent or one of the specific exceptions)
- A clear retention and disposal policy
- Appropriate security measures (encryption at rest and in transit, role-based access, audit trails)
- Often a DPIA (Data Protection Impact Assessment) for new processing
This is where Cyber Essentials-aligned and properly built client portals matter. A spreadsheet of children's data emailed around isn't compliant by any stretch.
Subject access requests
UK GDPR gives individuals the right to ask what you hold on them. You have one month to respond. For small businesses, this rarely happens — but you need a documented process for when it does. A privacy email address and a simple internal procedure is enough for most.
What to do if you have a breach
If a breach is likely to result in risk to rights and freedoms of individuals, you have 72 hours to notify the ICO. For most small business breaches (a stolen laptop, an accidental email to the wrong address), this is the right call. Document everything; the ICO is generally proportionate when you self-report and have reasonable controls in place.
How this connects to your website specifically
Three website-level things to get right:
- Privacy policy that reflects your actual data flows (not a generic template)
- Cookie banner that's compliant only if you actually need one
- Contact forms with appropriate consent capture
We typically include these as standard in any website build — they're not bolt-ons, they're baseline.
A note from the Bloomorbit studio
Every Bloomorbit website ships with a proper privacy policy tailored to the client's data flows, compliant cookie handling, and where relevant ICO/AML signposting. For solicitors, accountants and healthcare we go further with sector-specific compliance. If you'd like a free 10-minute call to talk through your specific situation, we offer those from our Cardiff studio.