Checklist & copy lines: UK website privacy policy for small businesses

If your website collects names, email addresses or even just tracks visitors with analytics, you need a privacy notice. That’s not optional under UK GDPR and the Data Protection Act 2018. The one thing to do today: put a short, plain notice on your site with your contact details, and link it to a fuller policy. The ICO sets the rules, and if you’d rather someone else sorted it, BasicBS builds this in as standard.
TL;DR:
- Small businesses must display a clear privacy notice on their site, including details such as data collected, lawful basis, data sharing, retention, and user rights.
- Cookies require specific consent, with necessary cookies exempt; banners must allow active, informed opt-in, rejection, and later changes, without pre-ticked boxes.
- Privacy policies must be truthful, current, and concise, with layered notices and just-in-time prompts to improve understanding and compliance.
- Breach reporting obligations require notification within 72 hours of awareness, with thorough documentation and phased updates if more information comes later.
- Confirm with your website provider that privacy setup and consent logging are properly implemented, as many small sites over-rely on default configurations or outdated templates.
Table of Contents
- What a UK privacy policy must include
- Cookies and consent: getting PECR right without annoying visitors
- When you legally need a policy, and other checkpoints worth knowing
- How to write a clear, layered privacy notice: step by step
- Handling a data breach: reporting and recordkeeping
- A practical checklist and template you can use today
- Our take: most sites overcomplicate this
- Sources
- FAQ
What a UK privacy policy must include
The ICO doesn’t require complicated legal language. It asks for clear, honest information in plain English about how you use people’s data, presented simply enough for customers to understand quickly.
Here’s what has to be in there, no exceptions:
- Who you are: your business name, contact details and, if you have one, your data protection officer.
- What data you collect: names, emails, IP addresses, payment details, whatever applies to your site.
- Why you collect it and your lawful basis: consent, contract, legal obligation or legitimate interests, stated for each purpose.
- Who you share it with: web hosts, payment processors, marketing tools, and whether any of that data leaves the UK.
- How long you keep it: a retention period or the criteria you use to decide.
- Their rights: access, correction, deletion, and how to withdraw consent or complain to the ICO.
The ICO’s guidance on writing a privacy notice recommends a layered approach: a short, plain notice up front, with a fuller detailed policy one click away. That’s not just good practice, it genuinely works better for readers than a wall of legal text nobody scrolls through.
A short headline notice does the heavy lifting. Something like: “We collect your name and email to respond to enquiries and send updates you’ve asked for. We never sell your data. Full details here.” That single sentence, sitting near a contact form, tells a visitor everything they need before they hand over their details.
Just-in-time notices matter too. If you’re collecting a phone number on a booking form, a one-line note next to that specific field (“We’ll only use this to confirm your appointment”) does more for trust than burying the explanation three pages deep in your policy. The ICO’s guidance on the right to be informed points to exactly this: layering, dashboards and just-in-time prompts keep your topline pages short while still covering everything required.
Skip the jargon. If your notice reads like it was written by a solicitor for another solicitor, you’ve missed the point. Plain English isn’t a nice-to-have here, it’s what the law actually expects.
Cookies and consent: getting PECR right without annoying visitors
Cookies are where a lot of small business sites fall down, mostly because whoever built the site ticked a box marked “cookie banner” and moved on. PECR, the Privacy and Electronic Communications Regulations, sets separate rules from GDPR, and they’re stricter than most people assume.
Not every cookie needs permission. Strictly necessary cookies, the ones that make your shopping basket or login work, don’t need consent. Everything else, analytics, advertising trackers, third-party embeds, needs it before it’s set.
Follow this order when setting up your banner:
- Split your cookies into categories: necessary, analytics, marketing, and anything else running on your site.
- Ask before you set anything non-essential, not after the visitor has already been tracked.
- Give a genuine “reject all” option, sitting as prominently as “accept all”, not hidden three menus deep.
- Never pre-tick optional boxes: consent has to be an active choice, not a default someone forgot to switch off.
- Let people change their mind later, via a visible link in your footer or cookie policy.
The ICO’s guidance on cookies is blunt about this: consent must be active and prior, and continued browsing doesn’t count as agreement. Pre-ticked boxes are a breach waiting to happen, not a shortcut.
Keep a record of what was agreed, when, and by what mechanism, your consent management tool should log this automatically. The ICO does not set a fixed expiry for cookie consent but suggests refreshing it about twice a year if your use of cookies remains unchanged; this is guidance rather than a strict legal requirement.

Pro Tip: If your website was built by someone else, log into your cookie banner tool and check the default settings yourself, plenty of small business sites still have “reject all” hidden behind an extra click, which isn’t compliant.
When you legally need a policy, and other checkpoints worth knowing
If your website processes personal data in any form, a contact form, a newsletter signup, even basic analytics, you need a notice. There’s no size exemption. Sole traders and one-person operations are covered exactly the same as larger companies.
Getting your lawful basis right matters more than most business owners realise. You can’t just pick “consent” for everything and call it done. A few checkpoints worth knowing:
- Consent works for marketing emails and optional cookies, but it must be freely given and easy to withdraw.
- Contract covers data you need to deliver something the customer’s paid for, like a delivery address.
- Legitimate interests can cover basic analytics or fraud prevention, but you need to document why it’s fair and proportionate.
- Special category data (health, religion, sexuality) needs extra safeguards, and data from children needs particular care around consent and age verification.
- ICO registration: most businesses processing personal data need to pay the data protection fee unless a specific exemption applies, so check your status rather than assuming.
