We’re often asked by clients whether their website needs a privacy policy. The short answer is: if your website collects personal data, you should have one.
That includes something as simple as a contact form, newsletter sign-up, online booking form, shop checkout, analytics tracking, live chat, embedded video, membership area, enquiry form or downloadable lead magnet.
This guide is not legal advice, and it is not a substitute for getting a solicitor to review your own circumstances. However, it should help UK small businesses, sole traders, charities and website owners understand what a good privacy policy — more accurately called a privacy notice — normally needs to cover.
You should always tailor your privacy policy to your own business, your website, your systems and the type of data you actually collect.
What is a privacy policy?
A privacy policy explains how your organisation collects, uses, stores and shares personal data. In the UK, this is often called a privacy notice because its job is to give clear information to the people whose data you collect.
Personal data means information that can identify a living person, either directly or indirectly. This could include names, email addresses, phone numbers, postal addresses, order details, IP addresses, booking information, payment references, account details, enquiry messages, form submissions or marketing preferences.
Your privacy policy should be written in plain English. It should not be hidden in legal jargon, and it should not claim things that are not true. A simple, honest policy that reflects how your business actually works is usually better than a long generic document copied from another website.
Does every UK website need a privacy policy?
Most business websites do.
You are likely to need a privacy policy if your website has any of the following:
- a contact form
- newsletter sign-up
- online booking system
- e-commerce checkout
- customer account area
- live chat
- Google Analytics or similar tracking
- Meta Pixel, Google Ads tracking or other marketing pixels
- embedded videos or third-party tools
- membership, course or download areas
- comments, reviews or testimonials
- event registrations or ticketing
- lead magnets, quizzes or surveys
Even a small brochure website can collect personal data if someone submits an enquiry form or if tracking tools collect information about visitors.
What should a UK privacy policy include?
A useful privacy policy should answer the questions a real visitor might ask:
- Who is collecting my data?
- What information are they collecting?
- Why do they need it?
- How did they get it?
- What lawful basis are they relying on?
- Who will they share it with?
- Will it be sent outside the UK?
- How long will they keep it?
- What are my rights?
- How can I contact them?
- How can I complain?
The sections below give you a practical structure you can adapt for your own website.
1. Who you are
Your policy should clearly say who is responsible for the website and the personal data it collects.
For example, you might include:
- your business or trading name
- your registered company name, if different
- your company number, if applicable
- your registered office or business address
- your contact email address
- your data protection contact, if different
- your ICO registration details, if applicable
Not every small organisation needs a Data Protection Officer, so avoid saying you have one unless you actually do.
2. What personal data you collect
List the types of information your business collects. Keep this specific to your organisation.
For a typical small business website, this might include:
- name and contact details
- email address and phone number
- billing and delivery address
- order history or booking details
- messages submitted through contact forms
- newsletter preferences
- account login details
- payment references
- website usage information, such as pages visited or forms submitted
- IP address, browser type and device information
- any information a customer chooses to include in an enquiry
If you collect sensitive information — such as health details, children’s information, financial details, identity documents or information about criminal convictions — you should be especially careful and consider getting legal advice.
3. How you collect personal data
Explain where the information comes from. This might include:
- when someone completes a website form
- when someone signs up to your newsletter
- when someone places an order
- when someone books a call or appointment
- when someone creates an account
- when someone emails, phones or messages you
- when someone interacts with your social media pages
- through website cookies and analytics tools
- from third-party platforms you use to run your business
The important thing is to be clear and transparent. If your website uses tools such as Google Analytics, Meta Pixel, Mailchimp, Stripe, PayPal, Calendly, HubSpot, Tawk.to, YouTube embeds, WooCommerce, Shopify, Eventbrite or similar services, your privacy policy should reflect that.
4. Why you use personal data
Your privacy policy should explain why you collect and use people’s information.
Common reasons include:
- responding to enquiries
- providing products or services
- processing orders and payments
- delivering digital downloads or online courses
- managing bookings, events or appointments
- creating and managing customer accounts
- sending service updates
- sending marketing emails where allowed
- improving your website and services
- preventing fraud and keeping your website secure
- keeping business, tax and accounting records
- complying with legal obligations
Do not include reasons that do not apply to your business. A privacy policy should describe what actually happens, not what might happen on a completely different website.
5. Your lawful basis for using personal data
Under UK data protection law, you need a lawful basis for using personal data. The most common ones for small business websites are:
Contract – for example, when you need someone’s details to provide a service, fulfil an order or manage a booking.
