Skip to content
Varsuite
Back to blog
Security

GDPR Basics for Small Business Websites: What You Must Have in Place

A plain English guide to GDPR for small business websites: privacy policies, cookie consent, forms and data handling, plus how Varsuite builds it in.

Jamie Woodruff Technical Director 20 Sep 2026 7 min read
Security

GDPR for small business websites comes down to four practical things: a privacy policy that says what you actually do with data, cookie consent that loads tracking scripts only after a visitor agrees, forms and storage that keep personal data secure and minimal, and a written record of what you collect and why. If you have those in place, you are meeting the core of UK data protection law. If you are missing any of them, you have a problem worth fixing this week, not next quarter.

I am the Technical Director at Varsuite. We design, build and run websites for UK businesses, and data protection is one of those areas where the details matter more than the paperwork. Most small businesses do not get caught out because they meant harm. They get caught out because a contact form quietly emails personal details to an unsecured inbox, or a cookie banner sets analytics cookies before anyone clicks accept.

Let me walk through what actually needs to be in place, in the order I would tackle it.

What does GDPR require from a small business website?

The law does not care about your headcount. It cares about whether you process personal data, and almost every website does. A name and email in a contact form is personal data. A newsletter list is personal data. An IP address logged by your server is personal data. Even a simple enquiry that lands in your inbox counts.

Your website needs five things:

  1. A privacy policy that names what you collect, why, how long you keep it, and who you share it with.
  2. A lawful basis for each type of processing, usually legitimate interests or consent.
  3. Cookie consent that blocks non-essential cookies until the visitor agrees.
  4. Secure handling of anything submitted through forms, including safe storage and safe email delivery.
  5. A way for people to ask what you hold about them, and to have it deleted.

That is the whole list. Everything else is detail.

What must a privacy policy actually say?

A privacy policy has to be specific. The generic templates you find online often describe a business that is not yours, which is worse than having nothing at all because it is inaccurate.

A usable policy covers: the identity of your business and how to contact you, the categories of data you collect, the purpose for each category, the legal basis, how long you retain it, who else sees it (your hosting provider, email platform, accountant), whether anything goes outside the UK, and the rights a person has over their data. Add a date and keep it current.

Write it in plain English. There is no requirement to sound like a solicitor. A policy a customer can actually read is doing its job better than one written to impress a regulator.

How should cookie consent work on a small business site?

Cookie consent is where most small sites fail. The rule is simple: no non-essential cookie or tracking script runs until the visitor has actively agreed.

That means your analytics, advertising pixels, heatmaps and chat widgets must not fire on page load. They fire after consent. A banner that says "by continuing to browse you accept cookies" is not valid consent, and neither is a banner where accept is easy and reject is buried.

Practical steps that work:

  • Run an audit of every script on the site and list what each one sets.
  • Group them into essential and non-essential.
  • Block non-essential scripts until consent is given.
  • Give accept and reject equal prominence.
  • Let people change their mind later, and log the consent you received.

If you use Google Analytics or Google Ads, this matters directly. You can read more about how we handle tracking and measurement in our overview of SEO and AIO automation.

What about contact forms and the data they collect?

Forms are the most common place small businesses leak personal data. Three failure modes I see regularly: forms that email submissions to a personal inbox, forms that store every entry forever in the site database, and forms that collect far more than they need.

The fixes are not complicated. Send form notifications over an encrypted connection and to a shared business mailbox rather than a personal one. Give submissions a retention period, and delete them automatically once it passes. Ask only for what you genuinely need. If you do not use a phone number, do not ask for one.

Anything stored on the site should sit behind proper access control. That usually means a database only the application can reach, with no public exposure. If you are collecting anything sensitive, such as health information or financial details, the bar goes up considerably and it is worth having that conversation early.

We build forms, storage and access controls as a single piece of work rather than bolting security on afterwards. Our websites service covers the build, and where a site needs to handle more complex data flows we bring in data integrations so records move between systems without being duplicated or left lying around.

Do I need to worry about security, or just paperwork?

Security is not separate from GDPR. It is the part that stops a data breach becoming a reportable incident. Article 32 of the UK GDPR requires appropriate technical measures, and for a small business website the practical list is short.

Keep your CMS and plugins patched. Use HTTPS everywhere. Use strong, unique passwords with two factor authentication on admin accounts. Take backups and test that they restore. Limit who has admin access. Do not leave staging sites publicly reachable.

We run security monitoring and code scanning on the sites we manage, because a site can be compliant on paper and still be wide open in practice. The two only work together.

How does Varsuite handle GDPR in a build?

We treat data protection as part of the build, not a document handed over at the end. When we design a site, the questions are asked up front: what personal data does this collect, where does it go, who can see it, and how long does it live?

AI agents in our process generate the privacy policy, the cookie configuration and the consent logic from the actual site behaviour rather than a template. That means the policy describes the site you have, not a generic one. A human then reviews every line before it ships, which is where the accuracy comes from.

We also build the operational side. Consent logs, retention rules and delete requests are handled by the system rather than remembered by a person. If you want to see how that fits into a wider build, our services overview sets out the full picture.

For most small businesses, getting GDPR right takes a few days of focused work, not months. The cost of getting it wrong, in trust and in fines, is far higher than the cost of doing it properly the first time.

Frequently asked questions

Do I need a privacy policy if my website is tiny?

Yes, if you collect any personal data at all. A contact form, a newsletter signup or analytics tracking all count. The policy needs to describe what you actually do, so keep it short and accurate rather than long and generic.

Is a cookie banner enough on its own?

No. The banner is only the front end. You also need the technical setup that blocks non-essential scripts until consent is given, records the consent, and lets people withdraw it later. A banner with nothing behind it is decoration.

How long can I keep form submissions?

There is no single number in law. You keep data only as long as you need it for the purpose you collected it. For most enquiries, that is weeks or months, not years. Decide a period, write it in your privacy policy, and automate the deletion.

Do small businesses ever get fined?

Fines are possible, but the bigger everyday risk is a breach you cannot explain, or a customer who asks what you hold about them and gets no answer. Good records and sensible security solve both problems before they arrive.

JW
Written by
Jamie Woodruff
Technical Director

Jamie is Technical Director at Varsuite and leads the technical development team, setting how we design and build everything we ship. He builds the AI models that power our agents and manages the AI s...

More from Jamie Woodruff

Get The Signal

Practical notes on AI, websites and automation for UK businesses. One useful email at a time, unsubscribe whenever.

What is The Signal?

About Varsuite

Varsuite is an AI-accelerated, human-perfected digital production company based in Rishton, Lancashire. Agents build, people perfect: websites, stores, software and AI automation.

Ready to put AI to work?

Let our agents design, build and manage it for you.

Start a build