Worth flagging too: the Data (Use and Access) Act 2025 has made some changes to cookie rules and breach reporting timelines, tweaking rather than replacing the existing framework. It’s still bedding in, so treat ICO guidance as the up-to-date word on anything DUAA-related.
How to write a clear, layered privacy notice: step by step
Before you write a word, gather your facts. You need a data map (what you collect and from where), a list of processors (your hosting provider, email tool, payment gateway), your retention periods, your lawful basis for each purpose, and a contact point for privacy queries.
Then build it in layers, following the structure the ICO recommends:
- Draft the short notice first: a few sentences covering what you collect, why, and how to contact you.
- Write the full policy second: expand on lawful basis, retention, third parties and rights.
- Add just-in-time notices at each data collection point, forms, checkout, newsletter signups.
- Link everything together: short notice links to the full policy, full policy links to your cookie settings.
Copy-ready lines you can adapt straight away:
- Purpose statement: “We use your details to process your order and keep you updated on its progress.”
- Contact line: “Questions about your data? Email us at [address] or write to [address].”
- Cookie banner short wording: “We use cookies to make the site work and, with your permission, to understand how it’s used. You can change your mind anytime.”
Placement matters as much as wording. Your privacy notice link belongs in the footer, on every page, not buried in a menu three clicks deep. Forms need a one-liner next to the submit button, not a link that opens a new tab and loses the customer halfway through booking. On mobile, that’s doubly true: nobody’s reading four paragraphs on a five-inch screen before they’ll fill in a callback form.
Handling a data breach: reporting and recordkeeping
If personal data gets exposed, lost or accessed without permission, you’re on the clock. Under ICO guidance on reporting a breach, you must report a notifiable breach within 72 hours of becoming aware of it, even if you don’t yet have the full picture.
A partial report beats no report. Submit what you know within 72 hours, then follow up with more detail as your investigation continues, the ICO expects and accepts phased updates.
- Notify affected individuals when the breach poses a genuinely high risk to their rights and freedoms, not for every minor slip.
- Document every decision, including any decision not to report, because the ICO can ask to see your reasoning later.
- Keep an internal log of what happened, when you spotted it, and what you did about it.
- Work through it in order: detect the issue, contain it, assess the risk, notify where needed, then review what let it happen.
Pro Tip: Don’t wait until you’ve “got all the facts” before contacting the ICO. Treating investigation as a reason to delay the 72-hour deadline is one of the most common and costly mistakes small businesses make.
A practical checklist and template you can use today
Here’s a one-page checklist worth printing and keeping by your desk:
- Privacy notice published and linked in your footer, on every page.
- Cookie banner set up with genuine accept/reject choices, no pre-ticked boxes.
- Data map showing what you collect, where it’s stored and who processes it.
- Retention periods set for each data type, with a review date.
- Contact details for privacy queries clearly listed.
A short layered template to build from: “We are [business name]. We collect [data types] to [purpose]. Our lawful basis is [basis]. We keep this data for [period]. Contact [email] for questions or to exercise your rights, or complain to the ICO. Full policy: [link].”
If you outsource your build, according to qualitative findings from the UK Business Data Survey 2024, many small businesses hand their cookie and privacy setup to their website provider and simply assume it’s been done properly. That’s a reasonable thing to delegate, but it’s worth asking your provider directly what’s been implemented and requesting evidence of how consent is logged.
At BasicBS, every website build includes a compliant cookie banner and a privacy notice framework as standard, alongside managed UK hosting and SSL. If you’re checking a provider’s work, ask three things: is there a written contract covering data processing and security, how is consent evidence stored, and can they show you the cookie policy they’ve set up on your behalf.
Our take: most sites overcomplicate this
Here’s the bit nobody tells small business owners: your privacy policy doesn’t need to be clever. It needs to be true, current, and short enough that someone actually reads it. We see far too many sites with a 3,000-word policy copied from a template in 2019, still referencing cookie rules that have since moved on, while the actual cookie banner underneath still pre-ticks the marketing box.
The conventional advice obsesses over legal completeness. Fair enough, that matters. But completeness without honesty is worthless: a policy that lists every lawful basis correctly while your banner ignores “reject all” isn’t compliant, it’s decoration.
Prioritise this: get your cookie banner actually working before you polish your policy wording. Then check what your website provider set up, don’t assume. A five-minute audit of your own site, done today, will tell you more than another read-through of legal text.
— Rhys
FAQ
Do you legally have to have a privacy policy on your website?
Yes, if your website collects any personal data, including through contact forms, newsletters or analytics cookies, UK GDPR and the Data Protection Act 2018 require a privacy notice. There’s no exemption for sole traders or small businesses based on size alone.
What are the legal requirements for a UK website?
A UK website handling personal data needs a privacy notice covering who you are, what data you collect, your lawful basis, retention periods and people’s rights, alongside PECR-compliant cookie consent. The ICO’s privacy notice guidance sets out exactly what to include.
Is there a privacy law in the UK?
Yes, UK GDPR and the Data Protection Act 2018 form the core framework, with PECR governing cookies and electronic marketing separately. The Data (Use and Access) Act 2025 has since updated some provisions around cookies and breach reporting.
Can you provide an example of a privacy policy in the UK?
A short example line reads: “We collect your name and email to respond to enquiries. We don’t sell your data. Read our full policy here.” The ICO offers a privacy notice generator that small businesses can use to build a complete policy from scratch.