The letters GDPR still make a lot of small business owners wince. You picture legal fees, cookie pop-ups nobody reads and a stack of paperwork that eats a weekend you do not have. The good news: for a typical local business website, GDPR and your website compliance comes down to a handful of sensible, do-once tasks, not a mountain of red tape.
This is a plain-English guide to what actually matters. No scare tactics, no legalese. If you run a dental practice in Leeds, a plumbing firm in Bristol or a café in Manchester, you can work through this list and know where you stand.
What GDPR actually means for a small business site
Since Brexit, the UK runs its own version of the rules, usually called UK GDPR, overseen by the Information Commissioner's Office (the ICO). The core idea has not changed: if your website collects personal data about people, you are responsible for handling it fairly, keeping it safe and being honest about what you do with it.
Personal data is anything that can identify someone. On most small-business sites that means the obvious stuff: names, email addresses and phone numbers from a contact form, plus quieter data like IP addresses and analytics identifiers. You do not need a data protection officer or a compliance department. You do need to know what you collect and why.
The privacy policy you genuinely need
Every site that collects data needs a privacy policy, and it has to be easy to find, usually linked in the footer on every page. This is not a place to copy a competitor's page and swap the name. Your policy should honestly describe what you collect, why, how long you keep it and who you share it with.
Write it in language a normal person understands. Say what happens when someone fills in your form, name the tools you use (your email provider, your booking system, your analytics) and tell people how to contact you if they want their data removed. A short, truthful policy beats a long, borrowed one every time. Good copywriting here builds trust rather than burning it.
Cookies and consent without the annoying pop-up
Cookie banners have a bad reputation because most of them are done badly. The rule is straightforward: anything beyond strictly necessary cookies (the ones that make the site work) needs consent before it loads. That covers analytics and most marketing or tracking scripts.
In practice that means a simple banner letting people accept or reject non-essential cookies, and your tracking scripts holding off until they choose. The mistake to avoid is a banner with only an 'accept' button, or one that fires Google Analytics the moment the page loads. Both fall short of what the ICO expects. Done well, consent can be a two-click, unobtrusive part of the page rather than a wall between the visitor and your content.
Forms, security and keeping data safe
Collecting data brings a duty to protect it. For a small-business site the essentials are refreshingly practical, and most are simply good web hygiene you would want anyway.
None of this is exotic. It is the baseline any decent build should include from day one, which is why we bake it into every website we design rather than treating it as an add-on.
A quick compliance checklist
If you want a fast gut-check, run your site against the list below. Most local businesses can get the important parts right in an afternoon, especially with a tidy, well-built site behind them.
Where most small business sites slip up
In our experience reviewing sites, the same few gaps come up again and again: a privacy policy lifted wholesale from another business, a cookie banner that does nothing, analytics firing before consent, and forms sitting on an old site with no SSL. None of these are hard to fix, but they are easy to miss when you are busy running the actual business.
That is exactly what a free teardown is for. We record a short walkthrough of your current site and flag the practical issues, GDPR-related and otherwise, in plain English. If you would rather see the bigger picture first, our services and transparent pricing lay out how a fixed-price rebuild works, with no lock-in and no hourly surprises.
- ✓UK GDPR for a small site is mostly a privacy policy, honest cookie consent and basic security.
- ✓You do not need a data protection officer or expensive legal advice for a typical local business website.
- ✓Fixing the essentials is usually an afternoon's work on a well-built site, not a major project.
Frequently asked questions
Do I really need a privacy policy on a small business website?
Yes. If your site collects any personal data, even just names and emails from a contact form, UK GDPR requires a clear privacy policy that is easy to find. It should honestly explain what you collect, why, and how people can ask you to remove their data. It does not need to be long, but it does need to be true to how your site actually works.
Are cookie banners a legal requirement?
If your site uses non-essential cookies, such as Google Analytics or marketing trackers, you need consent before they load, and a banner is the usual way to get it. Strictly necessary cookies that make the site function do not need consent. The key is giving people a genuine choice to accept or reject, not just an 'accept' button.
Can GDPR problems actually get me fined?
For most small businesses the realistic risk is a complaint to the ICO rather than a large fine, and the ICO usually works with you to put things right first. That said, sloppy data handling erodes customer trust, which costs you more quietly. Getting the basics right is cheaper and simpler than dealing with a complaint later.
How much does a compliant website cost?
Our websites are fixed-price so you know the cost up front, starting at £477 for a Starter site, £1,170 for Growth and £2,370 for Complete. Every build includes SSL, a simple admin panel and 30 days of aftercare, so the compliance basics are covered from the start. Care plans to keep everything maintained start at £27 a month. You can see the full breakdown on our pricing page.
How long does it take to build a new site?
Most of our sites go live in three to six weeks, depending on the size of the project and how quickly we get your content and photos. We are a small UK-based team you deal with directly, so there is no waiting on a call centre. A free teardown is the quickest way to get a realistic timeline for your project.
Not sure if your site measures up?
Book a free teardown and we will record a short, honest review of your current site, flagging the practical GDPR and design issues worth fixing first.
Book your free teardown →