{"id":1855,"date":"2026-04-25T14:51:29","date_gmt":"2026-04-25T13:51:29","guid":{"rendered":"https:\/\/www.duport.co.uk\/blog\/?p=1855"},"modified":"2026-04-25T15:11:54","modified_gmt":"2026-04-25T14:11:54","slug":"does-my-contact-form-need-a-privacy-policy-uk","status":"publish","type":"post","link":"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/","title":{"rendered":"Does My Contact Form Need a Privacy Policy UK?"},"content":{"rendered":"<h2>Does My Contact Form Need a Privacy Policy UK?<\/h2>\n<p>If your website has a contact form, you\u2019ll almost certainly need a privacy policy. This is something a lot of people miss when they\u2019re first putting a site together, but once you know what\u2019s required, it\u2019s fairly straightforward to fix.<\/p>\n<p>Below is what needs to go into it, where it should sit on your site, and why templates often cause more problems than they solve.<\/p>\n<h2>Do I legally need a contact form privacy policy in the UK?<\/h2>\n<p><strong>Yes, once your form starts collecting personal details (even just a name and email), you\u2019re expected to have a privacy policy in place.<\/strong><\/p>\n<p>UK GDPR and the Data Protection Act 2018 require any website collecting personal data to publish a privacy policy. It doesn\u2019t matter if it just lands in a Gmail or Outlook inbox and you reply manually. That puts you in the position of a data controller, even if you\u2019re just responding to enquiries from a basic inbox, and data controllers must give people clear information about how their data will be used. This applies just as much to a one-person business as it does to a larger company. A lot of sole traders assume this only applies once you \u201cscale up,\u201d but that\u2019s not how the law treats it.<\/p>\n<p>The full picture on how UK GDPR applies to your website is in<a href=\"https:\/\/www.duport.co.uk\/blog\/how-to-make-your-small-business-website-gdpr-compliant\/\"> How to Make Your Small Business Website GDPR Compliant<\/a> worth reading alongside this article.<\/p>\n<h2>What must a privacy policy include for a UK website in 2026?<\/h2>\n<p><strong>At a minimum, your privacy policy should cover a few key points. This is where most template policies fall short, they stay too vague to be useful. Name what data you collect, why you hold it, your lawful basis for processing it, who you share it with, how long you keep it, and how people can request deletion.<\/strong><\/p>\n<p>The ICO&#8217;s transparency requirement, Article 13 of UK GDPR, sets out this list precisely. Under &#8216;what data you collect,&#8217; be specific. For example, if your form asks for a name, email, and message, say exactly that, not just \u201ccontact details.\u201d Under &#8216;lawful basis,&#8217; state it explicitly. For a typical \u2018get in touch\u2019 form, most businesses rely on legitimate interests, because you\u2019re responding to someone who has actively contacted you, not sending follow-up marketing emails later.<\/p>\n<p>Two details that are easy to overlook (and regularly missing when we review sites): You need to name yourself as the data controller, your business name and, if you are a limited company, your registered number. You should also explain people\u2019s rights, like requesting access, corrections or asking for their data to be deleted, which many shorter template policies skip over.<\/p>\n<h2>Where exactly should the privacy policy link appear?<\/h2>\n<p><strong>Ensuring you have a contact form privacy policy in the UK is a matter of both legal compliance and user trust. In practice, you\u2019ll want it in two places: your footer (so it\u2019s always accessible) and right next to your contact form, where someone is about to submit their details.<\/strong><\/p>\n<p>A footer link on its own usually isn\u2019t enough, most people won\u2019t scroll down and go looking for legal pages before submitting a form. UK GDPR requires you to give people privacy information at the time you collect their data. When someone is about to submit a contact form, a link to the policy needs to be visible right there. A simple line under the submit button is usually enough, something short and readable that doesn\u2019t interrupt the form. For example: \u2018We\u2019ll use your details to respond to your enquiry: see our privacy policy.&#8217; or place the link directly beside the submission button.<\/p>\n<p>Your footer link covers general browsing. The in-form link covers the moment of data collection. Both are required.<\/p>\n<h2>Can I use a template privacy policy?<\/h2>\n<p><strong>You can start from a template, but you cannot leave it unchanged and call it compliant.<\/strong><\/p>\n<p>It\u2019s surprisingly common to see templates still containing another company\u2019s name, or leftover sections from whoever created the template in the first place. The ICO specifically advises that a privacy policy must reflect your actual processing activities. For example, a policy that mentions Google Analytics when your site doesn\u2019t use it is technically inaccurate, and something the ICO would expect you to correct if challenged. One that does not mention the inbox where you store enquiries is incomplete.<\/p>\n<p>Templates are fine as a starting point, but they\u2019re not \u201cset and forget\u201d, they need going through line by line against how your site works.