If your website collects any personal data from visitors, you need a privacy policy under UK law. That means almost every UK business website, because contact forms, newsletter sign-ups, analytics tools, and booking widgets all count as data collection. The Data Protection Act 2018 and UK GDPR together require you to tell people what you collect, why, and how long you keep it. Your quickest starting point is the ICO's privacy notice generator, which is free, built for small organisations, and produces a bespoke document you can publish the same day.
Key takeaways
A UK website privacy policy is a legal requirement under UK GDPR and the Data Protection Act 2018 for any site that collects personal data, and it must accurately describe your actual processing, lawful bases, retention periods, and data subject rights.
| Point | Details |
|---|---|
| Legal requirement | UK GDPR and the Data Protection Act 2018 require a privacy notice if your site collects any personal data. |
| Core clauses | Include who you are, what you collect, lawful basis, purpose, recipients, retention periods, and contact details. |
| Cookies need PECR compliance | Non-essential cookies require active consent under PECR; pre-ticked boxes and passive browsing do not count. |
| Keep it current | Review your policy after adding any new tool or data activity, and log every change with a version date. |
| Ace-sites publishing | Ace-sites lets you publish and update your privacy policy page without code, with SSL and footer links included. |
Table of Contents
- Does your UK website legally need a privacy policy?
- What must your UK privacy policy actually contain?
- Cookies and consent: what PECR means for your site
- How to create and publish a UK privacy policy: a step-by-step guide
- When and how to update your privacy policy
- Common mistakes that attract ICO attention and how to fix them
- Publishing your privacy policy: a practical checklist for small businesses
- Why a clear privacy policy is good for your business, not just a legal box to tick
- Your privacy policy, published and up to date with Ace-sites
- Sources
Does your UK website legally need a privacy policy?
Yes, and the threshold is lower than most small business owners expect. Under UK GDPR and the Data Protection Act 2018, any organisation that processes personal data must give individuals a privacy notice. "Processing" covers collecting, storing, viewing, sharing, or deleting data, so if your site does any of those things, the obligation applies to you.
Gov confirms that transparency is a core duty, not an optional extra. Articles 13 and 14 of UK GDPR set out exactly what information you must provide: once at the point of collection (Article 13) and when you obtain data indirectly, such as from a third-party list (Article 14).
The ICO explains that most organisations holding personal data must provide a privacy notice covering what you collect, why you need it, how you use it, and how long you keep it. Alongside UK GDPR, the Privacy and Electronic Communications Regulations (PECR) adds a separate layer of rules around cookies and electronic marketing, which we cover in detail below.
Common triggers that make a privacy policy necessary for your site include:
- A contact form that captures names, email addresses, or phone numbers
- An e-commerce checkout that processes payment and delivery details
- A newsletter or mailing list sign-up
- Google Analytics, Meta Pixel, or any other analytics or tracking tool
- Embedded third-party widgets such as booking systems, live chat, or social media feeds
- User accounts or login areas
- Job application forms
If your site does any one of these things, you need a compliant privacy notice published and accessible to visitors.
What must your UK privacy policy actually contain?
The ICO's guidance on how to write a privacy notice maps directly to the transparency requirements in Articles 13 and 14 of UK GDPR. Every clause below has a legal basis; none of them are optional padding.
| Clause | What to include | Legal basis |
|---|---|---|
| Who you are | Your full business name, trading name if different, and registered address | Article 13(1)(a) UK GDPR |
| What data you collect | Specific categories: names, emails, IP addresses, payment details, usage data | Article 13(1)(e) |
| Lawful basis | The legal ground for each processing activity | Article 13(1)(c) |
| Purpose | Why you collect each type of data | Article 13(1)(c) |
| Recipients | Who you share data with (processors, third parties, sub-contractors) | Article 13(1)(e) |
| International transfers | Whether data leaves the UK and what safeguards apply | Article 13(1)(f) |
| Retention periods | How long you keep each category of data | Article 13(2)(a) |
| Data subject rights | Rights to access, rectify, erase, restrict, object, and portability | Article 13(2)(b) |
| Contact details | How to reach you or your DPO to exercise rights | Article 13(1)(a) |
Lawful bases explained briefly. You must identify at least one lawful basis for each processing activity. The three most common for small business websites are:
- Consent: the person has actively agreed, for example by ticking an opt-in box for a newsletter. Consent must be freely given, specific, and easy to withdraw.
