What UK GDPR actually expects of an ordinary small-business site — a contact form, some analytics, maybe a newsletter — and what a privacy policy has to say.
Short answer: if a website collects any personal data — a name and email from a contact form is enough — UK GDPR applies, with no small-business exemption. The site needs a privacy policy explaining what's collected, why, how long it's kept, and who it's shared with (like a hosting or email provider), and needs consent before setting any non-essential cookie such as analytics. This isn't legal advice; check ico.org.uk for the current guidance before relying on any summary, including this one.
"GDPR" tends to sound like something that only applies to large companies with legal departments. It doesn't — it applies the moment any personal data is processed, and a website run by one person with a contact form on it processes personal data the instant someone fills that form in.
Yes, in almost every realistic case. UK GDPR (the UK's version of the EU regulation, sitting alongside the Data Protection Act 2018) has no size-based exemption for businesses — a sole trader with one page is covered the same as a large company, the moment the site collects a name, an email address, or anything else that identifies a real person.
A name and email address is personal data on its own.
Collecting an address for a newsletter or offers.
Google Analytics and similar tools set cookies and track visits.
Booking forms and live chat widgets both store personal details.
Almost every generated or hand-built site with a working contact form — see our guide on setting one up — hits the first case immediately.
A privacy policy exists to answer one question honestly: what happens to someone's data after they hand it over. At minimum, it should say:
Cookies that are strictly necessary for the site to function (like remembering a shopping basket) don't need consent. Analytics cookies generally do — UK PECR rules (the same regulation behind our cold email guide) expect informed consent before a non-essential cookie is set, not just a banner announcing that it already has been. A simple accept/decline choice, respected before any analytics script runs, is the practical baseline.
A privacy policy copied wholesale from another business's site is a genuine liability, not a shortcut — it routinely names the wrong company, describes tools the site doesn't actually use, and misses ones it does. A plain-English generator built around the actual answers above is a reasonable starting point for a simple site; anything handling sensitive data, under-16s, or larger volumes is worth a genuine conversation with someone qualified rather than a template.
Yes — there's no small-business exemption. If a website collects any personal data at all, most commonly through a contact form, an email signup, or analytics, UK GDPR applies regardless of the size of the business collecting it.
Yes. A contact form that collects a name and an email address is processing personal data, which is enough on its own to require a privacy notice explaining what's collected, why, how long it's kept, and who it might be shared with (such as a hosting or email provider).
Generally yes — analytics cookies are not classed as strictly necessary, so UK rules (PECR, alongside GDPR) expect informed consent before they're set, not just a notice saying they exist. This is a genuinely fiddly area and worth checking ico.org.uk directly for the current guidance rather than relying on any one summary, including this one.