Cookie banners have become the most misunderstood box on the modern web. Some small business sites bolt on an enormous consent pop-up they don't need; others quietly break the law with a single line saying "by using this site you accept cookies". Neither is right. Here's what UK GDPR and PECR actually ask a small business website to do, and how to get it right without overengineering it.
Two laws, not one
In practice this means a small business website needs to think about consent twice: once for whether a cookie can be set in the browser at all, and again for what happens to any personal data that cookie or your forms then collect. Most compliance failures come from focusing on the banner and completely ignoring the second half.
Consent mode and analytics without breaking the rules
If you're using Google Analytics to understand where your traffic comes from — something we'd generally recommend, and cover in our guide to checking your website traffic — the practical setup is: consent banner loads first, nothing analytical fires until "Accept" is clicked, and the choice is remembered so returning visitors aren't asked every time.
What your privacy policy needs to say
At minimum it should cover:
- What personal data you collect (name, email, phone number, IP address via analytics) and how.
- Why you collect it and the lawful basis — usually "legitimate interest" for responding to an enquiry, or "consent" for marketing emails.
- How long you keep it, and roughly when it gets deleted.
- Who else sees it — your email provider, hosting company, CRM, any marketing platform.
- How someone requests a copy of their data or asks you to delete it.
The ICO publishes a free small business privacy notice template, and for most sites we build it's a case of adapting that rather than starting from nothing. It doesn't need to be long or written by a solicitor — it needs to be accurate.
Contact forms, retention and the bits people forget
A sensible, low-effort approach: decide roughly how long you genuinely need enquiry data (a year is common for a small trades or service business), note that figure in your privacy policy, and periodically clear out anything older. If you're on a managed hosting plan with us, this is the kind of housekeeping we can build into routine maintenance rather than leaving it to chance.
Common questions
Does my small business website need a cookie banner?
Only if it sets non-essential cookies — analytics, advertising or embedded third-party content. A site with no tracking and no embeds doesn't need a consent banner at all.
Is Google Analytics allowed under UK GDPR?
Yes, with prior consent, because its cookies are non-essential. That means analytics must not load until the visitor has actively agreed.
What does a privacy policy need to say?
What data you collect, why, the lawful basis, how long you keep it, who else sees it, and how someone requests a copy or deletion. The ICO publishes a free small business template.
Is 'by using this site you accept cookies' enough?
No. Implied consent hasn't been valid for years. Consent must be an active choice, and refusing must be as easy as accepting.
Want a website that does this automatically?
Our managed plans handle the domain, SSL, updates, backups and edits so you never have to think about it. Free, no-pressure chat — usually within a day.
Part of our running & maintaining guides.
Written by Adam, A9 Web Design
Adam builds hand-coded websites for small businesses across Cambridgeshire and looks after their hosting, SEO and advertising day to day. Everything here comes from work on real client sites — no theory, no filler.