<\/p>\n<h2>What happens if I don&#8217;t have a privacy policy?<\/h2>\n<p><strong>If someone fills in your contact form and later asks what data you hold on them, that counts as a Subject Access Request, and you\u2019ll need to respond within 30 days.<\/strong><\/p>\n<p>Fines are possible, but in reality most small businesses notice the impact elsewhere first, usually when a customer hesitates because something feels incomplete or off. A formal data subject complaint via the ICO creates a paper trail regardless of whether a fine follows. In practice, it often comes down to comparison, especially for service businesses where people are deciding between two similar providers, the one with a properly set up site tends to feel more credible.<\/p>\n<p>If you are also unsure about the checkbox and consent wording on your form,<a href=\"https:\/\/www.duport.co.uk\/blog\/do-i-need-a-checkbox-on-my-contact-form-uk-gdpr\/\"> Do I Need a Checkbox on My Contact Form? UK GDPR<\/a> covers exactly what to write and when you need explicit consent.<\/p>\n<p>One thing worth checking while you review your privacy policy: the rest of your site&#8217;s compliance. UK law requires a privacy policy, cookie notice, terms and conditions, and the right business information in your footer. Platforms like Wix or Squarespace will give you template pages, but they don\u2019t check whether you\u2019ve filled them in correctly, or at all.<\/p>\n<p>Already have a website? Most sites we review are missing at least one of these, often things like a missing cookie notice, incomplete company details in the footer, or a privacy policy that doesn\u2019t match how the form works. Run it through our free compliance checker:<\/p>\n<p><a href=\"https:\/\/uk-website-check.base44.app\/\">Check your website now \u2192<\/a><\/p>\n<h2>Your website sorted properly, not just theoretically<\/h2>\n<p>Duport builds professional websites for UK small businesses. Every site includes the key legal pages, written to match your business, rather than copied from a generic template.<\/p>\n<p><a href=\"https:\/\/www.duport.co.uk\/related-services\/website-design\">Duport&#8217;s website build<\/a> starts from \u00a3360. Mention this article when you get in touch and we&#8217;ll honour the \u00a3144 rate.<\/p>\n<h6>This article is for general guidance. For advice specific to your business, speak to a qualified solicitor or data protection specialist.<\/h6>\n<hr \/>\n<h2>FAQs<\/h2>\n<ul>\n<li>\n<h3>Does a sole trader need a privacy policy on their website?<\/h3>\n<\/li>\n<\/ul>\n<p>Yes, this applies whether you\u2019re a sole trader or a limited company, that\u2019s another one people often assume only applies to larger businesses. If your site collects personal data, the requirement is the same.<\/p>\n<ul>\n<li>\n<h3>Does my privacy policy need to mention cookies?<\/h3>\n<\/li>\n<\/ul>\n<p>Yes, if your site uses cookies, which most sites do. Cookie use is typically covered in a separate cookie notice, but your privacy policy should reference it and link to it.<\/p>\n<ul>\n<li>\n<h3>How often should I update my privacy policy?<\/h3>\n<\/li>\n<\/ul>\n<p>Review your policy whenever data processing changes. This includes adding tracking tools, email marketing, or changing how you handle enquiries. Update it for legal changes too. The ICO updated its guidance in March 2026 following the DUAA 2025. Policies written before then may now be outdated.<\/p>\n<ul>\n<li>\n<h3>Is my Wix or Squarespace website legally compliant in the UK?<\/h3>\n<\/li>\n<\/ul>\n<p>Not automatically. UK law requires a privacy policy, cookie notice, and clear terms. Limited companies must also display their registered name and number. Most website builders provide basic templates. However, they do not check if your content is accurate or complete. Use our free website compliance checker to see what your site has and what it&#8217;s missing.<\/p>\n<p><a href=\"https:\/\/uk-website-check.base44.app\/\">Check your website \u2192<\/a><\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Does My Contact Form Need a Privacy Policy UK? If your website has a contact form, you\u2019ll almost certainly need a privacy policy. This is something a lot of people miss when they\u2019re first putting a site together, but once you know what\u2019s required, it\u2019s fairly straightforward to fix. Below is what needs to go [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1864,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[185],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.8.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Contact Form Privacy Policy UK: 2026 Legal Requirements Guide<\/title>\n<meta name=\"description\" content=\"Do you need a contact form privacy policy in the UK? Learn the 2026 GDPR requirements, mandatory inclusions, and how to stay compliant.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Contact Form Privacy Policy UK: 2026 Legal Requirements Guide\" \/>\n<meta property=\"og:description\" content=\"Do you need a contact form privacy policy in the UK? Learn the 2026 GDPR requirements, mandatory inclusions, and how to stay compliant.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/\" \/>\n<meta property=\"og:site_name\" content=\"Duport Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-25T13:51:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-25T14:11:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.duport.co.uk\/blog\/wp-content\/uploads\/2026\/04\/T11-C1.