Consent – for example, when someone actively signs up to receive certain types of marketing emails.
Legitimate interests – for example, responding to business enquiries, improving your services or protecting your website, provided your interests do not unfairly override the person’s rights.
Legal obligation – for example, keeping accounting records or complying with tax rules.
Your policy should match each purpose with the correct lawful basis. Avoid saying “we use consent for everything” unless that is genuinely how your business works.
6. Who you share personal data with
Most businesses share data with trusted service providers. This does not necessarily mean selling data. It often means using other systems to help run your website or business.
Examples may include:
- website hosting providers
- email providers
- payment processors
- accounting software
- CRM systems
- email marketing platforms
- booking systems
- analytics providers
- delivery or fulfilment providers
- IT support providers
- professional advisers
- regulators or authorities where required by law
You should name key providers where practical, or at least describe the categories of provider you use. You should also make sure these providers handle data securely and have appropriate terms in place.
7. International data transfers
Many popular website and business tools are operated by companies outside the UK. For example, your email marketing, analytics, CRM, booking system or payment provider may process data in another country.
Your privacy policy should explain whether personal data may be transferred outside the UK and what safeguards are used. For many small businesses, this section will refer to using reputable third-party providers that apply recognised data protection safeguards.
This is an area where wording should be checked carefully, especially if you use many international platforms.
8. How long you keep personal data
Your policy should explain how long you keep different types of information, or how you decide how long to keep it.
For example:
- enquiry form messages may be kept for a limited period after the enquiry is resolved
- customer and order records may be kept for accounting and tax reasons
- newsletter data may be kept until someone unsubscribes or asks to be removed
- account data may be kept while the account remains active
- analytics data may be kept according to your analytics platform settings
- legal or complaint records may need to be kept for longer
Avoid vague wording such as “we keep data for as long as we want”. It is better to explain your retention periods or the criteria you use to decide them.
9. Marketing emails
If you send marketing emails, your privacy policy should explain how people get added to your list and how they can opt out.
You should also make sure your sign-up forms, checkout forms and enquiry forms are clear. People should not be surprised to receive marketing emails because they filled in an unrelated form.
Good practice includes:
- being clear what someone is signing up for
- not using pre-ticked consent boxes
- keeping a record of consent where you rely on consent
- including an unsubscribe link in marketing emails
- honouring opt-out requests promptly
- not adding people to general marketing lists without a proper basis
10. Cookies, analytics and tracking
If your website uses cookies or similar technologies, you should explain what they are used for. This may be covered in your privacy policy, your cookie policy, or both.
Typical categories include:
- Necessary cookies – needed for the website to function properly.
- Functional cookies – used for features such as preferences, chat tools or embedded content.
- Analytics cookies – used to understand how people use the website.
- Marketing cookies – used for advertising, remarketing or tracking across websites.
Cookie rules continue to evolve, so it is important not to rely on an old banner or an outdated “we use cookies” sentence copied from another site. Your cookie notice should be accurate, and visitors should be given appropriate information and choices for non-essential cookies and tracking technologies.
11. People’s rights
Your privacy policy should explain that individuals have rights over their personal data. These may include the right to:
- be informed about how their data is used
- access a copy of their personal data
- ask for inaccurate data to be corrected
- ask for data to be erased in certain circumstances
- ask for processing to be restricted
- object to certain types of processing
- ask for data portability in certain circumstances
- withdraw consent where consent is the lawful basis
- complain to the Information Commissioner’s Office
You should also explain how someone can contact you to exercise their rights.
12. Security
Your privacy policy should say that you take reasonable steps to protect personal data. You do not need to publish a detailed security blueprint, but you can mention practical measures such as:
- using secure website hosting
- using SSL/HTTPS
- limiting access to personal data
- using strong passwords and multi-factor authentication where possible
- keeping website software, plugins and systems updated
- using reputable third-party providers
- backing up important data
- reviewing access when staff or suppliers change
Security wording should be honest. No website can guarantee perfect security, but businesses are expected to take appropriate care.
13. Children’s data
If your website is aimed at children, likely to be used by children, or collects information about children, you should take extra care. This is particularly relevant for schools, tutors, clubs, charities, family services, online courses, children’s activities and youth-focused organisations.
Your policy should explain what data is collected, why it is needed, who provides it, how it is protected and who it may be shared with.
If children’s data is central to your business, use a generic template only as a starting point and get proper advice.
