What is GDPR and what does it mean for your website?
Definition

What is GDPR and what does it mean for your website?

GDPR is an EU and UK law on handling personal data. It applies to your website whenever you collect visitor info via forms, cookies or analytics.

A1 Digital A1 Digital · written & reviewed by the team 4 min read Updated 14 July 2026

Quick answer

GDPR (the General Data Protection Regulation) is an EU and UK law governing how businesses collect, store and use personal data. For your website it means you must publish a privacy policy, ask consent before tracking visitors with cookies, secure the data you hold, and let people view or delete it on request.

Up to £17.5m

or 4% of global turnover, the maximum UK GDPR fine

Source: ICO

1 month

the deadline to respond to a data access or deletion request

Any data

GDPR applies the moment a site collects names, emails, IPs or cookies

GDPR sounds like something only big corporations need to worry about, and that assumption is exactly what trips small businesses up. A one-page site for a local plumber is covered just as much as a national retailer, because the law triggers on the data, not the size of the business. The reassuring news: for a small site, compliance is mostly common sense and a short checklist, not a legal department.

GDPR (the General Data Protection Regulation) is an EU and UK law that controls how businesses collect, store and use people’s personal data, and it applies to your website the moment you gather any visitor information, including names, emails, enquiry forms, analytics or cookies. If your site has a contact form, a newsletter sign-up, or even Google Analytics, GDPR applies to you.

The one-line version

GDPR means you must tell visitors what data you collect and why, get clear permission before tracking them, then keep that data safe and let people see or delete it on request.

What counts as personal data?

Personal data is any information that can identify a living person. On a typical small-business website that includes:

  • Names, email addresses and phone numbers from a contact form or enquiry
  • IP addresses and device data collected by analytics
  • Cookies that track behaviour across pages
  • Booking details, payment records and customer accounts
  • Anything in your email inbox tied to a real person

If your website touches any of the above, you’re a “data controller” under the law and you have legal duties.

Does GDPR still apply in the UK after Brexit?

Yes. The UK kept GDPR after leaving the EU, in a near-identical form called UK GDPR, enforced by the Information Commissioner’s Office (ICO). If you also serve EU customers, EU GDPR applies on top. For most small businesses the practical rules are the same either way.

Regulation Applies to Enforced by
UK GDPR UK businesses & UK visitors ICO (Information Commissioner)
EU GDPR Anyone serving EU residents EU data authorities
PECR Cookies, marketing emails, calls ICO

PECR (the Privacy and Electronic Communications Regulations) is the partner law that governs cookie banners and marketing emails specifically. People often lump it in with GDPR.

What your website actually needs

You don’t need a legal team. For most small sites, compliance comes down to a short checklist:

1

Publish a privacy policy

A plain-English page explaining what data you collect, why, how long you keep it, and who you share it with. Link it in your footer.

2

Add a compliant cookie banner

If you use analytics or tracking, ask consent BEFORE those cookies load. A banner that only says 'we use cookies' with no choice isn't enough.

3

Get consent on forms

Use an unticked checkbox for marketing sign-ups. Never pre-tick it. Collect only the data you genuinely need.

4

Secure the data

Run your site over HTTPS, keep software updated, and store enquiries somewhere protected, not a shared inbox anyone can read.

5

Honour requests

People can ask to see or delete their data. You must respond, usually within one month.

Cookie banners aren't decoration

A banner that drops tracking cookies the instant the page loads, before the visitor clicks anything, breaks the rules. Consent must come first. The detail’s in cookie banners explained.

The risks of ignoring it

The headline GDPR fines (up to £17.5m or 4% of turnover) are aimed at large companies misusing data at scale. A small business is far more likely to face:

  • A complaint to the ICO from an unhappy customer or competitor
  • Reputational damage if a data breach goes public
  • Lost trust, since visitors increasingly notice missing privacy policies

The realistic risk is rarely a giant fine. It’s the slow erosion of trust, and the scramble if you ever do have a breach with no policy in place.

Key takeaway

GDPR compliance for a small website is mostly about three things: tell people what you collect, ask before you track them, and keep their data safe. Get those right and you’re most of the way there.

Because we build and manage the whole site, GDPR basics are baked in: HTTPS by default, a privacy policy tailored to your services, a consent-first cookie banner, and forms that store enquiries securely rather than scattering them across inboxes. You stay focused on the business while the compliance plumbing is handled. See what’s included on the pricing page. Weighing up DIY versus managed? DIY vs done-for-you website walks through the trade-offs.

Open your own website right now and check three things: is there a privacy policy linked in the footer, does a cookie banner appear before tracking starts, and is the address bar showing a padlock (HTTPS)? If any answer’s no, that’s your first job this week.

Frequently asked questions

Does GDPR apply to my small business website?

Yes. GDPR applies to any business that collects personal data, regardless of size. If your website has a contact form, newsletter sign-up, online booking, or even Google Analytics, you're collecting personal data and the rules apply. There's no exemption for sole traders or small firms.

Do I need a cookie banner?

If your site uses any non-essential cookies, such as analytics or advertising trackers, then yes. The banner must ask for consent before those cookies load, not after. A banner that simply announces 'we use cookies' with no real choice doesn't meet the requirement under UK GDPR and PECR.

Is UK GDPR different from EU GDPR after Brexit?

They're nearly identical. The UK retained GDPR as UK GDPR, enforced by the ICO, after leaving the EU. If you serve customers in the EU, EU GDPR also applies, but for most UK small businesses the day-to-day rules are effectively the same.

What happens if I ignore GDPR?

The largest fines target big companies misusing data at scale. A small business is more likely to face an ICO complaint, reputational damage, or a costly scramble after a data breach with no policy in place. The bigger everyday risk is losing customer trust when basics like a privacy policy or HTTPS are missing.

GDPR privacy compliance cookies website data protection
Share Link copied
A1 Digital

Written by the A1 Digital team

We handle the entire online presence for small businesses, website, branded email, Google, AI search, content and reviews, for one simple monthly plan. No tech headaches, no lock-in.