Skip to main content

All articles

GDPR and Cookie Consent for UK Small Business Websites

Running & maintaining 8 min read

Cookie banners have become the most misunderstood box on the modern web. Some small business sites bolt on an enormous consent pop-up they don't need; others quietly break the law with a single line saying "by using this site you accept cookies". Neither is right. Here's what UK GDPR and PECR actually ask a small business website to do, and how to get it right without overengineering it.

Two laws, not one

People talk about "GDPR cookies" as if it's one rule, but there are actually two pieces of law working together. UK GDPR governs how you handle personal data generally — contact forms, customer records, email lists. The Privacy and Electronic Communications Regulations (PECR) specifically govern cookies and similar tracking technologies, and it's PECR that requires consent before you set most cookies at all.

In practice this means a small business website needs to think about consent twice: once for whether a cookie can be set in the browser at all, and again for what happens to any personal data that cookie or your forms then collect. Most compliance failures come from focusing on the banner and completely ignoring the second half.

Essential vs non-essential cookies

Not every cookie needs permission. The law draws a fairly clear line:

  • Strictly necessary cookies — things like a shopping basket, a login session, or a cookie that remembers the visitor's consent choice itself. These can be set without asking, because the site literally cannot function without them.
  • Non-essential cookies — analytics (Google Analytics, Hotjar), advertising and retargeting pixels (Meta, Google Ads), and third-party embeds that set their own cookies (YouTube videos, some booking widgets, live chat tools). These all require prior, informed consent before they load.

The word "prior" is doing a lot of work there. It's not enough to load analytics on every visit and only remove it if someone objects — the script must not run until the visitor has actively said yes. This is the single most common thing we find broken when we audit an existing small business site: Google Analytics or a Facebook pixel firing on page load, with a cookie banner sitting underneath it doing nothing.

What a compliant banner actually looks like

The Information Commissioner's Office (ICO) has been increasingly clear about what does and doesn't count as valid consent. A compliant banner needs to:

  • Give a genuine "Reject all" option that's just as easy to find and click as "Accept all" — not buried in a secondary settings screen while accept is a single big button.
  • Have no boxes pre-ticked for non-essential categories. Consent has to be an active, opt-in choice, not something the visitor has to notice and switch off.
  • Explain, in plain language, what the cookies actually do — not just "we use cookies to improve your experience", which tells a visitor nothing.
  • Let someone withdraw consent later, usually via a small "cookie settings" link in the footer.
  • Not block access to a basic informational or brochure site until the visitor chooses. Cookie walls are only defensible in narrow circumstances, and for a typical small business site — a plumber, a dentist, a shop — there's rarely a case for one.

If your current banner has a bright green "Accept" button and a barely visible grey "Manage preferences" link with reject three clicks deep, it doesn't meet that bar, however professional it looks.

What your privacy policy needs to say

A cookie banner handles consent at the point of visiting. A privacy policy is the fuller explanation of what happens to someone's data after that, and UK GDPR requires every site collecting personal data to have one — that includes a simple contact form, not just sites with logins or checkouts.

At minimum it should cover:

  1. What personal data you collect (name, email, phone number, IP address via analytics) and how.
  2. Why you collect it and the lawful basis — usually "legitimate interest" for responding to an enquiry, or "consent" for marketing emails.
  3. How long you keep it, and roughly when it gets deleted.
  4. Who else sees it — your email provider, hosting company, CRM, any marketing platform.
  5. How someone requests a copy of their data or asks you to delete it.

The ICO publishes a free small business privacy notice template, and for most sites we build it's a case of adapting that rather than starting from nothing. It doesn't need to be long or written by a solicitor — it needs to be accurate.

Contact forms, retention and the bits people forget

The area we see go wrong most often isn't the banner at all — it's what happens after someone submits a contact form. Enquiries land in an inbox and sit there indefinitely, get forwarded to a personal Gmail account, or feed into a spreadsheet nobody's ever reviewed for old entries. None of that is inherently illegal, but it's hard to justify keeping someone's phone number for three years after a one-off quote request, and it's exactly the kind of thing a complaint or data request will expose.

A sensible, low-effort approach: decide roughly how long you genuinely need enquiry data (a year is common for a small trades or service business), note that figure in your privacy policy, and periodically clear out anything older. If you're on a managed hosting plan with us, this is the kind of housekeeping we can build into routine maintenance rather than leaving it to chance.

If your site doesn't track anything, you don't need a banner

This is the point that gets lost in all the compliance noise: if your website is a straightforward set of pages with no analytics, no advertising pixels, and no third-party embeds that set cookies, you don't need a cookie banner at all. Plenty of the hand-coded static sites we build fall into exactly this category — fast, simple, nothing to track, nothing to consent to.

The moment that changes is the moment you add Google Analytics, a Facebook pixel, a booking widget, or an embedded YouTube video — at which point you're back to needing proper consent, not the moment before. It's worth reviewing what's actually running on your site before assuming you need the full machinery. We go through this as standard as part of any new website design project, alongside the basics covered in is your website secure — cookie compliance and site security tend to get audited at the same time, for the same reason: nobody's looked at either since launch.

Common questions

Does my small business website need a cookie banner?

Only if it sets non-essential cookies — analytics, advertising or embedded third-party content. A site with no tracking and no embeds doesn't need a consent banner at all.


Is Google Analytics allowed under UK GDPR?

Yes, with prior consent, because its cookies are non-essential. That means analytics must not load until the visitor has actively agreed.


What does a privacy policy need to say?

What data you collect, why, the lawful basis, how long you keep it, who else sees it, and how someone requests a copy or deletion. The ICO publishes a free small business template.


Is 'by using this site you accept cookies' enough?

No. Implied consent hasn't been valid for years. Consent must be an active choice, and refusing must be as easy as accepting.

Want a website that does this automatically?

Our managed plans handle the domain, SSL, updates, backups and edits so you never have to think about it. Free, no-pressure chat — usually within a day.

Part of our running & maintaining guides.

Written by Adam, A9 Web Design

Adam builds hand-coded websites for small businesses across Cambridgeshire and looks after their hosting, SEO and advertising day to day. Everything here comes from work on real client sites — no theory, no filler.

Start a conversationGet a quote