- Contract: processing is necessary to fulfil a contract with the person, for example processing a delivery address to complete an order.
- Legitimate interests: you have a genuine business reason that is not overridden by the individual's rights. Analytics for improving your site often falls here, but you must document your reasoning.
Retention periods. Vague phrases like "we keep data for as long as necessary" are not compliant. Give specific periods where you can. Common examples: newsletter subscriber emails until unsubscribe plus 30 days; order records for six years to meet HMRC requirements; support enquiry records for two years after resolution.
Contact block. Your policy must include a clear way for people to exercise their rights. A compliant contact block looks like this:
To exercise any of your rights, or to ask a question about how we use your data, contact us at: [email address] or [postal address]. We will respond within one calendar month.
Cookies and consent: what PECR means for your site
A privacy policy and a cookie policy are not the same thing, though they often sit together. PECR is the separate regulation that governs cookies and electronic marketing in the UK, and it requires you to obtain informed consent before setting any non-essential cookie on a visitor's device.
Strictly necessary cookies are exempt. These include session cookies that keep a shopping basket working, or cookies that remember a user's login state. You do not need consent for these, but you should still describe them in your policy.
Non-essential cookies cover analytics (Google Analytics, for example), advertising pixels, social media trackers, and personalisation tools. For these, PECR requires that consent is informed, freely given, and revocable. That means your cookie banner must offer a genuine "reject" option, not just an "accept all" button with no alternative. Consent must be recorded so you can demonstrate it if the ICO asks.
Practically, this means:
- Scripts for non-essential cookies must be blocked until the visitor consents
- The banner must name the cookie categories clearly
- Visitors must be able to withdraw consent as easily as they gave it
- Your privacy policy should describe each cookie category and link to your full cookie policy or cookie settings
Pro Tip: Match the cookie category names in your banner exactly to the names used in your privacy policy. If your banner says "analytics cookies" but your policy says "performance cookies", visitors cannot tell whether they refer to the same thing. Consistent naming reduces confusion and strengthens your compliance position.
How to create and publish a UK privacy policy: a step-by-step guide
There are four realistic routes for a small business: the ICO generator, a free template, a paid template, or a solicitor-drafted policy. The right choice depends on how complex your data processing is.
Step 1: Inventory your data flows. Before you write a single word, list every way your site collects, stores, or shares personal data. Go through each form, plugin, and third-party tool. Note what data each one captures, where it is stored, and who has access.
Step 2: Choose your creation route.
- ICO generator — best for straightforward sites with standard processing (contact forms, basic analytics, no special category data). Free, quick, and produces a document that meets Articles 13–14 by design.
- Free vetted template — free UK GDPR-compliant templates are available from specialist providers, but you must customise every clause to reflect your actual processing. A template left unchanged is worse than useless; it may describe data you do not collect or omit data you do.
- Paid template — services such as LawDepot UK and GetTerms offer guided questionnaires that generate a customised policy. These are a good middle ground when your processing is slightly more complex.
- Solicitor-drafted policy — necessary if you process special category data (health, financial, biometric), run a subscription service with complex consent flows, or share data internationally without standard contractual clauses in place. Legal publishers such as Practical Law (Thomson Reuters) publish model policies for lawyers to adapt.
Step 3: Draft and customise. Work through each clause in the table above. Replace every placeholder with your actual business name, contact details, data types, and retention periods. Do not leave generic text in place.
