Cookie Policy Generator for small businesses
Written for a website, a contact form, a mailing list and a card machine - and nothing more elaborate.
Most small business sites run three or four cookies and could describe them in half a page. The reason they usually have no cookie policy is that nobody looked - not that the site is complicated.
Small businesses are subject to the same transparency obligations as large ones, and they usually meet them with a copied policy that describes a company they are not. The result is a document that names cookies the site does not set, promises procedures nobody runs, and misses the one thing the business actually does with personal data.
The realistic processing set for a small business is short: enquiries through a form or an inbox, a customer list for invoicing, a mailing list if there is one, card payments through a terminal or gateway, and a website with analytics. Describing those five things accurately produces a better document than any template.
The obligations people underestimate are the ones outside the privacy policy: the ICO registration fee in the UK, retention of accounting records, and the fact that CCTV on business premises is processing with its own signage and access requirements.
What a cookie policy for a small business has to cover
Analytics cookies and the provider behind them
Any embed - maps, booking widgets, social feeds - and its cookies
Which cookies are strictly necessary and which are not
How consent is captured and changed
How a small business actually moves personal data
Enquiries by form, email and phone
Name and contact details held in an inbox indefinitely unless someone decides otherwise.
Customer records and invoicing
Held in accounting software, retained for statutory periods.
Mailing lists
Often built informally from customers and enquiries, with no consent record behind them.
Card payments
Through a terminal or online gateway, with the provider handling card data.
Website analytics
Usually Google Analytics, installed once and never revisited.
CCTV on premises
Processing of images of identifiable people, with signage and retention duties attached.
Third parties the draft will ask you about
Xero, QuickBooks or Sage · SumUp, Zettle or Stripe · Google Workspace or Microsoft 365 · Mailchimp · a website host · a CCTV provider
The rules that apply
Transparency regardless of size
No small-business exemption in UK or EU data protection law. The obligations follow the processing.
ICO registration in the UK
Most businesses processing personal data by automated means must pay the annual data protection fee.
Marketing consent rules
PECR and equivalents apply to a mailing list of fifty as much as to one of fifty thousand.
CCTV and premises monitoring
Processing with its own signage, retention and subject access implications.
Accounting record retention
Statutory periods that justify keeping some customer data after the relationship ends.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
A realistic small-business checklist
List what you actually collect
Enquiries, customers, mailing list, payments, website, CCTV. Five or six lines.
Write the policy from that list
Rather than editing someone else’s.
Pay the ICO fee if you are UK-based
And set an annual reminder.
Fix the mailing list
Suppress anything you cannot evidence and re-collect consent.
Add a cookie notice if you run analytics
And make it actually block until consent.
Set retention for enquiries and CCTV
And apply it.
Where this usually goes wrong
A copied policy describing tools you do not use
The most common small-business failure, and easy for anyone to spot.
A mailing list built without consent records
Adding customers to a newsletter because they bought something is only permitted under narrow soft opt-in conditions.
Not paying the ICO fee
A separate legal duty from anything in the policy, checked against a public register.
Enquiry emails kept forever
There is no purpose after the enquiry is closed and any follow-up window has passed.
CCTV with no notice or retention rule
Signage is required, and footage kept indefinitely is difficult to justify.
Analytics running with no cookie notice
A small site with GA4 and no banner is the single most common finding in the UK.
Frequently asked questions
Does a small business need a privacy policy?
Yes if it processes personal data, which a contact form or a customer list already does. There is no exemption based on size or turnover in the UK or EU.
Do I need to register with the ICO?
Most UK businesses processing personal data by automated means do. The fee is tiered by size and turnover and is enforced separately from other obligations.
Can I email past customers about offers?
Only under the soft opt-in - your own similar products, to someone who bought from you, with an opt-out offered at the time and in every message - or with consent.
Do I need a cookie banner for a small website?
If it runs analytics or any third-party embed, in the UK and EU yes, and it needs to hold those tags until consent is given.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator for small businesses
Answer a short questionnaire and get a draft written for a small business. Free to start, no card required.
Generate your cookie policyOther documents a small business needs
Each one is written for the same context, not a generic template.
The same document, by business type
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.