We build websites, we are not solicitors, and this is general information rather than legal advice. For anything unusual or high risk, the Information Commissioner's Office publishes free guidance for small businesses and it is genuinely readable.
Does it even apply to you?
Almost certainly yes. UK GDPR applies to any business handling personal data, and there is no small business exemption. If your website has a contact form, you are handling personal data.
The good news is that the obligations for a typical local business with a brochure site and a contact form are modest. Most of the anxiety around this comes from guidance written for companies processing data at scale.
Contact forms: the part that matters most
Your form collects a name, an email, probably a phone number and a description of what someone needs. That is personal data and you need three things.
A lawful basis
For someone actively asking you to quote, this is usually legitimate interests or steps prior to entering a contract. You are not required to make them tick a box to be contacted about the thing they just contacted you about.
Transparency
A short line near the form saying what happens to their details, linking to your privacy policy. Something like: "We use these details only to reply to your enquiry. See our privacy policy."
Not keeping it forever
Old enquiries sitting in an inbox for a decade are data you no longer have a reason to hold. Decide roughly how long you keep them and say so in your policy.
Adding a mandatory "I consent to being contacted" tickbox to a contact form. It is usually unnecessary, it reduces enquiries, and consent is often the wrong lawful basis for someone who has just asked you to get in touch.
Cookie banners: when you actually need one
This is where most small sites get it wrong in both directions, either having no banner while running analytics, or bothering visitors with a banner for cookies they do not set.
Under the UK rules, you need consent before setting non-essential cookies. Essential ones, such as those making a form or basket work, do not need consent.
- Plain brochure site, no analytics, no embeds: you very likely need no banner at all
- Google Analytics: non-essential. Consent needed before it loads
- Facebook or ad pixels: non-essential, and the most scrutinised of the lot
- Embedded YouTube, maps or social feeds: these usually set third party cookies on load
If your banner says "by continuing to browse you accept cookies", that is not valid consent. Continuing to scroll is not agreement.
The simplest way to avoid the problem
Do not load non-essential things you do not need. A lot of small sites carry an analytics tag nobody has looked at in two years, an embedded map that could be a link, and a social feed that slows the page down. Removing them is faster, better for privacy, and takes the cookie question off the table entirely.
Your privacy policy
You need one, it needs to be reachable from every page, and it needs to actually describe what you do rather than being a template with someone else's business name in it.
For a typical local business it should cover:
- Who you are and how to contact you
- What you collect, which is usually form submissions and possibly analytics
- Why, and your lawful basis for it
- Who else sees it. Your form provider, your email host, your hosting company. Name them
- How long you keep it
- People's rights, including access, correction and deletion
- How to complain, including to the ICO
That last point about third parties catches people out. If your contact form goes through a service, that service processes your visitors' data and should be named.
Do you need to register with the ICO?
Many organisations processing personal data must pay the ICO's data protection fee, which starts at a modest annual figure for small businesses. There are exemptions, and the ICO has a short self assessment on its site that tells you in about two minutes. Worth doing rather than guessing.
A practical checklist
- Privacy policy exists, is specific to you, and is linked from every page
- Contact form has a one line note about what happens to the details
- No unnecessary mandatory consent tickbox on the enquiry form
- You know which non-essential cookies your site sets, if any
- If it sets any, consent is requested before they load, with a genuine reject option
- Third parties handling data are named in the policy
- You have decided how long you keep enquiries
- You have checked the ICO self assessment on the registration fee
- Your site runs over HTTPS, so form submissions are encrypted
That last one is easy to forget and easy to check: look for the padlock in the address bar. A contact form on an unencrypted page sends personal data in the clear.
Ours is set out on our privacy policy if you want to see a working example rather than a template. If you would rather someone just handled it, get in touch, and what a website needs covers the rest of the essentials.