10% off every plan until October — because my rent's due.
Back to blog

One week GDPR fixes for UK small sites, updated for new cookie rules

Isometric cookie consent compliance title card

If your website collects names, emails, IP addresses or cookie data, it must comply with UK GDPR and the Data Protection Act 2018, full stop. Do three things today: publish a plain-language privacy notice, fix your cookie banner so it meets PECR and the updated Data (Use and Access) Act rules, and write down your lawful basis for each piece of data you collect. Everything else on this page builds out from there.


TL;DR:

  • Most small websites collect personal data and must update their privacy notices, cookie banners, and record lawful bases for processing.
  • Loosened rules for low-risk, first-party cookies take effect February 2026, but third-party or advertising cookies still require explicit consent.
  • Key tasks include mapping data flows, installing a proper cookie mechanism, and registering with the ICO if applicable.
  • Baseline security measures like SSL certificates, regular updates, and backups are essential to maintain compliance.
  • Most breaches involve neglect or outdated policies; a clear breach response plan and proper documentation help manage incidents effectively.

Basic-bs
Get Your Website Live Without Hidden Costs
BasicBS builds affordable small-business websites with zero upfront costs, transparent pricing, and a typical five to seven working day turnaround.
Visit BasicBS

Table of Contents

What does GDPR website compliance actually involve?

Right, let’s cut the rubbish. GDPR compliance isn’t a one-off tickbox you complete then forget. It’s an ongoing habit, and for most small sites it breaks down into eight jobs you can knock out in a week or two.

  1. Map your data flows. List every form, analytics tool and third-party widget on your site and note what data each one grabs.
  2. Write or update your privacy notice and put it where data actually gets collected, not buried three clicks deep.
  3. Install a proper cookie mechanism with a real accept/reject choice, and log every consent decision.
  4. Document your lawful basis for each processing activity, in writing, even if it’s a single line per activity.
  5. Sort baseline security: TLS certificates, software updates, backups.
  6. Decide if you need a DPIA for any high-risk tracking or profiling.
  7. Register with the ICO and pay the fee if your business falls into a paying category.
  8. Set a consent refresh schedule so old permissions don’t quietly go stale.

None of this needs a law firm. It needs an afternoon, a spreadsheet, and the will to actually do it rather than copy your competitor’s privacy policy and hope nobody notices.

Privacy notice essentials: what to include and where to put it

Your privacy notice isn’t marketing copy, and it isn’t a legal essay either. Under Articles 13 and 14 of the ICO’s guidance, it needs to spell out:

  • Who you are and how to contact you
  • What data you collect and why
  • Your lawful basis for each purpose
  • Who you share data with, if anyone
  • How long you keep it
  • What rights people have (access, correction, deletion, and so on)
  • How to complain to the ICO if they’re unhappy

Placement matters as much as content. Link it in your footer, sit it right next to any form that gathers data, and reference it in transactional emails too. The ICO’s privacy notice generator gives you a solid starting template rather than a blank page. Keep a simple version history so you can show what changed and when.

Pro Tip: Write your privacy notice for a nervous customer, not a solicitor. If your nan wouldn’t understand a sentence, rewrite it.

PECR has always said the same thing: tell people you’re setting cookies, explain what they do, and get consent for anything non-essential. No consent, no cookie. That hasn’t changed.

What has changed is the Data (Use and Access) Act 2025, which loosens things slightly from 5 February 2026. Under the new exceptions, a narrow band of low-risk, first-party cookies, such as ones controlling how your site looks or gathering basic first-party statistics, no longer need prior consent. Emergency assistance cookies get the same treatment. The catch: this exception has hard limits. Anything feeding advertising networks or shared with third parties still needs full opt-in consent, no exceptions.

Your banner still needs to get the mechanics right:

  • Genuine opt-in, not a pre-ticked box masquerading as consent
  • A reject option that’s just as visible as accept, not greyed out in a submenu
  • An easy way to withdraw consent later, not just to give it

Nearly six months is the refresh window the ICO recommends as a sensible default for storage and access technology consent, unless your circumstances demand something shorter. Log every consent decision through your cookie management platform or server logs, and list the third parties involved. BasicBS’s own cookie policy is a working example of how a small provider documents this in plain terms.

