Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

Do I Need a Privacy Policy on My Small Business Site?

If you are skim reading
Straight answer: yes, almost certainly, because the moment your site collects an email address, drops a cookie, or runs Google Analytics, UK and EU data protection law says visitors must be told what you're doing with their information.

Straight answer: yes, almost certainly, because the moment your site collects an email address, drops a cookie, or runs Google Analytics, UK and EU data protection law says visitors must be told what you're doing with their information. The only small businesses that can skip it are ones running a static, no-forms, no-tracking brochure site, which is rarer than people think. For everyone else, it's not optional and it's not just a box-tick, because a wrong or copied one can cause more trouble than having none at all.

Why this isn't really a grey area

UK GDPR and the Data Protection Act 2018 apply to any business processing personal data of people in the UK, regardless of how small you are or how many staff you have. "Processing" includes collecting a name on a contact form, storing an email address in Mailchimp, running cookies through Google Analytics, or taking orders through a WooCommerce checkout. If any of that happens on your site, Articles 13 and 14 of UK GDPR require you to tell people, in writing, who you are, what you're collecting, why, how long you keep it, and what rights they have over it. That written notice is your privacy policy. It isn't a nice-to-have for big companies. It's a legal document triggered by what your site does, not by your headcount or turnover.

There's also a separate but related requirement under the Privacy and Electronic Communications Regulations (PECR), which covers cookies specifically. That's a different job to the privacy policy and it's worth understanding the difference, because I see small business owners treat a cookie banner as the whole job when it's only half of it. I've written about this distinction in more detail if you want to check whether you need visitor consent for Google Analytics, because the cookie consent piece trips up more small businesses than the privacy policy itself does.

A worked example

Say you run an online candle shop. You've got a Shopify store, a newsletter signup box offering 10% off, Google Analytics tracking visitors, a Meta pixel for retargeting ads, and a WhatsApp chat widget so customers can ask about scent allergies before buying. Every single one of those tools collects personal data: an email, an IP address, a phone number, browsing behaviour. That means your privacy policy has to name each category of data you collect, say which third parties you share it with (Shopify, Mailchimp or whichever email tool you use, Meta, Google), state how long you keep it, and tell customers how to ask you to delete it. If you're using WhatsApp for customer service, there are additional data handling questions about where those messages live and who can see them, which is exactly why I wrote a separate guide on connecting WhatsApp Business API to your website rather than bolting on a widget and hoping for the best.

Now compare that candle shop to a one-page site for a local plumber that has no forms, no analytics, no chat widget, and exists purely as a digital business card with a phone number. That plumber doesn't need a privacy policy, because the site isn't processing any personal data at all. The difference isn't size of business. It's what the site does.

What it has to include

A compliant privacy policy for a typical small business site needs, as a minimum:

  • Who you are: your business name, trading address, and a contact email or form for data queries
  • What data you collect: names, emails, IP addresses, payment details, cookies, and anything a form or tool captures
  • Why you collect it: the legal basis, usually "consent" for marketing or "legitimate interest" for basic site function
  • Who you share it with: your email platform, your hosting provider, any ad platforms, any CRM
  • How long you keep it: a specific period, not "as long as necessary", though that phrase appears constantly and tells a visitor nothing useful
  • What rights people have: access, correction, deletion, and how to complain to the ICO if they're unhappy
  • Whether you transfer data outside the UK or EEA, which matters if you use US-based tools like Mailchimp or HubSpot

That's the content. Where it goes matters too: it needs its own page, linked from your footer on every page, and ideally referenced at the point you collect data, such as next to a checkout box or a signup form.

The bit most guides skip over

Here's what nobody wants to say out loud: downloading a free privacy policy template and pasting it onto your site word for word is arguably worse than having nothing, because it makes a written legal claim about your data practices that may not be true. If a generic template says you don't share data with third parties and you're running Google Analytics and a Meta pixel, you've just put a false statement on your own website. Under GDPR, that's not a technicality, it's a compliance failure that's easier to prove than "they didn't have a policy at all." The ICO doesn't go hunting for small businesses with no policy nearly as often as they respond to a complaint from a customer who read the policy, realised it didn't match reality, and reported it.

The fix isn't complicated, it just takes more honesty than copying a template: list the actual tools your site uses, write down what each one collects, and build the policy from that list rather than from a generic draft you found on page one of Google.

Work with me

Want AI doing the heavy lifting in your marketing?

I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.

People conflate these three constantly. A privacy policy is the written statement of what you do with data. A cookie banner is the mechanism that asks for consent before non-essential cookies fire. A consent management platform is the software that runs that banner, logs consent, and lets you prove compliance if challenged. You can have a privacy policy without a working consent tool, and that's a common gap: the words are right, the mechanism behind them isn't. If you're still deciding which tool to use for the consent side, I've compared the best consent management platforms for small business, and separately looked at whether you should simply block Google Analytics on your business website entirely if you'd rather sidestep the consent question than manage it.

What happens if you skip it

The ICO's maximum fine under UK GDPR is £17.5 million or 4% of global annual turnover, whichever is higher, though in practice fines at that scale hit large organisations, not a five-person consultancy. For small businesses, the real exposure is smaller and more common: a complaint from a customer, a warning letter from the ICO giving you a set period to fix it, and reputational damage if a customer publicly calls you out for having no policy or a dishonest one. There's also the separate Data Protection Fee that most people forget: if you process personal data electronically, you're legally required to register with the ICO and pay an annual fee, which sits at £40 for a micro-organisation (fewer than 10 staff, turnover under £632,000), rising to £60 for small and medium organisations, and £2,900 for large ones. Failing to pay it can itself result in a fine of up to £4,350. Most small business owners have never heard of this fee, which means plenty of sites with a perfectly good privacy policy are still technically non-compliant on the registration side.

How to write one without overcomplicating it

  1. List every tool on your site that touches personal data: forms, analytics, email platform, payment processor, chat widgets, booking systems
  2. For each tool, note what it collects and where that data is stored or sent
  3. Write the policy section by section against the list above, matching language to what you do
  4. Add a last-updated date and commit to reviewing it whenever you add a new tool
  5. Link it in your footer and at every data collection point on the site
  6. Register with the ICO and pay the data protection fee if you haven't already

If you're running AI tools on your site, such as chatbots, lead scoring, or automated email sequences, those need to be in the list too, since they often process more personal data than people realise. I cover this in more depth in the wider guide to AI for small business, because the data question doesn't disappear just because the tool feels like "just marketing software."

Frequently asked questions

Do I need a privacy policy if I only have a simple contact form?

Yes. A contact form collects a name, email, and whatever a visitor types, which counts as personal data processing under UK GDPR, so you need a privacy policy explaining what happens to that information even if it's your only data collection point.

Is a free privacy policy generator good enough for a small business?

A generator can give you a starting structure, but it's only accurate if you edit it to match the exact tools and data your site uses; an unedited template that claims you don't share data when you're running Google Analytics and a Meta pixel is a compliance risk, not a shortcut.

Do sole traders need a privacy policy, or just limited companies?

UK GDPR applies to any business processing personal data, regardless of legal structure, so sole traders collecting emails, running analytics, or taking online payments need a privacy policy exactly the same as a limited company does.

How often should I update my privacy policy?

Update it every time you add or remove a tool that touches personal data, such as a new email platform, a chat widget, or a new ad pixel, and review it at least once a year even if nothing's changed, noting the review date on the page itself.

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.