Stage 2Get Online

Privacy & Cookies: What You Actually Need (UK Guide)

10 min read
confident
decide
Share:

You're not alone if GDPR compliance feels overwhelming—but you only need two things in place, and this guide shows you exactly how to set them up in 45 minutes.

The moment you add Google Analytics, a contact form, or a Facebook Pixel to your website, you're collecting data. And under UK law (GDPR and the Privacy and Electronic Communications Regulations), you must ask permission before tracking users—not just tell them you're doing it.

Most micro-business owners freeze at this point. The terminology is confusing. The ICO guidance runs to hundreds of pages. And the internet is full of contradictory advice about what's "good enough."

Here's the truth: You need exactly two things to be compliant:

  1. A Privacy Policy that clearly states what data you collect and why
  2. A Cookie Consent Banner that actually blocks tracking until users click "Accept"

That second point trips up most people. Those "This site uses cookies—Continue" banners you see everywhere? They're not compliant. UK law requires prior consent—meaning scripts like Google Analytics must be blocked until the user actively agrees.

This guide cuts through the legal jargon to deliver one specific action: Installing the minimal necessary compliance elements that satisfy UK law for a small business website. You'll have both elements live and working by the end of this article.

On this page:


Quick Start: 5-Step Compliance Checklist (30 Minutes)

If you're confident with website basics and just need the action steps, follow this condensed version. For detailed explanations, skip to the Complete Guide.

Step 1: List Your Data Collection Points (5 minutes)

Open a document and note every place you collect data:

  • Contact forms (names, email addresses, phone numbers)
  • Newsletter sign-ups
  • Google Analytics or similar tracking
  • Facebook Pixel or other advertising pixels
  • Payment processing (even though Stripe/PayPal handle the data, you need to mention it)
  • Any lead magnets or downloadable resources

Step 2: Choose a Cookie Consent Platform (5 minutes)

You need a tool that:

  • Automatically blocks scripts until consent is given (called "prior consent" mode)
  • Works with UK/GDPR requirements
  • Fits your budget

Recommended options:

  • Cookiebot (from £0/month for small sites, excellent auto-detection)
  • Complianz (WordPress plugin, free version available)
  • CookieYes (free tier for up to 25,000 page views/month)

All three automatically detect and block common scripts like Google Analytics.

Step 3: Generate Your Privacy Policy (10 minutes)

Most CMPs include a policy generator. Use it, then customize:

  1. Add your business name and contact details
  2. List every data collection point from Step 1
  3. Specify how long you keep data (e.g., "Contact form submissions are kept for 2 years")
  4. Include your legal basis for processing (usually "Legitimate Interest" for analytics, "Consent" for marketing)

Critical UK requirement: Include information about users' rights (access, deletion, portability) and how to contact the ICO if they have concerns.

Step 4: Install the CMP Code (5 minutes)

Your chosen CMP will provide a code snippet. Place it in your website's `<head>` section:

  • WordPress: Use a plugin like "Insert Headers and Footers" or add to your theme's header.php
  • Squarespace: Settings → Advanced → Code Injection → Header
  • Wix: Settings → Custom Code → Add Code to Head

The CMP will now load before any other scripts, allowing it to block them until consent is given.

Step 5: Verify It's Working (5 minutes)

  1. Open your website in an incognito/private browser window
  2. Before clicking anything on the cookie banner, open your browser's Developer Tools (F12)
  3. Check the Network tab—Google Analytics and other tracking scripts should NOT be loading
  4. Click "Accept" on the banner
  5. Refresh the page—now the scripts should load

✅ Completed the quick version? Move on to Terms & Conditions: What to Include or continue below for the detailed walkthrough explaining why each step matters and how to handle edge cases.


Complete Step-by-Step Guide: Achieving UK Compliance

This section explains the reasoning behind each action and handles the complexity that the Quick Start skips.

