GDPR and cookies on a small business website
GDPR and cookies on a small business website comes down to two things you can check this week: what your site stores on a visitor's device, and what it does with the details people type into it. Non-essential cookies need consent before they're set, unless a narrow exception applies, and contact form data needs a reason to be kept and a date to be deleted.
This is general information, not legal advice. The rules come from UK GDPR and the Privacy and Electronic Communications Regulations (PECR).
What a compliant cookie banner does
The ICO's guidance on storage and access technologies says that if no exception applies, you must get consent before the cookie or tag is used. A banner saying "by continuing to use our website, you consent" doesn't meet that. The ICO gives that wording as an example of bad practice.
Refusing has to be as easy as accepting. That means a "Reject all" button as prominent as "Accept all". The ICO's consent guidance also says pre-ticked boxes and silence are not consent, so optional toggles start in the off position. People must be able to change their mind later, with the same ease, through something like a cookie settings link in the footer.
Some storage needs no consent at all. The strictly necessary exception covers things the site can't work without from the visitor's point of view. Keeping someone signed in counts, and so does remembering the choice they made in your cookie banner. Advertising never counts, however much it helps pay for the site.
What changed in 2026
The Data (Use and Access) Act 2025 added new exceptions to PECR. Under the government's Commencement No. 6 Regulations, the cookie changes came into force on 5 February 2026, and the ICO finalised its updated guidance on 29 April 2026.
Two of the new exceptions matter for a typical small business site:
- Statistical purposes: analytics whose sole purpose is aggregate statistics about how your site is used, to improve it. Page visits and how people arrived can qualify. Tracking or profiling individuals cannot, and nor can advertising.
- Appearance: storage whose sole purpose is to adapt how the site looks or works to the visitor's preference, such as a chosen language.
For both, the ICO says you must give clear information about the purpose and a simple, free way to object. If you skip either, the exception doesn't apply and you're back to needing consent. If you use a third-party analytics tool under the statistical exception, the ICO says that provider must act as your processor and only use the data to improve your site.
The same Act raised the ICO's maximum fines under PECR to the UK GDPR level, and the ICO's statement on commencement confirms that applied from 5 February 2026.
What your contact form stores, and for how long
A contact form collects personal data, such as a name and email address alongside the message itself. Under the storage limitation principle, the ICO says you must not keep it for longer than you need it. You need to be able to justify that period.
The law doesn't give a number for enquiries. The ICO expects a policy with standard retention periods where you can set them. When the period ends, delete or anonymise the data. Check where submissions actually land. A copy can sit in your inbox as well as the form tool's dashboard, and your period applies to both.
What your privacy notice must say
The ICO's guidance on the right to be informed lists what you must always tell people when you collect their data. Start with who you are and how to contact you. Then give the purposes you use the data for and the lawful basis for each.
You must always give the retention period, or the criteria you use to set it. You must explain people's rights and that they can complain to the ICO. Other items depend on your situation, such as who you share the data with. If you rely on consent, say people can withdraw it.
Who processes the data
For your website, you're the controller. You decide why the data is collected and how. A processor handles it on your behalf. Your hosting company and the service behind your contact form can be processors. So can your email provider and your analytics tool.
The ICO's guidance on contracts says that whenever a controller uses a processor, there must be a written contract binding the processor. With an online provider this can be a data processing agreement within their terms. Find it and keep a copy. Securing those systems is a separate job, covered in our piece on Cyber Essentials for small businesses.
Where Eight Mile fits
Getting GDPR and cookies on a small business website right is partly a build question. Our website service covers design and build, and we host the site and register the domain. Branded email on your own domain is included, and so are page titles and sitemaps. One monthly figure covers the build and the care afterwards. Our own cookie policy states that the site uses no advertising or tracking cookies.
If you want to know what your current site sets and where its form data goes, talk to an engineer. Tell us the address of the site and which tools it uses.