Guide

GDPR and privacy policies for small UK business websites

What UK GDPR actually expects of an ordinary small-business site — a contact form, some analytics, maybe a newsletter — and what a privacy policy has to say.

Published 22 August 2026 · Scoutline

Short answer: if a website collects any personal data — a name and email from a contact form is enough — UK GDPR applies, with no small-business exemption. The site needs a privacy policy explaining what's collected, why, how long it's kept, and who it's shared with (like a hosting or email provider), and needs consent before setting any non-essential cookie such as analytics. This isn't legal advice; check ico.org.uk for the current guidance before relying on any summary, including this one.

"GDPR" tends to sound like something that only applies to large companies with legal departments. It doesn't — it applies the moment any personal data is processed, and a website run by one person with a contact form on it processes personal data the instant someone fills that form in.

Does GDPR really apply to a small business website?

Yes, in almost every realistic case. UK GDPR (the UK's version of the EU regulation, sitting alongside the Data Protection Act 2018) has no size-based exemption for businesses — a sole trader with one page is covered the same as a large company, the moment the site collects a name, an email address, or anything else that identifies a real person.

What triggers it on a typical small-business site

common

Contact form

A name and email address is personal data on its own.

common

Email signup

Collecting an address for a newsletter or offers.

common

Analytics

Google Analytics and similar tools set cookies and track visits.

less common

Bookings & chat

Booking forms and live chat widgets both store personal details.

Almost every generated or hand-built site with a working contact form — see our guide on setting one up — hits the first case immediately.

What a privacy policy actually has to cover

A privacy policy exists to answer one question honestly: what happens to someone's data after they hand it over. At minimum, it should say:

  • Who's collecting the data — the actual business name and a way to contact them about it.
  • What's collected — typically name, email, phone, and anything else a form asks for.
  • Why, and the legal basis — usually "to respond to your enquiry" (legitimate interest) or "because you asked to be added" (consent) for a newsletter.
  • How long it's kept, even approximately — "until the enquiry is resolved" is more honest than an unstated indefinite hold.
  • Who else sees it — a hosting provider, an email-sending service, a booking platform — anywhere the data actually goes, not just where it's first collected.
  • The individual's rights — to see what's held, correct it, or ask for it to be deleted, and how to actually make that request.

Cookies and analytics

Cookies that are strictly necessary for the site to function (like remembering a shopping basket) don't need consent. Analytics cookies generally do — UK PECR rules (the same regulation behind our cold email guide) expect informed consent before a non-essential cookie is set, not just a banner announcing that it already has been. A simple accept/decline choice, respected before any analytics script runs, is the practical baseline.

Getting one written honestly, not just copied

A privacy policy copied wholesale from another business's site is a genuine liability, not a shortcut — it routinely names the wrong company, describes tools the site doesn't actually use, and misses ones it does. A plain-English generator built around the actual answers above is a reasonable starting point for a simple site; anything handling sensitive data, under-16s, or larger volumes is worth a genuine conversation with someone qualified rather than a template.

Common questions

Questions people actually ask

Does UK GDPR apply to a small business website?

Yes — there's no small-business exemption. If a website collects any personal data at all, most commonly through a contact form, an email signup, or analytics, UK GDPR applies regardless of the size of the business collecting it.

Does a simple website with just a contact form need a privacy policy?

Yes. A contact form that collects a name and an email address is processing personal data, which is enough on its own to require a privacy notice explaining what's collected, why, how long it's kept, and who it might be shared with (such as a hosting or email provider).

Do I need a cookie banner if I only use Google Analytics?

Generally yes — analytics cookies are not classed as strictly necessary, so UK rules (PECR, alongside GDPR) expect informed consent before they're set, not just a notice saying they exist. This is a genuinely fiddly area and worth checking ico.org.uk directly for the current guidance rather than relying on any one summary, including this one.