Skip to content
Varsuite
Back to blog
Security

GDPR for Small Business Websites: What You Must Have in Place

GDPR for small business websites means a clear privacy policy, cookie consent, and secure form handling. Here's the plain English checklist.

Jamie Woodruff Technical Director 3 Aug 2026 9 min read
Security

GDPR for small business websites comes down to one simple idea: know what personal data you collect, tell people clearly, and handle it securely. You do not need a legal degree to comply. You need a privacy policy, working cookie consent, and straightforward form practices. This article is your plain English checklist, written for a UK business owner, not a lawyer.

I am Jamie Woodruff, Technical Director at Varsuite. We build and manage websites for UK businesses, and we see the same GDPR gaps time and again. The good news is that fixing them is not expensive or complicated. This guide explains what you must have in place, and how we help our clients get there.

What is GDPR and does it apply to my small business website?

Yes, GDPR applies to any business that collects or processes personal data from people in the UK or EU, regardless of size. If your website has a contact form, an email newsletter signup, an online store, or even a simple analytics tool, you are processing personal data.

Personal data means anything that can identify a living person. Names, email addresses, phone numbers, IP addresses, and even cookies that track browsing behaviour all count.

Being small does not exempt you. The ICO (Information Commissioner's Office) can and does act against small businesses. Non-compliance can lead to fines, but more often it leads to reputational damage and lost trust.

What are the three essentials for GDPR compliance?

The quickest way to think about GDPR is in three parts: transparency, consent, and security. You need a privacy policy that explains what you do with data, a consent mechanism that gets proper permission, and forms and storage that keep data safe.

Most websites already have some of this in place, but often it is incomplete or outdated. Let us walk through each part.

Do I need a privacy policy on my small business website?

Yes, you do. A privacy policy is a legal requirement under GDPR. It must tell visitors exactly what personal data you collect, why you collect it, how you use it, who you share it with, and how long you keep it.

It also needs to explain their rights under GDPR, such as the right to access, correct, and delete their data. You must also provide your business name and contact details.

Your privacy policy should be written in clear, simple language. It should be easy to find, usually in the footer of every page.

Many small businesses copy a privacy policy from another website. That is risky because your data practices are probably different. A generic policy might not cover your contact forms, analytics, or email marketing.

When we build a website, we draft a privacy policy based on exactly what the site does. We ask questions about the data you handle, so the policy matches reality.

How does cookie consent work for GDPR?

If your website uses cookies that are not strictly necessary, you need consent before setting them. Strictly necessary cookies include things like shopping cart cookies or login sessions. Analytical cookies, advertising cookies, and marketing cookies all need consent.

Cookie consent means showing visitors a clear banner or popup when they first arrive. It must explain what cookies you use and why. They must be able to accept, reject, or choose which cookies they allow.

The key is that consent must be freely given, specific, informed, and unambiguous. You cannot have pre-ticked boxes. You need a positive action, like clicking an "Accept" button.

You also need to record consent. Keep a log of when and how someone consented, so you can prove it if asked.

Most cookie consent tools handle the technical side for you. But you need to make sure it is set up correctly and matches the cookies your site actually uses. A mismatch is a common compliance failure.

At Varsuite, we configure cookie consent as part of every website we build. We audit the cookies on your site and set the tool to match.

What data do I need to protect on my website forms?

Any form on your website, whether it is a contact form, a newsletter signup, or a checkout, collects personal data. You must protect that data from the moment it is submitted.

First, use HTTPS. That encrypts data in transit. Most websites today have SSL certificates, but you should double check yours is active and applied across all pages.

Second, store data securely. If you are getting form submissions by email, that is risky. Email is not a secure way to handle personal data. Better to store submissions in a secure database with access controls.

Third, minimisation. Only collect the data you truly need. If you do not need a phone number, do not ask for it. That reduces your risk and your obligation.

Fourth, retention. Do not keep data forever. Decide how long you need it and delete it after that. For example, you might keep contact form enquiries for two years, then delete them.

