What does your website legally need? A practical guide for UK small businesses
A practical guide to website legal requirements in the UK. Learn about cookies, privacy and the information your website actually needs with Danny Prince-Brand, ORB’s IT director and founder of Cahillbrand.
When I look at a business website, one of the first things I do is scroll to the footer.
Why? Because it immediately tells me who I’m doing business with.
If I don’t find the company name, registration number or address, I feel uneasy.
Second, I look for a privacy and cookie policy.
After some combing, I can pretty much tell whether someone has used a template or whether the policy actually reflects how the business operates.
To be clear, I’m a web developer, not a solicitor. This is a practical guide to some common UK website legal requirements and privacy issues, not legal advice. If your setup is complex or you’re unsure how the rules apply to your business, please do speak to a legal or data-protection specialist.
CHECK ONE: UK website legal requirements — what information should be on your website?
Does your website say who you actually are?
Limited company? Check for:
- Full registered company name including Ltd/Limited
- Company registration number
- Registered office address
- Where the company is registered (England and Wales, Scotland or Northern Ireland)
- A genuine means of contacting you
Sole trader or partnership? If you trade under a business name, make sure customers can identify the person or people behind it and that you provide the business information required for your circumstances. If you sell goods and services online, additional contact and business-information rules may apply.
Depending on what you do, as requirements vary, you might include…
- VAT registration number
- Regulatory requirements
- Professional bodies and memberships
CHECK TWO: What is your website actually collecting?
Imagine you’re in a bakery. You put two cinnamon buns in your basket which you leave on the counter while you wander over to look at the cakes. The bakery remembers what’s already in your basket while you continue shopping.
That’s useful. You’ve asked it to remember something so the service works. Your cinnamon buns might go poof otherwise – disappearing from your basket and making you start again!
But now imagine someone starts following you around with a clipboard…
This person isn’t needed to keep your basket working. They want to know which shelves you stop at, how long you spend there and what catches your eye. And, depending on the tracking involved, they might be preparing to follow you beyond the bakery too…
That’s where your choice comes in.
The first example represents the technologies a website genuinely needs to provide the service you’ve asked for. The busy-body with a clipboard represents the analytics, advertising and other tracking technologies that can raise additional consent and privacy questions.
Why I don’t use Google Analytics and Tag Manager
Google Analytics can show business owners information about visitor numbers, sessions, approximate locations, devices and behaviour across a website.
It is widely used by small businesses partly because it is powerful, available without a standard subscription fee, and attached to one of the most recognisable technology brands in the world.
Google Tag Manager is a Tag Management System (TMS) that allows you to set up and manage digital marketing tags (sometimes referred to as tracking pixels, web beacons, or snippets of JavaScript code) on your site without changing your website’s code.
But recognisable does not automatically mean simple, proportionate or right for every small business.
I don’t add Google Analytics or Tag Manager as standard because most small-business websites don’t need that level of tracking or complexity.
The more technology you add, the more you need to understand exactly what it is doing and whether consent or another lawful exception applies.
So why introduce tracking and consent complexity when many small businesses don’t need that level of data?
My preference is to collect less in the first place.
I use Plausible, which is designed to provide aggregated website analytics without cookies, cross-site tracking or persistent user identifiers. For many small businesses, that gives you the information you actually need without introducing unnecessary tracking.
While it is a paid platform, I like Plausible’s approach: it is deliberately designed without cross-site or cross-device tracking.
Open your own website and ask…
- Does a cookie banner appear?
- Can I reject as easily as accept?
- What happens before I choose?
- Do I have Google Analytics or Tag Manager installed?
- Are advertising pixels running?
- Can I change my preferences later?
CHECK THREE: Does your privacy policy describe reality?
A privacy policy isn’t boilerplate legal decoration. It should accurately reflect your actual business and the technology you use to run it.
Many privacy and cookie policies have been copied from another business, generated years ago, or left untouched while the website or business changed around them.
I’ve updated my own privacy policy for full transparency about the apps, platforms and artificial intelligence I use in my business. Here it is as an example (never copy, just as a guide!)
Your privacy information should tell people:
- Who you are
- What information you collect
- Why
- The legal basis where applicable
- Who else processes it
- How long you retain it
- International transfers where relevant
- People’s rights and how to contact/complain (give a direct email or phone number)
A common situation I see is that the website has changed but the policy didn’t. New CRM, new booking system, new payment provider… or maybe someone added a tracking pixel many moons ago. These changes also need to be reflected in the policy.
The 10-minute UK website legal requirements check
Open your website now and check:
- Is it clear who owns/runs this website?
- Is the required company/business information there?
- Can someone contact you directly?
- Do you know which cookies/trackers are running?
- Do you know what happens before someone consents?
- Is rejecting as straightforward as accepting where consent is needed?
- Does your cookie information match reality?
- Does your privacy policy match the tools you currently use?
- Are you collecting data you don’t actually need?
- When did you last review all of this?
Where I come in
You don’t need to become an expert in UK website legal requirements, but somebody does need to check that your website reflects how your business actually operates.
I’m a big believer in website health under the hood, which is why I built CahillPulse, a free website audit tool that helps you spot potential gaps and understand what’s actually happening on your site.
Start there. Run your website through CahillPulse and see what comes back. You might find a few straightforward things you can sort yourself.
But if the results leave you with more questions than answers — or you’d simply rather have another human look at it — that’s where I come in.
As ORB’s IT Director, I’m always happy to help fellow members understand what their website is doing, identify what needs attention, and make the technical changes needed to put it right.
Because ultimately, a responsible website should make it easy for people to understand who they’re dealing with, what happens to their information, and how they can get in touch.
Compliance is the baseline. Being clear, transparent and thoughtful about the people using your website is the bit worth aiming for.

Danny Prince-Brand
Founder of Cahillbrand
Danny Cahill is the founder of Cahillbrand, a Southend-on-Sea based web design and development business helping small, service-led organisations make their digital presence work harder.
With more than 15 years’ experience in web development and digital systems, Danny takes a practical, business-focused approach. Cahillbrand creates bespoke, high-performing websites alongside UK-based hosting, ongoing support and lightweight digital systems.
Practical thinking extends to responsible business, too. Cahillbrand operates remotely and paperless, keeps its digital infrastructure lean, and focuses on efficient websites designed to last rather than encouraging clients into unnecessary rebuilds. The business monitors factors such as page weight, loading times and hosting efficiency, with plans to introduce sustainability benchmarks across client projects.
Cahillbrand also supports small local organisations and non-profits through cost-conscious solutions and flexible pricing where appropriate. Danny’s aim is simple: give organisations digital tools they can actually use and maintain, without unnecessary complexity or spend.