Choosing the right lawful basis for your site’s data

Consent isn’t the only lawful basis, and treating it as the default answer for everything is a common mistake. UK GDPR gives you six options, but three cover most website scenarios:

  • Consent — for marketing cookies, newsletter sign ups, non-essential tracking
  • Contract — for processing needed to fulfil an order or deliver a service someone’s paid for
  • Legitimate interests — for things like basic CRM record keeping, provided you can justify it and it doesn’t override the person’s own rights

Ask yourself: could I do this processing without asking permission and still treat the person fairly? If not, get consent, and record which basis you chose and why. Special category data, such as health or religious information, needs extra conditions beyond a standard lawful basis, and consent must always be genuinely withdrawable.

Security, DPIAs and what to do if something goes wrong

Baseline security isn’t glamorous, but it’s non-negotiable groundwork: an SSL certificate, regular software updates, working backups, and sensible account access controls that get reviewed occasionally rather than set once and forgotten.

You need a Data Protection Impact Assessment when your processing involves large-scale tracking, profiling, or special category data. The ICO’s DPIA templates make this far less painful than it sounds.

If a breach happens:

  • Assess how likely and severe the harm to individuals could be
  • Log the incident regardless of severity
  • Notify the ICO within 72 hours if the risk to people is real
  • Tell affected individuals directly when the risk is high

Pro Tip: Keep a one-page breach response plan pinned somewhere obvious. Panic is the enemy of the 72-hour clock.

ICO registration and free tools for small businesses

Most organisations processing personal data need to pay the ICO’s data protection fee, with the exact band depending on turnover and staff numbers, so check where you sit rather than assume you’re exempt.

The ICO doesn’t leave you to figure this out alone:

  • The privacy notice generator and self-assessment walk you through the basics for free
  • DPIA guidance templates save you commissioning a consultant
  • Recording your self-assessment answers gives you a paper trail if anyone ever asks how you reached your decisions

Your one-page compliance plan for this week

Day one: map your data flows and check your cookie banner actually works properly. Week one: publish your privacy notice, document lawful bases, and register with the ICO if the fee applies to you. Month one: run a DPIA if you need one, set your consent refresh reminder, and review third-party scripts.

  1. Site owner reviews forms and analytics tags
  2. Marketer confirms cookie categories and consent copy
  3. Developer implements the banner and logging
  4. Owner signs off the privacy notice and files it for reference

Bring in paid help once the fix touches code you can’t safely edit yourself, that’s usually the tipping point.

Pro Tip: Screenshot your consent banner and privacy notice once they’re live. That dated evidence is worth more than any policy document if a customer ever queries what you were showing them.

A working developer’s honest take on small-site compliance

Most small sites don’t fail GDPR because of malice, they fail because nobody owns the task. The privacy notice was copied in 2019 and never touched again. The cookie banner was installed once and forgotten. Fixing that isn’t expensive, it’s just neglected. A managed hosting setup that includes SSL and regular updates as standard removes half the security worry before you’ve even thought about cookies.

— Conor

How BasicBS handles the compliance groundwork for you

If reading that checklist made your afternoon disappear before your eyes, you’re not alone, and DIY is absolutely still an option if you’ve got the time. But if you’d rather someone else sorted the technical side, BasicBS builds UK-hosted websites with SSL included as standard, cookie and privacy notice implementation done properly from day one, and ongoing monthly support so nothing quietly goes out of date.

Basic-bs

Plans start with affordable monthly fees and sites go live within a week, which is quicker than many agencies take to reply to your first email. Have a look at our website examples to see the kind of builds we deliver, or read why cheap website development often fails before you commit to a bargain-bin option elsewhere. Ready to get your compliance sorted properly? Get started with BasicBS and ask for a compliance review alongside your build.

Sources

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

What is GDPR compliance for websites?

It means your site follows UK GDPR and the Data Protection Act 2018 whenever it collects personal data, covering lawful basis, transparency, security and individuals’ rights.

Does GDPR apply to the United Kingdom?

Yes. The UK operates its own version, UK GDPR, alongside the Data Protection Act 2018, enforced by the ICO.

Is my website GDPR compliant?

Run through the ICO’s self-assessment for small organisations; if your privacy notice, cookie banner and lawful basis records are all in place and current, you’re in reasonable shape.

Does a UK website need a privacy policy?

Yes, any UK site processing personal data needs a privacy notice covering what’s collected, why, and what rights visitors have, placed somewhere they’ll actually see it.

The ICO suggests roughly every six months as a sensible starting point, or sooner if your cookie purposes or third parties change.