What to Include in a Small Business Website Privacy Policy (UK)

What to Include in a Small Business Website Privacy Policy (UK)

If your website has a contact form, a newsletter signup, or even just analytics tracking, you are collecting personal data. In the UK, that means you almost certainly need a privacy policy, whatever the size of your business.

Direct answer: a UK small business privacy policy needs to explain who you are, what personal data you collect, why you collect it, how long you keep it, who you share it with, and what rights visitors have under UK GDPR. It should sit at a stable URL, linked from your footer and any page that collects data. This guide explains what to cover and where it fits into your website build, without acting as a substitute for tailored legal advice.

Do I actually need a privacy policy?

In practice, yes, for almost every small business website. UK GDPR and the Data Protection Act 2018 require transparency whenever you collect personal data, and that threshold is lower than most business owners assume. It covers:

  • Contact form submissions
  • Newsletter or email signups
  • Website analytics, such as Google Analytics
  • Online bookings or enquiries
  • Cookies that track visitor behaviour

Even a simple brochure site with just a contact form and basic analytics falls under this requirement. There is genuinely no small-website exemption.

What the policy needs to cover

1. Who you are

State your business name and how visitors can contact you about privacy questions specifically. This is usually a dedicated email address rather than your general enquiries inbox.

2. What data you collect

List the categories of personal data you actually collect, not a generic list copied from elsewhere. Common examples for a small business site: name, email address, phone number, IP address, and any information submitted through forms.

3. Why you collect it

Explain the purpose for each type of data. A contact form email address is collected to respond to enquiries. Analytics data is collected to understand how visitors use the site. Being specific here is both a legal requirement and genuinely reassuring to visitors.

4. How long you keep it

State a retention period, even an approximate one, for each category of data. Keeping data indefinitely without a stated reason is a common compliance gap.

5. Who you share it with

If you use third-party tools, such as an email marketing platform or a booking system, name them or at least the category of service, since visitor data passing through those tools is part of what your policy needs to disclose.

6. What rights visitors have

Under UK GDPR, individuals have rights to access, correct, delete, and object to the use of their data. Your policy should explain these rights in plain terms and how someone can exercise them.

7. Cookies

If your site uses cookies beyond the strictly necessary kind, this typically needs separate consent under PECR rules, alongside disclosure in the policy itself.

A simple structure to follow

Section What to include
Who we are Business name, contact details for privacy queries
What we collect Specific categories of personal data, not a generic list
Why we collect it The purpose behind each category
How long we keep it A stated retention period
Who we share it with Named tools or categories of third party
Your rights Access, correction, deletion, objection, in plain English
Cookies What you use them for, and how consent is handled
Last updated date Keep this visible and current

Where it fits into your website build

Your privacy policy is one of the legal pages worth planning for from the start rather than bolting on after launch. If you are working from a website design brief, flag it alongside your other page requirements so a developer can build the footer link and cookie consent mechanism into the site from day one, rather than retrofitting it later. It should also appear in your essential pages list alongside Home, About, Services and Contact, even though it will not appear in your main navigation.

Common mistakes

  • Copying a template word for word. A policy needs to reflect what your business actually does. A mismatch between your stated practices and your real ones creates genuine legal risk.
  • Burying it where nobody can find it. It should be linked from your footer on every page, not just a single obscure link.
  • Never updating it. If you start using a new tool, add a new form, or change how you handle data, your policy needs to reflect that.
  • Confusing it with a cookie policy. These often sit together but cover slightly different things, and some sites need both.

When to get professional legal help

This guide covers what a privacy policy needs to include and where it fits into your website, but it is not a substitute for tailored legal advice. If your business handles sensitive data, operates across multiple countries, or you are simply not confident drafting the wording yourself, a solicitor or a specialist legal service can prepare a policy tailored to exactly what your business does.

FAQs

Do all UK websites need a privacy policy? Almost all business websites do, since even basic analytics or a contact form counts as collecting personal data under UK GDPR. There is no general small-business exemption.

What happens if my website doesn’t have a privacy policy? You risk non-compliance with UK GDPR, which the ICO can enforce, and you also undermine visitor trust, since an increasing number of people specifically check for one before submitting personal information.

Is a privacy policy the same as a cookie policy? Not always. A privacy policy covers how you handle personal data generally, while a cookie policy specifically addresses tracking technologies. Many small sites cover both within a single combined policy.

Can I write my own privacy policy? You can, and this guide explains what to include, but a self-written policy carries more risk if it does not accurately reflect your practices or misses a legal requirement. For anything beyond a very simple site, professional review is worth the investment.

progressd Avatar
No comments to show.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

Insert the contact form shortcode with the additional CSS class- "wydegrid-newsletter-section"

By signing up, you agree to the our terms and our Privacy Policy agreement.