Skip to content

GDPR and cookie consent for small business websites (EU & UK guide)

If people in the EU or UK visit your website, European privacy law applies to how you collect their data — even if your business is elsewhere. The good news: for most small business sites, compliance comes down to a few clear steps. (General information, not legal advice.)

Updated · Aethel Digital

The two laws that matter

  • GDPR (and the UK GDPR) governs personal data: names, emails, IP addresses, anything that identifies a person. You need a lawful reason to collect it, must say what you do with it, and must keep it secure.
  • The ePrivacy rules (PECR in the UK) govern cookies and similar tracking. Non-essential cookies — analytics, advertising, most embedded social widgets — need consent before they are set.

What a compliant cookie banner looks like

Regulators including the UK ICO and France's CNIL have been specific:

  • Nothing non-essential loads until the visitor agrees.
  • "Reject" is as easy as "Accept" — same prominence, same number of clicks.
  • No pre-ticked boxes, and continuing to browse is not consent.
  • Visitors can change their mind later as easily as they gave consent.
  • The banner says plainly what each category is for.

Strictly necessary cookies — the ones a site needs to work, such as security tokens or a shopping basket — don't need consent.

Contact forms and enquiries

A contact form collects personal data, so:

  • Only ask for what you need to reply.
  • Link to your privacy policy next to the form.
  • Don't add people to a marketing list unless they opt in separately (an unticked box).
  • Make sure the form submits over HTTPS and the data is stored securely.
  • Delete enquiries you no longer need.

Your privacy policy

It must say, in plain language: who you are and how to contact you; what data you collect and why; the lawful basis; who you share it with (your email provider, analytics, CRM); how long you keep it; and people's rights to access, correct and delete their data. A copied template that doesn't match what your site actually does is a common failure.

Analytics without the headache

Privacy-friendly, first-party analytics that don't set tracking cookies or share data with advertisers can, depending on configuration and country, reduce what you need consent for. Many businesses still ask for consent to be safe. Either way, it's worth checking which third-party scripts your site loads — each one is a data transfer you're responsible for.

What happens if you get it wrong

Fines can reach €20 million or 4% of global turnover for the most serious GDPR breaches, though small businesses usually face warnings, orders to fix and smaller penalties first. The bigger everyday risk is trust: a banner that bullies visitors into accepting, or a form that leaks data, costs you customers.

Questions

Does GDPR apply if my business is in the US?

It can. If you offer goods or services to people in the EU or UK, or monitor their behaviour (for example with analytics), GDPR may apply to that data.

Do I need a cookie banner if I only use Google Analytics?

In the EU and UK, standard Google Analytics sets non-essential cookies, so you need consent before it loads.

Is a free cookie banner plugin enough?

Only if it actually blocks scripts until consent and makes rejecting as easy as accepting. Many free banners only display a notice.

Want to know where your own site stands?

A free reading takes about twenty seconds — speed, search, mobile design, security and the path to contact.