Data protection and cookie consent can feel daunting, but for most small business websites the requirements come down to a handful of sensible practices: be clear about what you collect, ask permission where the law requires it and look after the data you hold. This guide gives an overview of the main points.
Please note: this is general information, not legal advice. For your specific situation, check the latest guidance from the Information Commissioner’s Office (ICO) or speak to a legal professional.
The two sets of rules that apply
Two pieces of law are relevant to most websites:
- UK GDPR and the Data Protection Act 2018, which cover how you collect, use and store personal data, such as names and email addresses from your contact form.
- The Privacy and Electronic Communications Regulations (PECR), which cover cookies and similar technologies, as well as electronic marketing such as emails and texts.
The Data (Use and Access) Act 2025 amends parts of both, including some exemptions from cookie consent, for example for certain analytics cookies, as its provisions come into force. Because these changes are being phased in, it is worth checking the ICO’s current guidance rather than relying on older articles.
Cookies and consent
Under PECR, you need to tell visitors about the cookies you use and, for cookies that are not strictly necessary, get their consent before setting them. Strictly necessary cookies are those needed for something the visitor has asked for, such as keeping items in a basket or keeping someone logged in.
Advertising and tracking cookies, such as those set by social media pixels or ad platforms, generally need consent. A compliant cookie banner should:
- Not set non-essential cookies until the visitor agrees.
- Make rejecting as easy as accepting. A prominent “Accept” with “Reject” hidden behind several clicks is not acceptable.
- Avoid pre-ticked boxes.
- Let visitors change their mind later, for example through a link in the footer.

Photo by Bayu Syaits on Unsplash
Your privacy notice
If your website collects personal data, which almost every website with a contact form does, you need a privacy notice explaining:
- Who you are and how to contact you.
- What data you collect and why.
- Your lawful basis for using it, such as responding to an enquiry or fulfilling a contract.
- Who you share it with, such as your email provider, CRM or payment processor.
- How long you keep it.
- People’s rights, including access and deletion, and how to complain to the ICO.
Write it in plain language and keep it up to date when you add new tools to your website.
Contact forms and email marketing
Only ask for the information you need. If you want to add people to a mailing list, use a separate, unticked opt-in box rather than assuming that sending an enquiry means they want your newsletter. Keep a record of when and how consent was given.
Security and suppliers
UK GDPR requires appropriate security for the personal data you hold. For a website, that means HTTPS, up-to-date software, strong passwords with two-factor authentication for admin accounts and not keeping form submissions longer than necessary. If your website sends data to other services, such as hosting, email or CRM providers, make sure they are reputable and have suitable data processing terms.
Registering with the ICO
Most organisations that process personal data need to pay an annual data protection fee to the ICO, although some are exempt. The ICO website has a short self-assessment to check whether you need to pay.
A quick checklist
- List every cookie and third-party script on your website.
- Make sure non-essential ones only load after consent.
- Check your cookie banner offers an equally easy “Reject”.
- Review your privacy notice against the tools you actually use.
- Remove form fields you do not need.
- Check whether you need to pay the ICO fee.
When we build websites, we set up consent handling and data collection carefully from the start. If you would like us to review your current setup from a technical point of view, get in touch.


