GDPR website compliance: a practical guide for UK businesses
22 July 2026 · 3 min read
GDPR website compliance: a practical guide for UK businesses

What GDPR website compliance means for UK businesses
GDPR website compliance means your website meets the legal and technical standards required to collect, store, and process personal data from UK and EU residents lawfully. For UK businesses, two frameworks apply simultaneously: the EU GDPR, which governs data belonging to EU residents, and the UK GDPR, which is the retained domestic version that came into force after Brexit. Both carry the same core obligations.
Any website that collects personal data through contact forms, cookies, analytics tools, or newsletter sign-ups falls within scope. The GDPR applies to any organisation processing personal data of EU or UK residents, regardless of where the business is based. A sole trader running a local plumbing website is as much in scope as a national retailer.
Six pillars underpin compliance for websites:
- Privacy policy: A clear, accessible document explaining what data you collect, why, how long you keep it, and who you share it with.
- Consent management: Active, granular consent obtained before any non-essential cookies or trackers load.
- Legal basis documentation: A recorded lawful basis under Article 6 for every processing activity (consent, contract, legitimate interest, and so on).
- Data subject rights facilitation: Processes for handling access, deletion, correction, portability, and objection requests within one month.
- Security measures: TLS encryption, access controls, and a breach notification procedure meeting the 72-hour reporting window.
- Data Processing Agreements (DPAs): Signed agreements with every third-party processor handling your data.
The Information Commissioner’s Office (ICO) enforces UK GDPR in Great Britain. EU supervisory authorities handle EU resident data. Fines reach up to €20 million or 4% of annual global turnover, whichever is greater.

Why GDPR compliance matters more than ever for UK websites
Enforcement has accelerated sharply. Total GDPR fines have exceeded €7.1 billion historically, with €1.2 billion issued in recent enforcement cycles alone. These are not penalties reserved for large corporations. The ICO has pursued small and medium businesses for failures including inadequate consent mechanisms and missing privacy policies.
Enforcement in numbers: Article 6 violations, covering unlawful processing and missing legal bases, represent a significant portion of GDPR enforcement actions globally.
Beyond fines, non-compliance creates reputational damage that is harder to recover from. Customers increasingly check privacy practices before sharing personal details. A website without a proper cookie banner or a clear privacy policy signals carelessness, and that perception affects enquiry rates. The accountability principle under GDPR also means you cannot simply claim compliance; you must be able to prove it to the ICO on request.