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"2048\" \/>\n\t<meta property=\"og:image:height\" content=\"2048\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"rebecca\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@rebecca@duportltd.co.uk\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"rebecca\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/\",\"url\":\"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/\",\"name\":\"Contact Form Privacy Policy UK: 2026 Legal Requirements Guide\",\"isPartOf\":{\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#website\"},\"datePublished\":\"2026-04-25T13:51:29+00:00\",\"dateModified\":\"2026-04-25T14:11:54+00:00\",\"author\":{\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/7ab758c8f0702249ec7d30a15d69ef8b\"},\"description\":\"Do you need a contact form privacy policy in the UK? Learn the 2026 GDPR requirements, mandatory inclusions, and how to stay compliant.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.duport.co.uk\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Does My Contact Form Need a Privacy Policy UK?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#website\",\"url\":\"https:\/\/www.duport.co.uk\/blog\/\",\"name\":\"Duport Blog\",\"description\":\"Business help and advice\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.duport.co.uk\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/7ab758c8f0702249ec7d30a15d69ef8b\",\"name\":\"rebecca\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/713b221cb7214d94bdfde2651dbee3c3?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/713b221cb7214d94bdfde2651dbee3c3?s=96&d=mm&r=g\",\"caption\":\"rebecca\"},\"sameAs\":[\"https:\/\/twitter.com\/rebecca@duportltd.co.uk\"],\"url\":\"https:\/\/www.duport.co.uk\/blog\/author\/rebecca\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Contact Form Privacy Policy UK: 2026 Legal Requirements Guide","description":"Do you need a contact form privacy policy in the UK? Learn the 2026 GDPR requirements, mandatory inclusions, and how to stay compliant.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/","og_locale":"en_GB","og_type":"article","og_title":"Contact Form Privacy Policy UK: 2026 Legal Requirements Guide","og_description":"Do you need a contact form privacy policy in the UK? Learn the 2026 GDPR requirements, mandatory inclusions, and how to stay compliant.","og_url":"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/","og_site_name":"Duport Blog","article_published_time":"2026-04-25T13:51:29+00:00","article_modified_time":"2026-04-25T14:11:54+00:00","og_image":[{"width":2048,"height":2048,"url":"https:\/\/www.duport.co.uk\/blog\/wp-content\/uploads\/2026\/04\/T11-C1.jpeg","type":"image\/jpeg"}],"author":"rebecca","twitter_card":"summary_large_image","twitter_creator":"@rebecca@duportltd.co.uk","twitter_misc":{"Written by":"rebecca","Estimated reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/","url":"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/","name":"Contact Form Privacy Policy UK: 2026 Legal Requirements Guide","isPartOf":{"@id":"https:\/\/www.duport.co.uk\/blog\/#website"},"datePublished":"2026-04-25T13:51:29+00:00","dateModified":"2026-04-25T14:11:54+00:00","author":{"@id":"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/7ab758c8f0702249ec7d30a15d69ef8b"},"description":"Do you need a contact form privacy policy in the UK? Learn the 2026 GDPR requirements, mandatory inclusions, and how to stay compliant.","breadcrumb":{"@id":"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.duport.co.uk\/blog\/does-my-contact-form-need-a-privacy-policy-uk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.duport.co.uk\/blog\/"},{"@type":"ListItem","position":2,"name":"Does My Contact Form Need a Privacy Policy UK?"}]},{"@type":"WebSite","@id":"https:\/\/www.duport.co.uk\/blog\/#website","url":"https:\/\/www.duport.co.uk\/blog\/","name":"Duport Blog","description":"Business help and advice","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.duport.co.uk\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/7ab758c8f0702249ec7d30a15d69ef8b","name":"rebecca","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.duport.co.uk\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/713b221cb7214d94bdfde2651dbee3c3?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/713b221cb7214d94bdfde2651dbee3c3?s=96&d=mm&r=g","caption":"rebecca"},"sameAs":["https:\/\/twitter.com\/rebecca@duportltd.co.uk"],"url":"https:\/\/www.duport.co.uk\/blog\/author\/rebecca\/"}]}},"_links":{"self":[{"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1855"}],"collection":[{"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=1855"}],"version-history":[{"count":3,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1855\/revisions"}],"predecessor-version":[{"id":1878,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/posts\/1855\/revisions\/1878"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/media\/1864"}],"wp:attachment":[{"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=1855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=1855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.duport.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=1855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}