14. Links to other websites
Many websites link to third-party platforms such as social media pages, payment pages, booking tools, YouTube, event platforms or external resources.
Your policy should explain that your website may contain links to other websites and that visitors should review those organisations’ own privacy policies when they leave your site.
15. Complaints
Your privacy policy should tell people how to raise a concern with you first. It should also explain that they can complain to the Information Commissioner’s Office if they are unhappy with how their data has been handled.
Include a clear contact email address for privacy-related questions. This might be a dedicated email such as privacy@example.co.uk, or a general business email if that is more realistic for your organisation.
Example privacy policy structure
Here is a simple structure you can adapt for your own website:
- Introduction
- Who we are
- How to contact us
- What personal data we collect
- How we collect personal data
- Why we use personal data
- Our lawful basis for using personal data
- Who we share personal data with
- International transfers
- How long we keep personal data
- Marketing communications
- Cookies and analytics
- Data security
- Your rights
- Children’s data, if relevant
- Links to other websites
- How to complain
- Changes to this policy
- Last updated date
Common privacy policy mistakes
Here are some of the mistakes we regularly see on small business websites:
- copying a policy from another business without changing the details
- using a recruitment, medical or e-commerce policy for a completely different type of business
- claiming to use tools that are not actually on the website
- forgetting to mention analytics, pixels, live chat or email marketing tools
- saying “we do not share data” when data is shared with hosting, email or payment providers
- not explaining how long data is kept
- not giving a clear contact route for privacy questions
- using a cookie banner that does not match the tracking actually installed
- failing to update the policy after adding new plugins, forms or marketing tools
A practical website owner checklist
Before publishing or updating your privacy policy, review your website and ask:
- What forms are on the site?
- Where do form submissions go?
- Who receives enquiry emails?
- Do we store form entries in WordPress or another CMS?
- Do we use Google Analytics, Meta Pixel or similar tracking?
- Do we use live chat?
- Do we embed YouTube, Vimeo, maps or social media feeds?
- Do we take payments?
- Do we have customer accounts?
- Do we send email newsletters?
- Do we use a CRM?
- Do we collect sensitive information?
- Do children use the website?
- Do our cookie banner and privacy policy match what the website actually does?
A practical example privacy policy for a typical blog or shop website
The guide above explains what a privacy policy should include. However, it is often easier to understand when you can see an example in full.
Below is a sample privacy policy for a typical UK small business website that has a blog, contact form, shopping cart, email newsletter, social media links, Google Analytics, Google Search Console, embedded content and a cookie banner.
This is not legal advice and should not be copied blindly. Every website is different. Before using wording like this, you should replace the example details with your own business information, check which plugins and third-party services your website actually uses, and remove anything that does not apply.
Example Privacy Policy
Last updated: [Insert date]
1. Who we are
This website is operated by [Your Business Name].
Our website address is: [https://www.example.co.uk]
Our contact details are:
- Business name: [Your Business Name]
- Trading name: [Trading Name, if different]
- Company number: [Company number, if applicable]
- Registered address: [Registered or business address]
- Email: [privacy@example.co.uk]
- Telephone: [Phone number, if applicable]
This privacy policy explains how we collect, use, store and protect your personal information when you use our website, contact us, buy from us, subscribe to our mailing list or interact with us online.
2. What personal information we collect
We may collect and use the following types of personal information:
- your name
- your email address
- your phone number
- your billing and delivery address
- details of products or services you buy from us
- messages you send through our contact forms
- newsletter subscription preferences
- account login details, if you create an account
- order notes or information you choose to provide
- payment confirmation and transaction references
- IP address, browser type, device type and website usage information
- cookie and analytics information
- social media interactions, where you engage with us through platforms such as Facebook, Instagram, LinkedIn, YouTube or X
We do not usually collect sensitive personal information unless you choose to provide it to us in a message, form or order note. Please avoid sending sensitive information unless it is necessary.
3. How we collect your information
We collect personal information when you:
- visit our website
- complete a contact form
- leave a blog comment, if comments are enabled
- subscribe to our newsletter
- place an order through our shopping cart
- create a customer account
- download a free or paid resource
- book a service or appointment
- email, phone or message us
- interact with our social media pages
- accept or manage cookies through our cookie banner
We may also receive limited information from third-party services we use to run our website and business, such as payment processors, email marketing platforms, analytics tools, booking systems, social media platforms and website security tools.