Key GDPR requirements your website must meet
Knowing what compliance actually requires is where most small business owners get stuck. These are the specific obligations your website must satisfy:
- Privacy policy: Publish a policy that names every category of data you collect, the legal basis for each, your retention periods, and any third parties you share data with. Plain English is a legal requirement, not just good practice.
- Cookie consent: The ePrivacy Directive requires consent before any non-essential cookie or tracker loads, including analytics and advertising pixels. Pre-ticked boxes and implied consent do not meet the standard.
- Lawful basis under Article 6: Every processing activity needs a documented legal basis. Consent, contract performance, legal obligation, vital interests, public task, and legitimate interests are the six options. Legitimate interests requires a balancing test.
- Data subject rights: Under GDPR, individuals have the right to access, erasure, correction, restriction, portability, and objection. You must respond within one month and provide accessible channels for submitting requests.
- Security: TLS encryption on all pages handling personal data is a baseline requirement. You also need documented procedures for detecting and reporting data breaches to the ICO within 72 hours of becoming aware.
- Data Processing Agreements: DPAs are required with every third-party processor, including Google Analytics, Mailchimp, and any cloud hosting provider. Failure to have effective DPAs has led to fines exceeding €1 billion across enforcement actions.
How to make your UK website GDPR compliant: step by step
Working through compliance in a structured order prevents gaps. Follow these steps:
-
Map your data flows. List every point where your website collects personal data: contact forms, booking tools, live chat, analytics, email sign-ups. Record what data is collected, why, where it is stored, and who can access it. This becomes your Record of Processing Activities (ROPA).
-
Implement a compliant cookie consent tool. Choose a consent management platform that blocks all non-essential scripts until the visitor actively accepts them. The banner must offer a genuine “reject all” option alongside “accept all.” Granular category controls (analytics, marketing, functional) are best practice. For detailed requirements on cookie consent mechanisms, specialist guidance covers the technical specifics.
-
Publish a comprehensive privacy policy. Cover every data category, legal basis, retention period, and third-party processor. Link it from your website footer and from every form where personal data is collected. Update it whenever your data practices change.
-
Set up a data subject access request (DSAR) process. Add a dedicated email address or form for privacy requests. Log every request, the date received, and your response date. One month is the legal deadline; complex requests can extend to three months with notice.
-
Secure your website. Install a valid TLS certificate across every page, not just checkout pages. Review who has admin access to your CMS and hosting. Remove unused plugins and third-party scripts, as each one is a potential data exposure point. For practical guidance on securing website data, technical measures and document management connect directly.
-
Sign Data Processing Agreements with all processors. Review every tool your website uses. Google, Mailchimp, and most major providers offer standard DPAs; locate them in the provider’s legal or privacy section and sign or accept them formally. Document that you have done so.
-
Appoint a DPO or privacy contact. Most small businesses do not meet the threshold requiring a formal Data Protection Officer. However, designating a named individual responsible for privacy matters, and listing their contact details in your privacy policy, satisfies the ICO’s expectation for accountability.
-
Prepare a breach response procedure. Write a short internal document covering how you detect a breach, who is responsible for assessing it, and how you notify the ICO within 72 hours. Keep the ICO’s reporting portal bookmarked.
-
Schedule annual compliance reviews. Set a recurring calendar reminder to review your ROPA, privacy policy, and consent configuration. Any material website change, such as adding a new analytics tool or switching email providers, triggers an immediate review, not just the annual one.
Documenting and proving GDPR compliance
Documentation is your primary defence in any ICO investigation. Demonstrating compliance requires more than having policies in place; it means maintaining records that prove your practices match your stated commitments.