Step 1: Understand the UK Principle (Prior Consent)

The UK follows GDPR plus the Privacy and Electronic Communications Regulations (PECR). The key principle: You must get consent before placing non-essential cookies or tracking users.

"Non-essential" means anything beyond what's strictly necessary for the website to function. Google Analytics? Non-essential. Facebook Pixel? Non-essential. Even heatmapping tools like Hotjar? Non-essential.

What this means in practice:

Those "This website uses cookies—Continue" banners you see everywhere? They're called "Notice and Continue" or "Implied Consent" banners. They're not compliant under UK law. The ICO has been clear: you need prior consent, meaning the user must take an affirmative action (clicking "Accept") before tracking begins.

This is why you need a Cookie Consent Management Platform (CMP) that actually blocks scripts, not just displays a notice.

Why this matters for micro-businesses: The ICO can fine businesses up to £17.5 million or 4% of annual turnover (whichever is higher) for serious breaches. While they typically target large organizations, they've made examples of smaller businesses too. More importantly, proper consent builds trust with your customers—and that's worth more than avoiding fines.

For the complete picture of what's legally required on your website, see Legal Bits Every UK Small Business Website Needs.

Step 2: Inventory Your Data Collection Points

Before you can write an accurate Privacy Policy, you need to know exactly what data you're collecting. This is often more than you think.

Create a spreadsheet with these columns:

| What's Collected | Where | Why | Legal Basis | Retention Period |

|------------------|-------|-----|-------------|------------------|

| Email address | Contact form | To respond to enquiries | Legitimate Interest | 2 years |

| Name | Contact form | To personalize responses | Legitimate Interest | 2 years |

| IP address, browser info | Google Analytics | To understand site usage | Consent | 14 months |

| Email address | Newsletter signup | To send marketing emails | Consent | Until unsubscribe |

Common collection points to check:

  1. Contact forms (data collected via contact forms)—usually name, email, phone, message content
  2. Analytics tools (basic tracking methods)—IP addresses, device info, browsing behavior
  3. Marketing pixels (Facebook, LinkedIn, Google Ads)—browsing behavior, page views
  4. Payment processing—even though Stripe/PayPal handle the data, you need to mention it
  5. Email marketing tools (Mailchimp, ConvertKit)—email addresses, engagement data
  6. Live chat widgets—conversation history, email addresses
  7. Lead magnets or downloads—whatever you ask for in exchange

Don't forget third-party tools: If you've embedded a booking calendar, customer portal, or any other third-party service, check what data they collect. You're responsible for declaring it.

A quick comparison of popular UK/GDPR compliant CMPs, focusing on cost and key blocking features. Cookiebot offers the most comprehensive auto-detection but costs more; Complianz is excellent for WordPress users; CookieYes provides a generous free tier.

Step 3: Select Your CMP Tool and Generate Policy

Now you need to choose a Cookie Consent Management Platform. The right tool will:

  1. Automatically detect scripts on your site (Google Analytics, Facebook Pixel, etc.)
  2. Block them by default until consent is given
  3. Provide a customizable banner that meets UK requirements
  4. Generate a Privacy Policy based on what it detects
  5. Store consent records (proof that users agreed)

Evaluation criteria:

  • Prior consent mode: Essential. The tool must block scripts, not just notify users.
  • Auto-detection: Saves hours of manual configuration. The tool scans your site and identifies tracking scripts automatically.
  • Customization: You need to match your brand and add custom data collection points the tool might not detect.
  • Consent storage: Required for compliance. You must be able to prove users consented.
  • Price: Free tiers often work for micro-businesses (under 25,000 monthly page views).