Step 4: Get a second read. Ask someone unfamiliar with your business to read the draft. If they cannot understand what data you collect or how to contact you to exercise their rights, rewrite those sections.
Step 5: Publish it correctly. A policy buried in a subfolder nobody visits does not satisfy the transparency obligation. Publish it so it is:
- Linked in your website footer on every page
- Linked at every point of data collection (contact form, checkout, sign-up box)
- Accessible on mobile without horizontal scrolling
- Dated with the version date clearly visible at the top
Step 6: Link your cookie banner to the policy. Your cookie banner or cookie settings page should include a direct link to the relevant section of your privacy policy. See the how to publish a website in the UK guide for practical placement advice.
A sample privacy notice from NI Business Info shows how a structured, readable policy looks in practice, which is useful if you want to sense-check your own layout before publishing.
When and how to update your privacy policy
Publishing a policy once and forgetting it is one of the most common compliance failures. Your policy must reflect your actual processing at all times, which means it needs a review schedule and a versioning system.
Recommended review triggers. Review your policy whenever any of the following happen:
- You add a new tool, plugin, or third-party service that processes visitor data
- You start a new marketing activity (email campaigns, retargeting ads)
- You change your data retention periods
- You move to a new hosting provider or CRM
- UK data protection law changes
- The ICO issues new guidance relevant to your sector
Beyond event-driven reviews, an annual check is good practice even if nothing has changed. Set a calendar reminder for the same month each year.
Versioning. Every published version of your policy should carry a "Last updated" date at the top. When you make a material change, log it internally. A simple version log might look like this:
Version log example: v1.0 — 12 March 2024 — Initial publication. Covers contact form, Google Analytics, Mailchimp newsletter. v1.1 — 5 September 2024 — Added Meta Pixel (advertising cookies). Updated cookie section and retention table. v2.0 — 10 January 2026 — New booking widget added. Updated third-party processors list and international transfers clause.
Keep this log internally even if you do not publish it. If the ICO ever investigates a complaint, a clear version history demonstrates that you take compliance seriously and that your policy was accurate at the time of any alleged breach.
Consent records. If you rely on consent as a lawful basis for any processing, you must be able to prove that consent was given. Record the date, the version of the consent wording shown, and the mechanism used (for example, a checkbox on a sign-up form). Most email marketing platforms such as Mailchimp and Brevo store this automatically, but check your settings to confirm.
Common mistakes that attract ICO attention and how to fix them
Most privacy policy problems fall into a small number of categories. Here is what to look for and what to do about each one.
-
Generic template left unchanged. The policy describes data the site does not collect, or omits data it does. Fix: go clause by clause and delete or rewrite anything that does not match your actual processing. A short, accurate policy is always better than a long, inaccurate one.
-
No retention periods. Phrases like "we keep your data for as long as necessary" are not compliant. Fix: add specific timeframes for each data category. Use the examples in the table above as a starting point.
-
Cookie section missing or misaligned. The policy mentions cookies in passing but does not list the cookies used, their purpose, or their duration. Fix: audit your cookies using a browser tool such as Cookie Metrix or your browser's developer tools, then list each category with its purpose and lifespan.
-
No lawful basis stated. The policy says you collect data but does not say why you are legally allowed to. Fix: for each processing activity, identify and name the lawful basis (consent, contract, or legitimate interests).
-
Contact details missing or incomplete. Visitors cannot find out how to request their data or ask for deletion. Fix: add a dedicated contact email address and, if you have one, the name of your Data Protection Officer.
-
Policy not linked at point of collection. The form collects data but there is no link to the privacy policy beside the submit button. Fix: add a one-line statement with a hyperlink next to every form on your site: "We handle your data in line with our [privacy policy]."
-
No mention of third-party processors. You use Google Analytics, a booking widget, or a payment processor but the policy says nothing about them. Fix: list each third-party tool, what data it receives, and a link to its own privacy policy.