How do I handle data subject access requests?

Under GDPR, individuals can ask for a copy of their personal data, ask for it to be corrected, or ask for it to be deleted. You have one month to respond. This is called a subject access request.

You do not need a complicated system to handle these, but you do need a process. Make it clear on your website how people can make a request, for example via a contact page or email address.

When you receive a request, search your systems for that person's data. Provide it in a readable format. If the request is for deletion, remove their data from your active systems and backups where possible.

Most small businesses get very few of these requests. But having a simple process in place shows good faith and avoids panic when one arrives.

Does GDPR apply to my email marketing?

Yes, email marketing is a core GDPR area. You need consent to send marketing emails, unless you can rely on the "legitimate interests" basis for existing customers, which has conditions.

The safest route is explicit consent. Use a clear opt-in checkbox on your signup forms. Never pre-tick it. And always include an unsubscribe link in every email.

Your email marketing platform should be set up to manage consent and unsubscribes automatically. Most platforms like Mailchimp or Klaviyo have these features built in.

If you buy email lists, be very careful. GDPR requires that consent is specific to you. Bought lists rarely meet that standard, and using them can lead to fines.

What happens if I don't comply with GDPR?

The ICO can issue fines of up to 4% of annual global turnover or £17.5 million, whichever is higher. But for small businesses, fines are usually much lower, often in the thousands. The bigger risk is reputational damage and loss of customer trust.

Non-compliance also means you are not respecting your customers. In a market where trust is a differentiator, that can cost you more than any fine.

How can Varsuite help my small business with GDPR compliance?

At Varsuite, we bake GDPR compliance into every website we build. Because we use AI to accelerate the build, we can take the time to get the legal and technical details right without blowing your budget.

We start with an audit of your existing data practices. Then we create a privacy policy specific to your site. We configure cookie consent tools to match your actual cookies. We make sure your forms and data storage are secure.

If you need an online store, we handle GDPR for checkout, customer accounts, and payment data too. For business systems, we ensure data handling is compliant from the ground up.

Our care plans include ongoing security monitoring and updates, so your compliance stays current as your website evolves.

Prices for websites start from £500 with a £100 per month care plan, and online stores from £1,000 with a £150 per month care plan. Custom software and AI agents start from £1,000. Automated content marketing is from £100 per month.

Conclusion

GDPR for small business websites is not scary. You need a clear privacy policy, proper cookie consent, and secure forms and data handling. Start there, and you will be on the right side of the law and your customers.

If you are unsure whether your website is compliant, ask us for a quick audit. We will tell you what is missing and fix it for you.

Frequently asked questions

Do I need a cookie banner on my website in the UK?

Yes, if your website uses cookies that are not strictly necessary. This includes analytics and advertising cookies. You need to get consent before setting them, so a compliant cookie banner is essential.

Can I copy a privacy policy from another website?

No, you should not. Privacy policies must be specific to your data practices. Copying a generic policy can lead to non-compliance and potential fines.

How long should I keep personal data collected from my website?

Only as long as necessary. There is no fixed time, but you should decide a retention period based on why you collected the data. For example, contact form enquiries might be kept for two years. Delete data you no longer need.

What should I do if someone makes a subject access request?

Respond within one month. Search your systems for their data, provide it in a readable format, and if they ask for deletion, remove their data from active systems and backups where possible. Having a simple process in place makes this easy.

JW
Written by
Jamie Woodruff
Technical Director

Jamie is Technical Director at Varsuite and leads the technical development team, setting how we design and build everything we ship. He builds the AI models that power our agents and manages the AI s...

More from Jamie Woodruff

Get The Signal

Practical notes on AI, websites and automation for UK businesses. One useful email at a time, unsubscribe whenever.

What is The Signal?

About Varsuite

Varsuite is an AI-accelerated, human-perfected digital production company based in Rishton, Lancashire. Agents build, people perfect: websites, stores, software and AI automation.

Ready to put AI to work?

Let our agents design, build and manage it for you.

Start a build