© 2026
UK GDPR Isn't Optional
Data protection law applies to a five-page brochure site just as much as it does to a bank. The basics are simpler than you think, and skipping them is riskier.
LAWFUL.
Compliance built in, not bolted on
If your website has a contact form, an analytics tag, or a newsletter signup, you're processing personal data, and UK GDPR applies to you.
Small businesses often assume data protection law is something for corporations with legal departments. It isn't. UK GDPR and PECR (the rules covering personal data and electronic marketing) apply to every business website, whatever its size. The good news: for most small sites, compliance is a well-understood checklist, not a legal odyssey.
The two sets of rules
UK GDPR governs how you collect, store and use personal data: names, emails, phone numbers, anything that identifies a person. PECR sits alongside it and covers cookies and electronic marketing: when you can set tracking cookies, and when you can email or text people with marketing. Most website compliance questions are answered by one of the two.
What every small business site needs
A privacy policy that describes what you actually collect and why, not a copied template that mentions tools you've never used
Cookie consent that blocks non-essential cookies until the visitor agrees
A lawful basis for any marketing emails, and a working unsubscribe
Forms that collect only the data you genuinely need
A way to answer someone who asks what data you hold about them
Consent means consent
The rules on consent are stricter than most cookie banners suggest. Pre-ticked boxes don't count. "By using this site you agree" doesn't count. Rejecting cookies must be as easy as accepting them. A banner with a bright Accept button and a maze behind "Manage preferences" doesn't meet the standard. Analytics tags should simply not fire until someone has said yes.
The cost of ignoring it
The ICO, the UK regulator, can fine up to £17.5 million or 4% of global turnover for the most serious breaches. Enforcement against small businesses is rarer and usually starts with complaints about marketing emails or texts, but the reputational cost arrives sooner: customers notice sites that handle data carelessly, and so do the larger businesses you want to work with.
Build it in, don't bolt it on
Compliance is cheapest at build time. A site designed with a truthful privacy policy, honest consent, and minimal data collection barely notices the regulations. Retrofitting the same standards after a complaint is when it gets expensive. Treat it like structural work, not decoration.
Scoped, priced and agreed before anything starts. Built properly from day one.
Send one email and we'll reply within a working day with whether we can help, roughly what it costs, and what we'd do first. No sales call required.
You do. Every build is documented and handed over: you get the keys and the manual. No hostage-taking.
It depends on scope. Every build starts with a written proposal that sets out a clear timeline before work begins, and if it changes, we tell you.
Every build includes a 30-day defect warranty: if we broke it, we fix it free. It's in our terms, in writing.
No. We handle the technical side end to end and explain everything in plain English. Documentation and handover come as standard.