Recommended tools:

  1. Cookiebot (cookiebot.com)
  2. Best auto-detection
  3. Prior consent mode by default
  4. Free for up to 100 pages
  5. Excellent documentation
  6. Used by major UK brands
  7. Complianz (WordPress plugin)
  8. Free version available
  9. Good for WordPress sites
  10. Wizard-based setup
  11. Integrates with popular plugins
  12. CookieYes (cookieyes.com)
  13. Free up to 25,000 page views/month
  14. Simple setup
  15. Good documentation
  16. Works with all platforms

Setup process (using Cookiebot as example):

  1. Create an account and add your domain
  2. The tool scans your site and detects scripts
  3. Review the detected cookies and categorize them:
  4. Necessary: Required for site function (usually just session cookies)
  5. Preferences: Remember user choices (language, etc.)
  6. Statistics: Google Analytics, heatmaps
  7. Marketing: Facebook Pixel, Google Ads, retargeting
  8. Enable "Prior Consent" mode (usually the default for UK/EU)
  9. Customize the banner text and appearance
  10. Generate your Privacy Policy using the tool's generator

Critical settings to verify:

  • Consent mode: Must be "Opt-in" or "Prior Consent," NOT "Opt-out" or "Notice Only"
  • Auto-blocking: Enabled for all non-essential categories
  • Consent renewal: Set to 12 months (users must re-consent annually)
  • Geolocation: If you serve global customers, set different rules for UK/EU vs. other regions

NetNav Integration Point: Implementing a CMP can be tricky, especially verifying that scripts are genuinely blocked. Use NetNav's technical check after installation to confirm that non-essential scripts aren't loading before consent. This audit saves hours of manual browser inspection and gives you confidence that your implementation actually works.

Step 4: Customize and Publish the Privacy Policy

Most CMPs generate a basic policy, but you must customize it to be accurate and complete.

Required sections for UK compliance:

  1. Who you are
  2. Business name and trading name (if different)
  3. Contact details (email, phone, postal address)
  4. ICO registration number (if you have one—most micro-businesses don't need to register)
  5. What data you collect
  6. Use your inventory from Step 2
  7. Be specific: "We collect your name and email address when you submit our contact form"
  8. Don't use vague language like "we may collect various information"
  9. Why you collect it (legal basis)
  10. Consent: For marketing emails, non-essential cookies
  11. Legitimate Interest: For contact form responses, essential analytics
  12. Contract: For processing orders or delivering services
  13. Legal Obligation: For tax records, etc.
  14. How long you keep it
  15. Be specific: "Contact form submissions: 2 years"
  16. Explain why: "We keep contact form data for 2 years to maintain a record of customer service interactions"
  17. Who you share it with
  18. List all third parties: "We use Google Analytics (Google LLC) to understand site usage"
  19. Include payment processors, email marketing tools, hosting providers
  20. Mention if data leaves the UK/EU
  21. User rights
  22. Right to access their data
  23. Right to correction
  24. Right to deletion ("right to be forgotten")
  25. Right to data portability
  26. Right to object to processing
  27. Right to withdraw consent
  28. How to exercise these rights (usually "email us at...")
  29. How to complain
  30. "If you're not satisfied with our response, you can complain to the Information Commissioner's Office (ICO): ico.org.uk"

Customization checklist:

  • [ ] Replace all placeholder text with your actual business details
  • [ ] Add every data collection point from your inventory
  • [ ] Mention every third-party tool by name (not just "analytics providers")
  • [ ] Specify retention periods for each data type
  • [ ] Include a "last updated" date
  • [ ] Add a version number (for tracking changes)

Where to publish it:

Create a dedicated page at `/privacy-policy` or `/privacy`. Then link to it from:

  1. Website footer (required—must be accessible from every page)
  2. Next to every data collection point (contact forms, newsletter signups)
  3. Checkout process (if you sell products)
  4. Account creation (if users register)

Required placement: The Privacy Policy and Terms & Conditions must be linked in your website footer and near any data collection points (forms, checkout, etc.). This screenshot shows best practice for discoverability and compliance.

For guidance on footer structure and essential links, see What Should I Put on My Homepage? (which covers overall site structure including footers).

