PolicifyAI
Published July 2026 · 3 min read
Privacy Policy for a Small Business Website: What UK Law Actually Requires
A contact form is enough to trigger UK GDPR's transparency rules. The eight things your website privacy policy must cover - and the copied-template mistakes that get small businesses in trouble.
The threshold is lower than you think
You do not need a checkout, a login system, or a mailing list to need a privacy policy. If your website has any of the following, you are collecting personal data and UK GDPR's transparency rules (Article 13) apply:
- A contact or quote-request form
- A booking or appointment widget
- Analytics (Google Analytics or similar)
- An embedded map, video, or social feed that sets cookies
- A phone number that customers call - because you will note their details somewhere
That covers essentially every business website in the UK. There is no small business exemption from transparency: the duty is the same for a plumber's one-page site and a national retailer. What differs is how much there is to explain.
What the law actually asks for
UK GDPR requires that, at the time you collect someone's data, you tell them - in concise, clear, plain language - who you are, what you collect, why, on what legal basis, who you share it with, how long you keep it, and what rights they have. PECR adds the cookie rules: non-essential cookies need opt-in consent. A privacy policy linked from every page, plus a compliant cookie banner if you need one, satisfies both.
The eight sections your policy needs
- 1. Who you are: trading name, legal entity, and a monitored contact email - not a dead inbox
- 2. What you collect: be concrete -"name, email address and message contents when you use our contact form; usage data via analytics cookies"
- 3. Why and on what lawful basis: responding to enquiries (legitimate interests or pre-contract steps), sending marketing (consent), keeping invoices (legal obligation)
- 4. Who you share it with: your hosting provider, form or booking tool, email provider, accountant - name the important ones
- 5. International transfers: if any tool stores data outside the UK (many do), say so and name the safeguard
- 6. Retention: real periods -"enquiries deleted after 12 months; invoices kept 6 years as required by tax law". "As long as necessary" on its own is the phrase the ICO explicitly warns against
- 7. Rights: access, correction, deletion, objection, withdrawal of consent - and how to exercise them with you
- 8. Complaints: the right to complain to the ICO, with a link
The five mistakes that get small businesses in trouble
- Copying a US template. If your policy cites CCPA and never mentions UK GDPR or the ICO, it describes the wrong legal system - and signals to anyone checking that it was pasted
- Describing someone else's practices. A copied policy that lists tools you don't use (and misses ones you do) is worse than useless: it is inaccurate disclosure, which is itself a breach
- No lawful basis anywhere. The most common structural omission - every purpose needs one
- A contact route nobody monitors. Rights requests have a one-calendar-month deadline; an unwatched inbox quietly burns it
- Never updating. Added live chat? A newsletter? New analytics? Each changes what your policy must say. Review it whenever your stack changes, and at least annually
Cookies: you may need a banner - or you may not
The banner is only required for non-essential cookies. A brochure site with no analytics and no embedded third-party content does not need one at all - and removing analytics you never look at is a legitimate simplification strategy for very small sites. If you do run analytics or marketing pixels, consent must be opt-in, "Reject" must be as easy as "Accept", and the details belong in a cookie policy.
Plain English beats legalese
The ICO's guidance is explicit: transparency information must be understandable to your actual audience. A policy your customers can read in five minutes protects you better than ten pages of borrowed legal boilerplate - clarity is a compliance requirement, not a style preference. Write it once, properly, matched to what your website really does - a generator built for UK small businesses gets you there in minutes, and then it is just maintenance.
Frequently asked questions
My website is just a brochure with a contact form. Do I really need a policy?
Yes. A contact form collects names and email addresses, which is personal data processing under UK GDPR - the transparency duty applies from the first submission.
Can I copy a privacy policy from another website?
No. It will describe their tools, purposes, and retention, not yours - inaccurate disclosure is itself a compliance failure, and it is the most common mistake the ICO sees in small business policies.
Where should the policy live?
Linked from the footer of every page, and referenced next to every form that collects data. Users must be able to find it at the point of collection.
Need a policy for your business?
Generate a legally-formatted, AI-reviewed policy in under 60 seconds.
Generate your policy