{"id":1853,"date":"2026-04-25T14:51:14","date_gmt":"2026-04-25T13:51:14","guid":{"rendered":"https:\/\/www.duport.co.uk\/blog\/?p=1853"},"modified":"2026-04-25T15:12:00","modified_gmt":"2026-04-25T14:12:00","slug":"how-to-make-your-small-business-website-gdpr-compliant","status":"publish","type":"post","link":"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/","title":{"rendered":"How to Make Your Small Business Website GDPR Compliant"},"content":{"rendered":"<h1>How to Make Your Small Business Website GDPR Compliant<\/h1>\n<p>GDPR usually comes up at a slightly awkward moment. That catches a lot of people out, especially when trying to maintain GDPR compliance for small business websites that were put together quickly.<\/p>\n<p>This breaks down what needs to be in place, without the legal jargon that tends to make people switch off halfway through. You&#8217;ll find privacy policy requirements, contact form rules, the mailing list trap most businesses fall into, and what changed in 2026.<\/p>\n<h2>What does GDPR compliance for small business websites actually mean?<\/h2>\n<p><strong>If your site collects things like names, email addresses, or phone numbers, GDPR kicks in. Those rules cover how you collect that information, how you use it, and how long you keep it.<\/strong><\/p>\n<p>In practice, that includes even very simple setups, even a one-page site with a \u2018call me back\u2019 form or a basic booking calendar. If someone can type their details into your site, even just a \u2018call me back\u2019 box, that counts. It doesn\u2019t have to be a complex system. UK GDPR is enforced by the ICO and applies to all UK businesses regardless of size. There&#8217;s no minimum threshold.<\/p>\n<h2>Does my contact form need a privacy policy?<\/h2>\n<p><strong>Yes. A privacy policy is a legal requirement the moment your website collects any personal data.<\/strong><\/p>\n<p>UK GDPR and the Data Protection Act 2018 require you to publish a privacy policy. It must cover what data you collect, why you hold it, how long you keep it, and who you share it with. Put a link to it in your footer, and add a second link near any form on the page. Copying a privacy policy from another website and leaving it as-is is a common shortcut. But it\u2019s also where a lot of sites fall down. If it doesn\u2019t reflect what you do, it won\u2019t hold up. It needs to match what you actually do in practice. It\u2019s quite common to see policies mentioning tools or services the business doesn\u2019t even use anymore, often because the original version was copied and never revisited.<\/p>\n<p>At minimum, your policy must name the data controller, that&#8217;s you. It also needs your lawful basis for processing, how long you keep data, and how people can request its deletion. The ICO has a clear guide if you&#8217;re writing your own.<\/p>\n<h2>Do I need a checkbox on my contact form?<\/h2>\n<p><strong>For a standard enquiry form, where you&#8217;re only using the data to reply, a checkbox is not required. A link to your privacy policy is.<\/strong><\/p>\n<p>UK GDPR requires a &#8220;lawful basis&#8221; for every type of data processing. In most everyday cases, like replying to an inquiry, \u2018legitimate interests\u2019 is the basis people rely on. It\u2019s the practical option, and usually the correct one. You don&#8217;t need their explicit consent. What you need is a short statement near the form. Something like: &#8220;We&#8217;ll use your details to respond to your message. See our privacy policy.&#8221;<\/p>\n<p>If you plan to use that data for anything else, adding them to a mailing list, sending marketing or sharing with third parties, you need explicit consent. A standalone checkbox on the form is the right way to get it.<\/p>\n<h2>Can I add someone to my mailing list after they contact me?<\/h2>\n<p><strong>No, a contact form submission does not give you permission to send marketing emails.<\/strong><\/p>\n<p>This is where a lot of small businesses slip up, especially after a busy week of enquiries when it\u2019s tempting to add everyone into a mailing list. Someone fills in your contact form asking for a quote. You reply, maybe send a follow-up a few days later, and then add them to your newsletter list while you\u2019re tidying up your inbox at the end of the week. That extra step is where the issue starts. That requires separate, explicit consent. The original enquiry form did not provide it. This tends to happen gradually rather than deliberately, especially when you\u2019re trying to make the most of incoming enquiries.<\/p>\n<p>Pre-ticked boxes won\u2019t cut it. And hiding consent in your terms and conditions is just as ineffective. You need a clear, standalone opt-in, usually a separate unticked checkbox that explicitly mentions marketing emails. Anything less tends to fall into a grey area. If you plan to use someone&#8217;s data for anything beyond replying, get separate permission.<\/p>\n<h2>2026 Updates: GDPR compliance for small business websites<\/h2>\n<p><strong>The Data (Use and Access) Act 2025 came into force on 5 February 2026. It updated UK GDPR in ways small businesses should know about.<\/strong><\/p>\n<p>The main change is a new category called \u2018recognised legitimate interests\u2019, a seventh option for specific purposes. These cover areas like fraud prevention and network security, where organisations can process data without running a full Legitimate Interests Assessment. For most small business websites, especially ones just handling enquiries, you\u2019ll probably never notice this change in day-to-day use. It\u2019s more relevant to businesses dealing with things like fraud checks or network security.