4. Why we use your information
We use your personal information to:
- respond to your enquiries
- provide products, downloads or services you have requested
- process orders and payments
- deliver physical or digital products
- manage bookings, appointments or events
- create and manage customer accounts
- send service-related emails, such as order confirmations or account updates
- send newsletters or marketing emails where we have permission or another lawful basis to do so
- improve our website, products and services
- monitor website traffic and performance
- protect our website from spam, fraud and security threats
- keep accounting and tax records
- comply with legal obligations
5. Our lawful basis for using your information
Under UK data protection law, we need a lawful basis to use your personal information. Depending on the situation, we may rely on:
Contract – when we need your information to provide a product or service, process an order, deliver a download, manage a booking or respond to a request before entering into a contract.
Consent – when you have actively agreed to something, such as subscribing to our newsletter or accepting optional cookies.
Legitimate interests – when we use your information in a reasonable way to run and improve our business, respond to enquiries, understand website performance, prevent fraud or protect our website, provided your rights do not override those interests.
Legal obligation – when we need to keep certain records for tax, accounting or legal reasons.
6. Blog comments
If blog comments are enabled and you leave a comment on our website, we may collect the information shown in the comments form, your IP address and browser information to help detect spam.
Your name and comment may be visible publicly on the website. Your email address will not normally be published. Please do not include private or sensitive information in public comments.
We may use spam detection or website security services to help protect the website from unwanted or harmful content.
7. Shopping cart, orders and payments
If you buy something through our website, we collect the information needed to process your order. This may include your name, email address, billing address, delivery address, phone number, order details and payment status.
Payments are usually processed by third-party payment providers such as Stripe, PayPal, Square, WooPayments or another payment processor. We do not normally store your full card details on our website. Your payment provider will process payment information according to its own privacy policy and security standards.
We keep order and transaction records for business, customer service, accounting and tax purposes.
8. Email newsletters and marketing
If you subscribe to our newsletter or marketing emails, we will use your name and email address to send you updates, offers, news, blog posts or other information we believe may be relevant to you.
We may use an email marketing provider such as Mailchimp, MailerLite, Brevo, ConvertKit or a similar platform to manage our mailing list.
You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in our emails or by contacting us directly.
We will not sell your email address to other organisations.
9. Contact forms
When you submit a contact form, we collect the information you provide so that we can respond to your enquiry. This may include your name, email address, phone number and message.
Form submissions may be sent to us by email and may also be stored securely within our website or form plugin. We only keep enquiry information for as long as reasonably necessary to respond to you, manage our relationship with you and keep appropriate business records.
10. Cookies and similar technologies
Our website uses cookies and similar technologies. Cookies are small files placed on your device that help websites work, remember preferences, measure performance or support marketing activity.
We may use the following types of cookies:
- Necessary cookies – these help the website function properly, such as remembering items in your basket or keeping the website secure.
- Functional cookies – these may remember your preferences or support website features.
- Analytics cookies – these help us understand how visitors use our website.
- Marketing cookies – these may help us measure advertising or show relevant content on other platforms.
We use a cookie consent tool such as CookieYes, or a similar cookie management plugin, to display a cookie banner and allow visitors to accept, reject or manage non-essential cookies.
You can usually change your cookie preferences at any time using the cookie settings link or floating cookie icon on our website. You can also control cookies through your browser settings.
11. Google services
We may use Google services such as Google Analytics, Google Search Console, Google Tag Manager, Google Ads, Google Maps, YouTube embeds or Google reCAPTCHA.
These tools may collect information such as your IP address, device information, browser information, pages visited, referral source, approximate location and interaction data.
We use this information to understand website performance, improve our content, protect forms from spam, measure marketing activity and help visitors use our website.
Where required, non-essential Google tracking tools should only run after you have given the appropriate cookie consent.
12. Social media and embedded content
Our website may include links to social media platforms or embedded content from services such as Facebook, Instagram, LinkedIn, YouTube, Vimeo, TikTok, X or Pinterest.
Embedded content from other websites behaves in a similar way to visiting those websites directly. These third-party websites may collect data about you, use cookies, embed additional tracking and monitor your interaction with their content, especially if you are logged into your account with that service.
When you click a social media link or interact with embedded content, the relevant platform will handle your information according to its own privacy policy.
13. Who we share your information with
We only share personal information where necessary to run our website, provide our services, meet legal obligations or use trusted third-party systems.
