What Is GDPR and What Does It Mean for Small Business Websites?
GDPR is a UK/EU law protecting personal data. If your website collects customer information, you need to follow it.
GDPR is a law that controls how businesses collect, store and use people's personal information like email addresses or phone numbers. You must be transparent about it, keep data safe, and let people access or delete their information.
If you run a small business website in the UK, you've probably heard the word 'GDPR' mentioned at least once. It sounds complicated, but the core idea is straightforward: it's about treating people's personal information fairly and keeping it safe. This guide explains what it actually means for your business and what you need to do about it.
What Is GDPR?
GDPR stands for General Data Protection Regulation. It's a law that came into force in 2018 and applies to any business collecting or using personal data — which includes almost every UK business with a website.
Personal data means any information that could identify someone. This includes:
- Email addresses
- Phone numbers
- Names and addresses
- IP addresses (from website visitors)
- Cookies and tracking data
- Payment information
- Even photos if they show someone's face
The law exists to give people control over their own information and make sure businesses don't misuse it.
Why Should You Care?
Honestly, there are two reasons:
- It's the law. If you break GDPR rules, you can be fined. For small businesses, fines usually start smaller, but they're still painful.
- Your customers expect it. People want to know their data is safe. GDPR compliance shows you take that seriously.
What You Actually Need to Do
1. Work Out What Data You're Collecting
Start by listing everywhere you gather customer information:
- Contact forms on your website
- Email newsletters
- Online shop orders
- Booking systems
- Social media platforms (these count too)
- Google Analytics tracking visitors
Write this down. It's harder to protect data you've forgotten about.
2. Create a Privacy Policy
This is a legal requirement. It tells visitors what data you collect and what you do with it.
Your privacy policy must explain:
- What data you collect
- Why you're collecting it
- How long you keep it
- Who you share it with (payment providers, email services, etc.)
- What rights people have (to see, change or delete their data)
You can find templates online, but consider having a solicitor review it — it's worth the small cost. Put a link to your privacy policy at the bottom of every page and before any form that collects data.
3. Get Proper Consent
You need people's permission before collecting their data. This means:
- For email newsletters: Use a "double opt-in" — they tick a box and then confirm via email. Don't pre-tick the box for them.
- For forms: Make sure you have a clearly visible checkbox where they agree to your privacy policy.
- For marketing: Only email people who've actively chosen to hear from you. Buying email lists is not compliant.
The key word is active consent — they have to do something intentional to agree.
4. Keep Data Safe
This doesn't mean hiring an IT security firm (unless you're collecting sensitive data like payment cards). It means:
- Use strong passwords for any account holding customer data
- Keep software and plugins updated
- Use HTTPS on your website (that little padlock icon in the browser)
- Don't store credit card details yourself — use a secure payment provider
- Only share data with trusted services (your email marketing platform, for example)
5. Let People Access Their Data
If someone asks, you must tell them within 30 days what personal data you hold about them. Keep records so you can do this quickly.
6. Delete Data When You're Done
Don't keep customer information indefinitely. If someone unsubscribes from your email list, delete their address. If a customer doesn't buy anything for two years, you probably don't need their details anymore.
Tools and Services to Help
You don't have to do this alone. These tools help with GDPR compliance:
- Mailchimp, ConvertKit, GetResponse: Email services built with GDPR in mind
- Termly, iubenda: Generate privacy policies automatically
- Cookiebot, OneTrust: Manage cookie consent banners
- Google Analytics 4: Built-in privacy controls compared to older versions
These aren't free, but they're affordable and save you worrying about the technical details.
The Honest Bit
GDPR compliance isn't a one-time task. It's an ongoing part of running your business. Rules change, your tools update, and your data collection might grow. Set a reminder every six months to review your practices.
If you're genuinely unsure whether you're doing it right, an hour with a small business solicitor costs far less than potential fines. It's money well spent.
Next Steps
- List all the places you collect customer data
- Write or download a privacy policy
- Add it to your website footer
- Review your email consent — make sure it's active opt-in
- Check your payment and analytics tools are GDPR-ready
That's not a perfect system, but it's a solid start. GDPR isn't meant to stop small businesses from operating — it just means doing it respectfully.