Most small business websites are not compliant, usually through a banner that announces cookies rather than asking, and a privacy policy copied from a generator years ago.
This covers what is actually required and how to implement it. It is general guidance rather than legal advice, and anything unusual — health data, children, large-scale profiling — warrants proper professional input.
- 1
Find out what your site actually sets
Open the browser developer tools, clear everything, load the site and list every cookie and local storage entry. Most owners are surprised. Analytics, embedded videos, maps, chat widgets, social buttons and ad pixels all set them, often without anyone having decided to.
- 2
Sort them into strictly necessary and everything else
Strictly necessary means the site cannot function without it: session, security, load balancing, a basket. Analytics is not strictly necessary, however useful. Only the strictly necessary category may run without consent, and this is the distinction most banners get wrong.
- 3
Make the banner ask, not announce
Non-essential cookies must not be set until consent is given. Reject must be as easy as accept — a prominent Accept with Reject hidden behind a settings link does not meet the standard, and the ICO has said so repeatedly. No pre-ticked boxes.
- 4
Verify nothing fires before consent
Load the site fresh, decline, and check the network tab and cookie list. Plenty of banners display correctly while the analytics tag has already fired underneath. This is the single most common compliance failure and it is invisible without checking.
- 5
Write a privacy policy that describes your actual site
It must state what data you collect, why, the lawful basis, how long you keep it, who you share it with, and the rights people have. A generated template naming services you do not use is worse than none — it is a public statement that is untrue.
- 6
Make consent as easy to withdraw as to give
A persistent link or small icon that reopens the preferences. Withdrawal must be as straightforward as consent. A banner that appears once and can never be revisited fails this and is very common.
- 7
Keep the records and set a review date
Log consents with a timestamp. Note your lawful basis for each processing purpose. If you have staff or process significant volumes, keep a record of processing activities. Review annually, and whenever you add a tool that touches visitor data.
Contact forms
A form is processing personal data. Say on the form what you will use it for and link the privacy policy. Do not bundle marketing consent into an enquiry — a separate, unticked opt-in is required if you intend to email them later.
Realistic risk
ICO enforcement against small businesses is rare and usually complaint-driven. The practical risks are a complaint you must answer, an awkward question in a tender, and the trust cost of a site visibly ignoring the rules.
Frequently asked questions
Yes. Analytics cookies are not strictly necessary, so consent is required before they are set.
Would rather we did it?
These guides are here so you can do it yourself. If you would rather hand it over, that is what we do.
Start a conversation