← Blog Roll
Web Development13 November 20257 min read

Is your website GDPR compliant?

54 percent of UK small business websites have no privacy policy. 52 percent have no cookie consent. Most of them do not know they need one. Some of them genuinely do not.

You might not need any of this

Before we go any further, let us start with the thing nobody tells you. If your website does not collect personal data, does not set non-essential cookies, and does not use analytics or tracking scripts, your GDPR obligations are minimal. You may not need a cookie banner at all.

UK GDPR applies when you process personal data. The Privacy and Electronic Communications Regulations (PECR) require consent before setting non-essential cookies. If your site does neither, those rules have very little to say to you.

A simple brochure website with five static pages, no contact form, no analytics, and no embedded third-party content is about as low-risk as it gets. That website does not collect names, email addresses, or browsing behaviour. It does not set tracking cookies. It does not need a privacy policy, and it does not need a cookie banner.

The problem is that most websites are not that simple. Even when the owner thinks they are.

Your site probably does more than you think

92 percent of websites use cookies in some form. Many site owners have no idea theirs is one of them.

If your website has Google Analytics, it sets cookies. If it embeds a YouTube video, that embed loads scripts and sets cookies before the visitor even clicks play. If it has a Google Maps widget, a Facebook Like button, or a social media feed, those all set third-party cookies. If your site loads fonts from Google Fonts, it sends your visitor's IP address to Google. IP addresses are personal data under UK GDPR.

Even a basic WordPress installation often sets cookies through its CMS, its plugins, or its hosting provider. Your website might look like a simple five-page brochure, but under the surface it could be collecting data you never asked it to collect.

This is why 54 percent of UK small business websites have no privacy policy and 52 percent have no cookie consent mechanism. It is not that business owners are ignoring the law. They do not know their site is doing something that triggers it.

Cookie banners are not there to annoy you

Everyone hates cookie banners. Business owners hate adding them. Visitors hate clicking them. But they exist because the law says they have to.

Under PECR, you must get consent before setting any cookie that is not strictly necessary for the site to function. Strictly necessary means things like shopping basket cookies, login session cookies, and load-balancing cookies. Anything the site needs to work as the visitor expects.

Analytics cookies are not strictly necessary. Advertising cookies are not strictly necessary. Third-party cookies from embedded content are not strictly necessary. If your site sets any of those, you need consent before they fire. That means a cookie banner.

There is a new exception under the Data (Use and Access) Act 2025, which came into force in February 2026. First-party analytics cookies used solely to measure your own site performance can now operate on an opt-out basis instead of opt-in. But this only applies if no third party has contractual rights to use the data. Google Analytics does not qualify because Google's terms reserve rights to use the data for their own products. If you use GA4, you still need prior consent.

Most cookie banners do not actually work

Here is where it gets worse. Having a cookie banner is not enough. The banner has to actually block non-essential cookies until the visitor clicks accept. Most do not.

Only 15 percent of cookie banners meet basic compliance requirements. 73 percent of automated cookie consent tools fail to block all trackers before consent is given. The ICO reviewed the top 200 UK websites in 2023 and found 134 of them were non-compliant. 30 percent of the top 100 were setting advertising cookies without valid consent.

A banner that says "This site uses cookies" with an "OK" button and no actual script-blocking is decorative. It gives you no legal protection. It is the website equivalent of putting a "Beware of the Dog" sign on a gate with no dog behind it.

59 percent of websites still set cookies before the user has given consent. If yours is one of them, the banner is doing nothing except taking up screen space.

Contact forms make you a data controller

If your website has a contact form, you are collecting personal data. A name and an email address is all it takes. That makes you a data controller under UK GDPR, regardless of business size.

This means you need a privacy policy that explains what data you collect, why you collect it, how long you keep it, and who you share it with. You should link to it from the contact form page, ideally near the submit button.

The lawful basis for processing a contact form enquiry is usually legitimate interests. Someone has actively chosen to contact you. You are responding. That is straightforward. But you still need to document it, and you still need to tell people about it.

You also need a data retention policy. You cannot keep enquiry emails indefinitely. Define how long you hold the data, and delete it when that period ends. If you have never thought about this, you are not alone. But you do need to think about it.

The ICO is not coming for your corner shop

Let us put the fines in perspective. The maximum penalty under UK GDPR is 17.5 million pounds or 4 percent of global turnover. That number is designed for companies like British Airways, which was fined 20 million pounds, or Marriott Hotels, which was fined 18.4 million. These are serious breaches affecting millions of people.

For small businesses, the ICO takes a proportionate approach. In 2024, the ICO carried out 32 enforcement actions under UK GDPR. Only three resulted in fines. Eighteen were reprimands. No small business has been publicly fined specifically for website cookie non-compliance.

That does not mean the rules do not apply. The ICO investigates based on complaints, and anyone can file one. But the realistic risk for a small business is a compliance letter or a reprimand, not a seven-figure fine. The point is not to scare you. The point is to get it right because it protects your customers and it protects you.

What you actually need to do

Start by finding out what your website actually does. Run a cookie scanner. Check whether Google Analytics is installed. Look at your embedded content. If your site sets no non-essential cookies and collects no personal data, you may be fine as you are.

If your site does collect personal data or set non-essential cookies, here is the minimum. A privacy policy that names you as the data controller, lists the data you collect, explains the lawful basis, states how long you keep it, and tells people how to exercise their rights. A cookie banner that actually blocks non-essential scripts until the visitor gives consent. Not a banner that just appears and does nothing. One that works.

If you have a contact form, link your privacy policy near the submit button. Define a retention period for enquiry data. If you use Google Analytics, make sure it only fires after consent is given.

If your site genuinely does none of these things, do not add a cookie banner for the sake of it. A cookie banner on a site with no cookies is misleading. It suggests you are tracking people when you are not.

The bottom line

GDPR compliance is not all or nothing. It depends entirely on what your website actually does. A genuinely static site with no forms, no analytics, and no third-party embeds has minimal obligations. But the moment you add Google Analytics, a YouTube video, a contact form, or even Google Fonts, rules apply. Most small business owners do not know their site triggers them. That is the real problem.

The fix is not panic. It is awareness. Find out what your site collects. If it sets non-essential cookies, you need a banner that actually blocks them before consent, not one that just says "OK" and does nothing. If it has a contact form, you need a privacy policy. If it genuinely does none of these things, do not add a cookie banner for show. A banner on a site with no cookies is not compliance. It is theatre.

The ICO is not hunting small businesses. No small business has been publicly fined for website cookie non-compliance. But the rules protect your customers, and getting them right protects you. Know what your website collects, then act accordingly.

How we can help

Every website we build is designed with data protection in mind from the start. We do not add tracking scripts unless you need them. We do not embed third-party content that sets cookies without telling you. If your site does not collect personal data, we do not bolt on a cookie banner just to look compliant. Because a cookie banner on a site with no cookies is not compliance. It is theatre.

When a site does need analytics, we configure it properly. When it needs a contact form, we build in a clear privacy link and set up data handling that matches what your privacy policy says. When it needs a cookie banner, we use one that actually blocks scripts until consent is given.

We also audit existing websites for compliance gaps. If you are not sure what your site collects, we can tell you. And if it turns out you need less than you think, we will tell you that too.

Know what your website collects. Then act accordingly.

Share

Contact Us