UK GDPR Requirements for Small Business Websites

Developer writing code on a laptop, representative of website data handling

Every UK business with a website that collects any personal data, even a simple contact form, falls under GDPR. Many small business owners assume compliance is only for large companies handling sensitive data, which is a genuinely costly misunderstanding.

Quick Answer

UK GDPR applies to every business website that collects personal data, including names, email addresses, or phone numbers through contact forms, newsletter sign-ups, or analytics tools. Core requirements include a clear privacy policy, a genuine cookie consent mechanism, a documented lawful basis for processing data, and a process for handling data subject requests. Non-compliance can result in fines of up to £17.5 million or 4% of annual turnover, though most small business enforcement involves corrective notices rather than maximum fines.

Does GDPR Really Apply to Small Websites?

Yes, and this is the single biggest misconception among small business owners. If your website has a contact form, a newsletter sign-up, a booking calendar, or even just Google Analytics installed, you are processing personal data and GDPR applies. There is no size-based exemption, though the specific obligations that apply can scale with the complexity and risk of what you are doing with that data.

Core Requirements for a Compliant Website

  • A genuine privacy policy. Clearly explaining what data you collect, why, how long you keep it, and who you share it with, matching what your website actually does.
  • Real cookie consent. A cookie banner must give visitors a genuine choice before non-essential cookies load, not simply display a notice while tracking scripts run regardless.
  • A documented lawful basis. Every piece of personal data you collect needs a lawful basis for processing, such as consent, contract, or legitimate interests.
  • Clear terms and business information. Including your registered company name and number if applicable.
  • A process for data subject requests. Visitors have rights to access, correct, or request deletion of their data, and you need a way to respond.

The Cookie Banner Trap

One of the most common compliance gaps is a cookie banner that is purely cosmetic. If your site displays a consent popup but loads Google Analytics, Facebook Pixel, or other tracking scripts before the visitor makes a choice, or regardless of what they choose, this does not meet GDPR consent requirements. Genuine consent means those scripts only load after a clear, affirmative choice.

Contact Forms and Data Collection

Every contact form should clearly explain what happens to submitted data and link to your privacy policy nearby. A common mistake is collecting more data than genuinely needed for the stated purpose, which conflicts with the GDPR principle of data minimisation.

The Six Lawful Bases for Processing

  • Consent. The individual has given clear, informed agreement.
  • Contract. Processing is necessary to fulfil a contract with the individual.
  • Legal obligation. Processing is required to comply with the law.
  • Vital interests. Processing is necessary to protect someone’s life.
  • Public task. Processing is necessary for a task in the public interest.
  • Legitimate interests. Processing is necessary for your legitimate business interests, balanced against the individual’s rights.

For most small businesses, contract, legitimate interests, and consent cover the majority of everyday processing activities.

What Happens If You Don’t Comply

The Information Commissioner’s Office (ICO) enforces GDPR in the UK. For most small businesses, the realistic outcome of a compliance gap is an enforcement notice requiring you to fix the problem, rather than an immediate fine. However, complaints can come from anywhere, including competitors, and a single report of a missing privacy policy or fake cookie consent can trigger an investigation.

Website Accessibility and Data Protection Often Overlap

Businesses reviewing their website for GDPR compliance often benefit from reviewing accessibility compliance at the same time, since both involve auditing how your site handles user interaction and data collection. See our guide on whether website accessibility is a legal requirement in the UK for the other major compliance area most business websites need to address.

A Practical Starting Checklist

  • Audit exactly what personal data your website actually collects, including via third-party tools and plugins
  • Check your cookie banner genuinely blocks non-essential cookies until consent is given
  • Rewrite your privacy policy to match what your site actually does, not a generic template
  • Document a lawful basis for each type of data processing on your site
  • Set up a simple process for responding to data subject access requests

Frequently Asked Questions

Does GDPR apply to a one-page website with just a contact form?
Yes. Any collection of personal data, however simple, brings GDPR into scope.

Is a cookie banner enough for compliance?
Only if it genuinely blocks non-essential cookies until the visitor gives clear consent, not just displays a notice while scripts run anyway.

What is the maximum GDPR fine for a small business?
Up to £17.5 million or 4% of annual turnover, though in practice small business enforcement typically involves warnings or corrective notices rather than maximum penalties.

Do I need to register with the ICO?
Most UK businesses processing personal data need to register and pay the data protection fee, unless a specific exemption applies.

Can a template privacy policy be used safely?
Only if it is carefully checked and edited to accurately reflect what your specific website actually does, since a mismatched policy can be worse than no policy at all.

Related Reading

For official guidance referenced in this article, see the ICO’s GDPR guidance for small organisations.

Back To Top