GDPR compliance Staffordshire businesses are legally required to maintain affects every website that collects personal data from visitors. The word “GDPR” still makes most business owners’ eyes glaze over – and with good reason. When the regulation came into force in 2018, it was accompanied by a wave of confusing, often contradictory guidance that left many small businesses unsure what they actually needed to do.
Eight years on, things are clearer. The rules haven’t gone away – if anything, enforcement has increased – but the practical requirements for a typical small business website are more straightforward than the 2018 hysteria suggested.
Here’s what you actually need to know in 2026.
UK GDPR vs EU GDPR: What’s Different Post-Brexit?
When the UK left the EU, GDPR didn’t leave with it. The UK adopted its own version – known as UK GDPR – which runs alongside the Data Protection Act 2018 and is enforced by the Information Commissioner’s Office (ICO).
In practice, UK GDPR is very similar to EU GDPR. The core principles are the same: data must be collected lawfully, for a specific purpose, kept only as long as necessary, and protected appropriately.
The key differences are administrative:
- The UK has its own ICO rather than falling under EU supervisory authorities
- If you serve customers in both the UK and EU, you technically need to comply with both frameworks (though the overlap is significant)
- The UK is exploring some reforms, but as of 2026 the core requirements remain substantively aligned with EU GDPR
For most small UK businesses serving UK customers, UK GDPR is what applies, and it requires essentially the same practical steps as the original regulation.
Does UK GDPR Apply to Your Website?
Yes – if your website:
- Collects names, email addresses, phone numbers, or any other personal information (a contact form counts)
- Uses cookies that track user behaviour (Google Analytics counts)
- Processes payments or stores customer data
- Has a newsletter sign-up or any kind of mailing list
That covers the vast majority of business websites. Even a simple five-page site with a contact form and Google Analytics is processing personal data.
What Your Website Actually Needs
1. A Privacy Policy
This is non-negotiable. Your privacy policy needs to clearly explain:
- What personal data you collect
- Why you collect it (the “lawful basis”)
- How long you keep it
- Who you share it with (including third parties like Google Analytics, your email platform, your hosting provider)
- How people can request access to their data or ask you to delete it
- Your ICO registration number (if required)
A privacy policy copied from another website without modification is worse than useless. It needs to accurately reflect what your site actually does with data.
2. A Cookie Banner That Works
Not all cookie banners meet the legal standard. A compliant cookie consent mechanism needs to:
- Explain what cookies are being set and why, before they are set
- Give users a genuine choice to accept or decline non-essential cookies (analytics, marketing, tracking)
- Be as easy to decline as it is to accept
- Remember the user’s choice
- Not pre-tick optional cookie categories
Essential cookies (the ones needed to make the site function) don’t require consent. Analytics and marketing cookies do.
3. A Terms and Conditions Page
While not strictly a data protection requirement, terms and conditions set the legal basis for your relationship with visitors and customers. If you sell products or services through your site, or collect any personal data, you should have them.
4. Secure Data Transmission (HTTPS)
Your website should run over HTTPS – indicated by the padlock in the browser. This encrypts data sent between the visitor and your server, which is a baseline security requirement under UK GDPR’s data protection principles.
5. Secure Handling of Form Submissions
If your contact form submissions are emailed to you and then deleted, that’s a reasonable setup for many small businesses. Just make sure your email account is secured, you’re not storing enquiry data indefinitely, and your email provider’s privacy terms are referenced in your privacy policy.
Do You Need to Register With the ICO?
Most organisations that process personal data need to pay a data protection fee to the ICO – currently £40/year for most small businesses (Tier 1). There are some exemptions, but if you have a business website with a contact form and use Google Analytics, you almost certainly need to register.
You can check and register at ico.org.uk. The fine for not registering when required can be up to £4,000 – significantly more than the annual fee.
The Common Gaps We See on Business Websites
In 14 years of building and auditing websites, these are the most common data protection gaps we find:
- Privacy policy that doesn’t mention Google Analytics – if you’re using GA4, it must be named as a third party that receives data
- Cookie banners that don’t actually block cookies – some plugins display a banner but load analytics scripts regardless of what the user clicks
- No ICO registration number in the privacy policy – required for most businesses, easy to add once you have it
- Outdated privacy policy that hasn’t been reviewed since it was first written
A Simple Checklist for 2026
- Privacy policy is published, accurate, and up to date
- Privacy policy names all third-party services that receive visitor data
- Privacy policy includes your ICO registration number
- Cookie banner gives visitors a genuine choice to accept or decline non-essential cookies
- Cookie banner is as easy to decline as it is to accept
- Website runs over HTTPS
- ICO data protection fee is paid and up to date (ico.org.uk)
- You have a process for handling data subject access requests
If you can tick all of these, your site is in reasonable shape. If you can’t – start with the ones that carry the most risk: ICO registration, cookie consent, and privacy policy accuracy.
If you’d like us to review your website’s data protection setup as part of a broader website audit, get in touch – it’s something we include in our pre-launch checklist for every site we build.
Spires Web Tech are a web design agency based in Burntwood, Staffordshire. We’ve been building compliant, well-structured websites for businesses across the West Midlands since 2010.