Your ROPA should capture each processing activity with its legal basis, data categories, retention period, and the names of any processors involved. Small and medium businesses are strongly advised to maintain this record even when not strictly required by size thresholds. It takes a few hours to build initially and far less time to maintain.
Consent records need particular care. Consent must be logged with a timestamp and the exact version of the banner shown to the user at the time of consent. A simple “user accepted cookies” log is insufficient for a Data Protection Authority investigation. Your consent management platform should handle this automatically; if it does not, switch to one that does.
Pro Tip: Treat your privacy policy as a living document, not a one-time publication. Every time you add a new plugin, change your email marketing provider, or introduce a booking tool, update the policy and log the change date. Auditors look for version history.
Keep training logs if you have staff who handle personal data. The European Commission’s accountability guidance lists impact assessments, training records, and updated processing records as the core evidence set for supervisory audits.
Common mistakes that put UK websites at risk
Most GDPR failures by small businesses are predictable. Avoiding these specific errors removes the majority of your compliance risk.
Treating a cookie banner as the whole job. A banner that says “we use cookies” with only an “OK” button does not meet GDPR standards. Consent must be specific, informed, and freely given, with a genuine option to decline. Pre-ticked boxes and continued browsing do not count as consent under the regulation.
Copying a privacy policy template without adapting it. Generic templates list data categories that do not apply to your business and miss ones that do. A plumber’s website collecting booking requests has different data flows from a marketing agency. Your policy must reflect your actual practices.
Forgetting third-party scripts. Google Analytics, Facebook Pixel, embedded maps, and live chat widgets all process personal data. Each requires a DPA and, where consent is the legal basis, must be blocked until consent is given. Many small business websites load these scripts unconditionally on every page visit.
Missing the 72-hour breach notification window. Without a written procedure, most businesses discover a breach and then spend days deciding what to do. By that point, the notification deadline has passed. The ICO treats late notification as an aggravating factor.
Ignoring DSAR requests. A request submitted via a general contact form is still a valid DSAR. If you do not have a process for recognising and logging these, you will miss the one-month deadline without realising it.
Not updating documentation after website changes. Material website changes such as adding tracking pixels or switching email providers require immediate updates to your ROPA and lawful bases assessments. Many businesses update their site and forget their compliance records entirely.
UK GDPR vs EU GDPR: what changed after Brexit
The UK GDPR is the EU GDPR as it was incorporated into UK law via the European Union (Withdrawal) Act 2018, with amendments to make it function domestically. For most practical purposes, the two frameworks are equivalent in their core obligations: the same six lawful bases, the same data subject rights, the same documentation requirements.
The key differences affect businesses operating across both markets. If your website targets EU residents, you remain subject to EU GDPR for that data, enforced by the relevant EU supervisory authority. You may also need to appoint an EU representative if you have no establishment in the EU. The ICO handles UK resident data under UK GDPR.
Data transfers between the UK and EU currently operate under an adequacy decision, meaning personal data can flow freely without additional safeguards. This decision is subject to periodic review. For transfers to countries outside the UK and EU without adequacy status, Standard Contractual Clauses or other approved transfer mechanisms are required.
The UK government has signalled its intention to update UK GDPR through the Data (Use and Access) Act 2025, which introduces some divergence from the EU framework, particularly around legitimate interests and research exemptions. Businesses should monitor ICO guidance as these changes take effect.
How GDPR affects your marketing practices
GDPR changed the rules for email marketing and digital tracking in ways that directly affect how UK service businesses generate leads online.
Email marketing requires a clear lawful basis for every contact on your list. For marketing emails, consent is almost always the correct basis, and that consent must be specific to marketing communications. Buying email lists is incompatible with GDPR. Existing contacts acquired before GDPR came into force need to have given consent that meets the current standard; if they did not, they should be removed or re-permissioned. For guidance on lawful bases for processing personal data in professional services contexts, specialist resources cover the practical documentation requirements.
Tracking and analytics require consent before loading. Google Analytics, Meta Pixel, and similar tools set cookies and process IP addresses, which are personal data. Your consent banner must block these scripts until the visitor actively accepts analytics or advertising cookies. Running these tools without consent is one of the most common sources of GDPR enforcement action.
Retargeting and remarketing campaigns depend on consent-based tracking data. If a visitor declines cookies, you cannot retarget them. This is not a workaround problem; it is the intended outcome of the regulation. Businesses that build their marketing on first-party, consent-based data are better positioned for long-term compliance and audience quality.
For a broader view of how compliance requirements sit alongside other website obligations, the professional trade website checklist covers GDPR applicability alongside other practical requirements for UK service business websites.
Key takeaways
GDPR website compliance for UK businesses requires active implementation of legal, technical, and documentary measures across six core areas, with ongoing maintenance as your website and data practices evolve.
| Point | Details |
|---|---|
| Scope is broad | Any website collecting data from UK or EU residents must comply, regardless of business size. |
| Fines are substantial | Penalties reach up to €20 million or 4% of annual global turnover for serious breaches. |
| Consent must be active | Pre-ticked boxes and implied consent do not meet GDPR standards; non-essential scripts must be blocked until consent is given. |
| Documentation is your defence | Records of Processing, consent logs with timestamps, and signed DPAs are the evidence the ICO expects to see. |
| Compliance is ongoing | Material website changes require immediate updates to your ROPA, privacy policy, and lawful bases assessments. |

Get your website built with compliance in mind from day one
gtwelve builds websites for UK service businesses that handle enquiries, automate follow-ups, and connect to your existing tools, with privacy and data handling considered from the start, not bolted on afterwards. If your current site needs a compliance review alongside a professional upgrade, talk to gtwelve about what that looks like for your business.
Recommended
If this sounds like your website, we can take a look.
Note 02 of 68