We may share information with:
- website hosting providers
- website developers and IT support providers
- payment processors
- email marketing platforms
- analytics and reporting tools
- shopping cart and e-commerce platforms
- booking or event systems
- accounting and bookkeeping providers
- delivery, fulfilment or courier services
- spam prevention and website security tools
- professional advisers, such as accountants or solicitors
- regulators, authorities or law enforcement where required by law
We do not sell your personal information.
14. International transfers
Some of the third-party services we use may process personal information outside the UK. This may include providers of email marketing, analytics, payment processing, cloud storage, social media, security, hosting or business software.
Where personal information is transferred outside the UK, we expect our providers to use appropriate safeguards, such as recognised contractual protections or other lawful transfer mechanisms.
15. How long we keep your information
We only keep personal information for as long as necessary for the purpose it was collected, including legal, accounting, reporting and customer service purposes.
As a general guide:
- contact form enquiries may be kept for as long as needed to respond and manage future communication
- customer order records may be kept for accounting and tax purposes
- newsletter records are kept until you unsubscribe or ask us to remove you
- customer account information is kept while your account remains active or as needed for order history and legal records
- analytics data is kept according to the settings in our analytics tools
- legal, complaint or security records may be kept for longer where necessary
16. How we protect your information
We take reasonable steps to protect personal information from loss, misuse, unauthorised access, disclosure or alteration.
These steps may include:
- using secure website hosting
- using SSL/HTTPS encryption
- limiting access to personal information
- using strong passwords and two-factor authentication where possible
- keeping website software and plugins updated
- using reputable third-party providers
- backing up important website data
- monitoring the website for spam, malware and security threats
No website or online system can be guaranteed to be completely secure, but we take appropriate steps to reduce risk.
17. Your rights
Under UK data protection law, you have rights over your personal information. These may include the right to:
- ask for a copy of the personal information we hold about you
- ask us to correct inaccurate or incomplete information
- ask us to delete your information in certain circumstances
- ask us to restrict how we use your information
- object to certain uses of your information
- withdraw consent where we rely on consent
- ask for your information to be transferred to another provider in certain circumstances
- complain to the Information Commissioner’s Office
To exercise your rights, please contact us using the details at the top of this policy.
18. Children’s privacy
Our website is not usually aimed at children and we do not knowingly collect personal information from children without appropriate consent.
If you believe a child has provided us with personal information, please contact us and we will review the information and take appropriate action.
19. Links to other websites
Our website may contain links to other websites. We are not responsible for the privacy practices, content or security of those third-party websites.
When you leave our website, you should read the privacy policy of the website you visit.
20. Complaints
If you have any concerns about how we use your personal information, please contact us first so we can try to resolve the issue.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection.
ICO website: https://ico.org.uk
21. Changes to this privacy policy
We may update this privacy policy from time to time to reflect changes to our website, services, plugins, third-party tools or legal requirements.
The latest version will always be published on this page. Please check this page occasionally to make sure you are happy with any changes.
Before using this example
This example is designed to show the sort of wording a typical small business blog or shop website might use. It should be treated as a starting point, not a finished legal document.
Before publishing your own version, check:
- which contact forms your website uses
- whether form entries are stored in WordPress
- which payment provider you use
- which email marketing platform you use
- whether Google Analytics, Tag Manager, Ads or Search Console are installed
- whether Meta Pixel, TikTok Pixel, Pinterest Tag or LinkedIn Insight Tag are installed
- whether YouTube, Vimeo, Google Maps or social feeds are embedded
- whether your cookie banner blocks non-essential cookies before consent
- whether your cookie policy matches the cookies actually used on your website
- whether your privacy policy matches your real business processes
For WordPress websites, a cookie consent plugin such as CookieYes can be a practical way to add a cookie banner, scan for cookies, group cookies by category and allow visitors to manage their consent preferences. However, a plugin is only part of the solution. It still needs to be configured properly, and your privacy policy should still accurately describe how your website collects and uses personal information.
Final thought
A privacy policy should not be treated as a one-off legal page that is forgotten after launch. It should be reviewed whenever your website changes, especially if you add new forms, analytics tools, advertising pixels, payment systems, booking tools, membership features, downloads, courses or email marketing platforms.
At DADD, we can help website owners review the practical side of their privacy setup — including forms, cookies, tracking tools, analytics, plugins, email marketing and the pages visitors actually see.
For legal certainty, especially if your business handles sensitive data, children’s data, health information, financial information or complex marketing activity, you should also take professional legal advice.
Last updated: June 2026