Step 5: Implement the CMP Code and Verify Blocking

Now you need to install the CMP code on your website. This is the most technical step, but it's straightforward if you follow the instructions.

Installation methods by platform:

WordPress:

  1. Install your CMP's plugin (e.g., "Complianz" or "Cookiebot")
  2. Follow the setup wizard
  3. The plugin handles code placement automatically

Squarespace:

  1. Copy the code snippet from your CMP dashboard
  2. Go to Settings → Advanced → Code Injection
  3. Paste the code in the "Header" section
  4. Save

Wix:

  1. Copy the code snippet from your CMP dashboard
  2. Go to Settings → Custom Code
  3. Click "Add Custom Code"
  4. Paste the code, set it to load in "Head"
  5. Apply to "All Pages"

Custom HTML sites:

  1. Copy the code snippet from your CMP dashboard
  2. Paste it in the `<head>` section of your HTML, before any other scripts
  3. Upload the modified file to your server

Critical: Code placement matters. The CMP code must load before Google Analytics, Facebook Pixel, and other tracking scripts. This allows it to intercept and block them until consent is given.

Verification process (the incognito test):

This is how you confirm your implementation actually works:

  1. Open an incognito/private browser window (this ensures no previous consent is stored)
  2. Navigate to your website—the cookie banner should appear immediately
  3. Open Developer Tools (F12 on most browsers)
  4. Go to the Network tab and refresh the page
  5. Before clicking anything on the banner, check for tracking scripts:
  6. Search for "google-analytics" or "analytics.js"—should NOT be present
  7. Search for "facebook" or "fbevents.js"—should NOT be present
  8. Any other tracking pixels should NOT be loading
  9. Click "Accept" on the banner
  10. Refresh the page and check the Network tab again—now the tracking scripts SHOULD load
  11. Test the "Reject" option:
  12. Clear your browser data or open a new incognito window
  13. Visit your site again
  14. Click "Reject" or "Reject All"
  15. Verify that tracking scripts still don't load
  16. Test the settings/preferences option:
  17. Users should be able to accept some categories (e.g., Statistics) but reject others (e.g., Marketing)
  18. Verify that only the accepted categories' scripts load

Example of a compliant banner showing clear options for Accept/Reject and Settings, with the background scripts demonstrably blocked until the user makes a choice. Notice the "Necessary," "Statistics," and "Marketing" categories that users can control individually.

Common implementation mistakes:

  • Scripts loading before the CMP: Check that the CMP code is the first script in your `<head>` section
  • Hard-coded scripts: If you've manually added Google Analytics code to your theme, it might bypass the CMP. Remove it and add it through Google Tag Manager instead, which the CMP can control
  • Cached pages: Clear your website cache after installing the CMP, or you might be testing an old version of the page
  • Testing while logged in: Some CMPs don't show the banner to logged-in admins. Always test in incognito mode

🎉 Completed? You've secured the necessary privacy foundations and are ready for Terms & Conditions: What to Include, which covers the other essential legal document for your website.


Troubleshooting


What's Next

You've completed the privacy and cookie compliance requirements—one of the most important (and often dreaded) legal steps for your website.

Immediate next step: Terms & Conditions: What to Include

Your Terms & Conditions document covers how people can use your website, what they can and can't do, and your liability limitations. It's the companion to your Privacy Policy and equally important for protecting your business.

Go deeper into related topics:


Other Get Online Guides

Before you launch, make sure you've covered these essentials:


You've Completed the Essential Compliance Step

Privacy compliance isn't just about avoiding fines—it's about building trust with your customers. By implementing proper consent mechanisms and being transparent about data collection, you're showing visitors that you respect their privacy and take their data seriously.

You've now completed the essential (and often dreaded) compliance step. NetNav can audit your entire site across 9 pillars of health, including continuous monitoring of technical security and speed, in 60 seconds—see what else needs attention before you launch.

Run Your First NetNav Audit to check all 9 pillars of website health and ensure everything is working correctly before you launch.