Practical guide · Starting a Website

GDPR Basics for Small-Business Websites

A small-business website uses personal data whenever it can identify a person directly or indirectly. Contact forms, booking details, customer accounts, email lists, analytics identifiers, support messages and IP…

A small-business website uses personal data whenever it can identify a person directly or indirectly. Contact forms, booking details, customer accounts, email lists, analytics identifiers, support messages and IP addresses can all be relevant. The legal work therefore begins with understanding the real data flow, not with downloading a generic privacy-policy template.

This guide explains the practical foundation for UK websites. It is not legal advice. Information was checked on 21 July 2026 and reflects changes made by the Data (Use and Access) Act 2025.

Map the data before writing the notice

Create a simple record for every collection point:

Data inventory for a small-business website
Collection pointQuestions to answer
Contact or quotation formWhich fields are required, who receives the message, where it is stored and when it is deleted?
Booking or customer accountWhich service provider processes the data, what information is necessary and how long does the account remain?
AnalyticsWhich identifiers are used, whether consent or an exception applies and who can access the reports?
Email marketingHow permission or another lawful route is established, what evidence is retained and how people opt out?
PaymentsWhich payment provider handles card information and what the website itself receives?
Embedded servicesWhether maps, video, chat, fonts or social tools transfer information to third parties

Use the data protection principles

  • Lawfulness, fairness and transparency: use data for a valid reason and explain the use clearly.
  • Purpose limitation: do not quietly reuse information for an unrelated purpose.
  • Data minimisation: collect only what the task genuinely requires.
  • Accuracy: provide a way to correct important information.
  • Storage limitation: define retention rather than keeping everything indefinitely.
  • Security: protect access, transmission, storage and disposal.
  • Accountability: keep evidence of the decisions and controls.

A privacy notice describes these practices; it does not create them.

Choose the lawful basis before processing

Consent is only one possible lawful basis. Others include contract, legal obligation, vital interests, public task and legitimate interests. The correct basis depends on the purpose. Do not use consent automatically when the processing is required to perform a requested contract, and do not claim “legitimate interests” without understanding the necessity and impact.

Special category data, criminal offence data and information about children require additional care and may need a separate legal condition or specialist advice.

Write a privacy notice that matches reality

The notice should normally explain:

  • who the controller is and how to contact it;
  • the categories and sources of personal data;
  • the purposes and lawful bases;
  • legitimate interests where used;
  • recipients and processors;
  • international transfers and safeguards where relevant;
  • retention periods or criteria;
  • individual rights;
  • how to withdraw consent where applicable;
  • how to make a data protection complaint;
  • the right to complain to the ICO;
  • automated decision-making where relevant.

Place privacy information where people need it. A visible full notice can be supported by short wording beside forms, explaining what will happen to the submitted information.

Handle data protection complaints from 19 June 2026

All organisations handling personal data must provide a clear route for data protection complaints. They must acknowledge a complaint within 30 days, investigate it appropriately and communicate the outcome.

A practical process should include:

  1. A published contact method that reaches a responsible person.
  2. A log of the complaint, dates, evidence and actions.
  3. Acknowledgement within the required period.
  4. A fair investigation by someone with enough authority.
  5. A written outcome and explanation of any corrective action.
  6. Information about escalation to the ICO.

Use processors under appropriate arrangements

Hosting, CRM, email, booking, analytics and support suppliers may process data for the business. Record each provider, the data involved, location, security information and contractual terms. A familiar brand is not a substitute for checking whether the service is configured and contracted appropriately.

Protect forms and accounts

  • Use HTTPS across the site.
  • Limit form fields and avoid requesting sensitive information casually.
  • Protect administrative accounts with strong unique credentials and multi-factor authentication where available.
  • Restrict access according to role.
  • Keep software supported and updated.
  • Set retention and deletion routines for form submissions and dormant accounts.
  • Test backups and incident response.
  • Do not send sensitive data through ordinary email without assessing the risk.

Prepare for requests and incidents

The business should know how to recognise and route access, correction, deletion, restriction, objection and portability requests. It should also have a process for assessing personal data breaches, reducing harm, documenting decisions and notifying the ICO or affected people where required.

Official starting points

The next practical step is to complete a data inventory and assign an owner for privacy, requests, complaints and incidents before revising the public notice.

Keep the decision under your control

Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.