<\/p>\n<p>But the ICO updated its official guidance on 23 March 2026 to reflect the new legislation. Any privacy policy written before that date may now be partially out of date. If your policy hasn\u2019t been reviewed recently, it\u2019s worth a quick check, especially if it was written before 2026 and hasn\u2019t been touched since.<\/p>\n<p>If you\u2019re not completely sure your site covers all of this right now, run it through our free GDPR compliance for small business websites checker. It takes two minutes and tells you exactly what your website has and what&#8217;s missing.<\/p>\n<p><a href=\"https:\/\/uk-website-check.base44.app\/\">Check your website now \u2192<\/a><\/p>\n<p>Cookies and tracking tools fall under a separate set of rules. We&#8217;ve covered the full picture in <a href=\"https:\/\/www.duport.co.uk\/blog\/do-i-need-a-cookie-banner-on-my-website-uk-rules-explained\/\">Do I Need a Cookie Banner on My Website?<\/a> If you&#8217;re on Wix specifically, <a href=\"https:\/\/www.duport.co.uk\/blog\/is-my-wix-cookie-banner-gdpr-compliant\/\">Is My Wix Cookie Banner GDPR Compliant?<\/a> covers the specific gaps in Wix&#8217;s built-in cookie tool.<\/p>\n<h2>What happens if my website isn&#8217;t GDPR compliant?<\/h2>\n<p><strong>The ICO can issue fines of up to \u00a317.5 million or 4% of annual turnover, but for most small businesses the realistic risk looks different.<\/strong><\/p>\n<p>ICO enforcement focuses on organisations causing real harm; data breaches, deliberate misuse, or persistent non-compliance after a formal warning. For most small businesses, the issue shows up in more practical ways before anything else. Like a customer asking for their data, or a complaint you\u2019re not quite prepared to handle. A data subject access request you&#8217;re not set up to deal with. Or more subtly, it can chip away at trust, especially if someone notices gaps in how your site handles their information.<\/p>\n<p>Once you strip it back, GDPR at a small business level is manageable. It\u2019s just not always obvious where to start. It\u2019s rarely ignored completely, it just gets pushed down the list because the rules feel unclear.<\/p>\n<h2>Want a website that&#8217;s built compliantly from the start?<\/h2>\n<p>Duport builds professional websites for UK small businesses. Each site includes the legal pages you\u2019ll need from the start; privacy policy, cookie notice, and terms and conditions. They\u2019re based on how your business actually runs, rather than a generic template design.<\/p>\n<p><a href=\"https:\/\/www.duport.co.uk\/related-services\/website-design\">Duport&#8217;s website build starts from \u00a3360.<\/a> Mention this article when you get in touch and we&#8217;ll honour the \u00a3144 rate.<\/p>\n<p>Not sure whether it&#8217;s worth handing over? We&#8217;ve covered the full decision in <a href=\"https:\/\/www.duport.co.uk\/blog\/should-i-hire-someone-to-build-my-website\/\">Should I Hire Someone to Build My Website?<\/a><\/p>\n<h6><em>This article is for general guidance. For advice specific to your business and data processing activities, speak to a qualified solicitor or data protection specialist.<\/em><\/h6>\n<hr \/>\n<h2>FAQs<\/h2>\n<ul>\n<li>\n<h3>Does a small business need to register with the ICO?<\/h3>\n<\/li>\n<\/ul>\n<p>Most businesses that process personal data need to pay the ICO&#8217;s annual data protection fee. It starts at \u00a340 per year for small organisations and renews annually.<\/p>\n<ul>\n<li>\n<h3>How long can I keep data from my contact form?<\/h3>\n<\/li>\n<\/ul>\n<p>UK GDPR doesn&#8217;t set a fixed period; you decide what&#8217;s reasonable for your purpose, document that decision, and delete the data when the period ends.<\/p>\n<ul>\n<li>\n<h3>What is the ICO and do I need to tell them about my website?<\/h3>\n<\/li>\n<\/ul>\n<p>The ICO is the UK&#8217;s data protection regulator. You don&#8217;t notify them about individual forms, but most businesses processing personal data need to pay the annual data protection fee.<\/p>\n<ul>\n<li>\n<h3>Is my Wix or Squarespace website legally compliant in the UK?<\/h3>\n<\/li>\n<\/ul>\n<p>Not automatically. UK law requires your website to include a privacy policy, a cookie notice, clear terms and conditions, and specific business information; such as your registered company name and number if you&#8217;re a limited company. Most website builders include template pages for some of these, but they don&#8217;t check whether your content is accurate or complete. Use our free website compliance checker to see what your site has and what it&#8217;s missing.<\/p>\n<p><a href=\"https:\/\/uk-website-check.base44.app\/\">Check your website \u2192<\/a><\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to Make Your Small Business Website GDPR Compliant GDPR usually comes up at a slightly awkward moment. That catches a lot of people out, especially when trying to maintain GDPR compliance for small business websites that were put together quickly. This breaks down what needs to be in place, without the legal jargon that [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1861,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[185],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.8.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>GDPR Compliance for Small Business Websites | 2026 UK Guide<\/title>\n<meta name=\"description\" content=\"How to make your small business website GDPR compliant in the UK \u2014 contact form rules, privacy policy requirements, and what changed in 2026.