The ICO tends to investigate complaints rather than proactively audit small businesses, but a complaint from a single unhappy customer can trigger a formal inquiry. The simplest risk reduction is a policy that accurately describes what you actually do.
Publishing your privacy policy: a practical checklist for small businesses
Getting the policy written is only half the job. Publishing it correctly, keeping it accessible, and linking it from the right places is what makes it legally effective. Here is what to check on your site.
Technical publishing checklist:
- Footer link visible on every page, including the homepage
- Link labelled clearly ("Privacy Policy" or "Privacy Notice", not "Legal" or "Small Print")
- Policy page loads correctly on mobile without text overflow
- SSL certificate active on your site (data submitted via forms is encrypted in transit)
- Link from every data collection point: contact form, checkout, newsletter sign-up, booking widget
- Cookie banner links directly to the cookie section of your policy or to a separate cookie policy
- Version date displayed at the top of the policy page
How Ace-sites makes this straightforward. If you build your site on Ace-sites, you can add a footer link to your privacy policy page in a few clicks using the visual editor, with no code required. The platform's mobile-optimised templates mean your policy page will display correctly on any device without extra work. Built-in SSL is included as standard, so data submitted through contact forms and booking widgets is protected in transit. When you update your policy, you edit the page directly and republish, and the footer link updates automatically across every page on your site.
For small business owners who want to see how a published policy looks in practice, the Ace-sites privacy policy page is a working example of a policy hosted on the platform.
A note on E-E-A-T signals. Search engines and visitors both look for signs that your site is trustworthy. A clearly dated, accessible privacy policy is one of those signals. Pairing it with an "About" page that names the people behind the business, and a terms and conditions page linked alongside the privacy policy, builds a more complete picture of a legitimate, accountable business.
Why a clear privacy policy is good for your business, not just a legal box to tick
Most small business owners treat a privacy policy as something they need to avoid a fine. That framing undersells it. A well-written, honest privacy policy does something more useful: it tells a potential customer that you handle their information carefully, which directly affects whether they trust you enough to fill in your contact form or complete a checkout.
Think about it from a visitor's perspective. They land on a site they have never used before. They are about to hand over their name, email address, and possibly payment details. A privacy policy that clearly explains what happens to that data, in plain English, removes a real hesitation. A policy that is vague, generic, or obviously copied from a template has the opposite effect.
The businesses that get the most from their privacy policy are the ones that write it as a customer-facing document, not a legal disclaimer. Short sentences. Plain language. Specific answers to the questions a visitor would actually ask: what do you collect, why do you need it, and how do I get you to delete it if I change my mind?
There is also a practical business argument for keeping the policy current. If you add a new marketing tool or change your email platform and forget to update the policy, you are not just non-compliant. You are describing a version of your business that no longer exists. That gap is exactly what an ICO investigation would focus on.
Your privacy policy, published and up to date with Ace-sites
Getting your privacy policy written is one thing. Getting it published correctly, linked from every form, and kept current as your business grows is where most small business owners lose time.

Ace-sites gives you a straightforward way to publish your policy without touching any code. Add a footer link, create a dedicated policy page, and update it whenever your processing changes, all from the same visual editor you use to manage the rest of your site. Every Ace-sites site includes SSL as standard, mobile-optimised templates, and built-in contact forms that you can link directly to your policy at the point of collection.
If you would rather have the whole site built for you, including the privacy policy page and all the compliance links, the done-for-you website service handles the technical setup so you can focus on running your business. Please note: Ace-sites helps with publishing and visibility, not legal advice. For complex data processing, consult a solicitor.
Ready to get your site live and compliant? See what Ace-sites includes and start your free trial today.
Sources
Use these resources as your starting point. Each one is either a primary legal source or a tool specifically built for UK compliance.
- How to write a privacy notice and what goes in it | ICO
- Legislation
- Gov
- Free Privacy Policy Template (UK) | Website Contracts
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