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GDPR Compliance for Small Business Websites | 2026 UK Guide\" \/>\n<meta property=\"og:description\" content=\"How to make your small business website GDPR compliant in the UK \u2014 contact form rules, privacy policy requirements, and what changed in 2026.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/\" \/>\n<meta property=\"og:site_name\" content=\"Duport Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-25T13:51:14+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-25T14:12:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.duport.co.uk\/blog\/wp-content\/uploads\/2026\/04\/Gemini_Generated_Image_z0mpuqz0mpuqz0mp.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"2048\" \/>\n\t<meta property=\"og:image:height\" content=\"2048\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"rebecca\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@rebecca@duportltd.co.uk\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"rebecca\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/\",\"url\":\"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/\",\"name\":\"GDPR Compliance for Small Business Websites | 2026 UK Guide\",\"isPartOf\":{\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#website\"},\"datePublished\":\"2026-04-25T13:51:14+00:00\",\"dateModified\":\"2026-04-25T14:12:00+00:00\",\"author\":{\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/7ab758c8f0702249ec7d30a15d69ef8b\"},\"description\":\"How to make your small business website GDPR compliant in the UK \u2014 contact form rules, privacy policy requirements, and what changed in 2026.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.duport.co.uk\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Make Your Small Business Website GDPR Compliant\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#website\",\"url\":\"https:\/\/www.duport.co.uk\/blog\/\",\"name\":\"Duport Blog\",\"description\":\"Business help and advice\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.duport.co.uk\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/7ab758c8f0702249ec7d30a15d69ef8b\",\"name\":\"rebecca\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/713b221cb7214d94bdfde2651dbee3c3?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/713b221cb7214d94bdfde2651dbee3c3?s=96&d=mm&r=g\",\"caption\":\"rebecca\"},\"sameAs\":[\"https:\/\/twitter.com\/rebecca@duportltd.co.uk\"],\"url\":\"https:\/\/www.duport.co.uk\/blog\/author\/rebecca\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GDPR Compliance for Small Business Websites | 2026 UK Guide","description":"How to make your small business website GDPR compliant in the UK \u2014 contact form rules, privacy policy requirements, and what changed in 2026.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/","og_locale":"en_GB","og_type":"article","og_title":"GDPR Compliance for Small Business Websites | 2026 UK Guide","og_description":"How to make your small business website GDPR compliant in the UK \u2014 contact form rules, privacy policy requirements, and what changed in 2026.","og_url":"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/","og_site_name":"Duport Blog","article_published_time":"2026-04-25T13:51:14+00:00","article_modified_time":"2026-04-25T14:12:00+00:00","og_image":[{"width":2048,"height":2048,"url":"https:\/\/www.duport.co.uk\/blog\/wp-content\/uploads\/2026\/04\/Gemini_Generated_Image_z0mpuqz0mpuqz0mp.jpeg","type":"image\/jpeg"}],"author":"rebecca","twitter_card":"summary_large_image","twitter_creator":"@rebecca@duportltd.co.uk","twitter_misc":{"Written by":"rebecca","Estimated reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/","url":"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/","name":"GDPR Compliance for Small Business Websites | 2026 UK Guide","isPartOf":{"@id":"https:\/\/www.duport.co.uk\/blog\/#website"},"datePublished":"2026-04-25T13:51:14+00:00","dateModified":"2026-04-25T14:12:00+00:00","author":{"@id":"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/7ab758c8f0702249ec7d30a15d69ef8b"},"description":"How to make your small business website GDPR compliant in the UK \u2014 contact form rules, privacy policy requirements, and what changed in 2026.","breadcrumb":{"@id":"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.duport.co.uk\/blog\/"},{"@type":"ListItem","position":2,"name":"How to Make Your Small Business Website GDPR Compliant"}]},{"@type":"WebSite","@id":"https:\/\/www.duport.co.uk\/blog\/#website","url":"https:\/\/www.duport.co.uk\/blog\/","name":"Duport Blog","description":"Business help and advice","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.duport.co.uk\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/7ab758c8f0702249ec7d30a15d69ef8b","name":"rebecca","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/713b221cb7214d94bdfde2651dbee3c3?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/713b221cb7214d94bdfde2651dbee3c3?s=96&d=mm&r=g","caption":"rebecca"},"sameAs":["https:\/\/twitter.com\/rebecca@duportltd.co.uk"],"url":"https:\/\/www.duport.co.uk\/blog\/author\/rebecca\/"}]}},"_links":{"self":[{"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1853"}],"collection":[{"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=1853"}],"version-history":[{"count":4,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1853\/revisions"}],"predecessor-version":[{"id":1877,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1853\/revisions\/1877"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/media\/1861"}],"wp:attachment":[{"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=1853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=1853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=1853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}