Practical Guide to GDPR Website Compliance
A contact form can create a GDPR obligation before anyone on your team has read the submission. Add analytics, a newsletter sign-up, embedded video, online payments or a recruitment form, and the picture becomes more complex. This guide to GDPR website compliance is for organisations that need a website to support real commercial activity without treating privacy as a last-minute legal banner.
For most UK businesses, the aim is not to make a website look compliant. It is to understand what personal data enters the system, why it is there, who can access it and how long it stays. The UK GDPR and Data Protection Act 2018 set the wider framework. Cookie use also falls under the Privacy and Electronic Communications Regulations, commonly known as PECR. A sound implementation needs to account for both.
Start with the data your website actually collects
The quickest way to miss a risk is to begin with a generic privacy policy. Begin instead with a practical data map. Trace a visitor’s journey through the site, including the routes that sit behind the visible pages.
A typical map should cover four areas:
- Information supplied directly, such as names, email addresses, telephone numbers, CVs and enquiry details.
- Information collected automatically, including IP addresses, cookie identifiers, device data and usage behaviour.
- Information received or shared through third parties, such as payment providers, CRM systems, booking tools, email platforms and advertising networks.
- Information generated internally, such as sales notes, support records, lead scores and account history.
This exercise often exposes the real issues. A simple WordPress contact form may send submissions to several staff inboxes, retain them in the database and push them into a CRM. A Shopify store may pass customer data to fulfilment, accounting, marketing and review platforms. None of this is necessarily a problem, but it must be understood and justified.
For each data flow, record the purpose, lawful basis, recipient, retention period and security controls. This is not paperwork for its own sake. It gives directors, marketing teams and developers a shared view of how the live system behaves.
Choose a lawful basis before you collect data
Consent is only one lawful basis under UK GDPR, and it is frequently used where another basis would be more appropriate. A prospect submitting an enquiry form, for example, can usually expect their details to be used to respond to that enquiry. Depending on the circumstances, legitimate interests or steps taken before entering a contract may be relevant.
Consent is generally the right route for optional marketing and non-essential cookies. It must be freely given, specific, informed and unambiguous. Pre-ticked boxes, vague statements and consent buried in terms and conditions are weak foundations. People should be able to refuse as easily as they accept, and withdrawing consent should not involve an obstacle course.
The trade-off is commercial as well as legal. Aggressive lead capture and extensive tracking may provide more data in the short term, but they can reduce trust, damage conversion quality and increase operational risk. Collecting less, with a clear purpose, is often the more durable decision.
Be careful with marketing permissions
A form that asks for an email address to send a download does not automatically provide permission for ongoing promotional email. Keep service communications, enquiry follow-up and marketing consent distinct. The wording should explain what the person is agreeing to and, where relevant, identify the channel.
Marketing teams also need a process for honouring opt-outs across the CRM, email platform and any connected audience tools. A preference centre is useful only if the underlying integrations respect it.
Cookie compliance is about control, not a banner
A cookie banner that loads every analytics, advertising and personalisation script before the visitor makes a choice is not doing its job. Non-essential technologies should normally wait until consent has been given. Necessary cookies, such as those used to maintain a basket or provide site security, are treated differently, but their purpose should still be explained.
This is where website compliance often fails in practice. Tags are added through a tag manager, a marketing plug-in, a chat widget or an embedded social feed. Each may set cookies or transmit information to another provider. The banner may look correct while the page is already sending data.
Test the site in a clean browser session and review what fires before and after each consent choice. Repeat the test after campaign launches, plug-in changes and third-party integrations. Consent mode tools can help manage tags, but they do not replace clear configuration or an understanding of what each supplier does.
Your cookie information should identify the categories in use, their purposes, the relevant providers and how visitors can change their choices. Avoid calling every cookie essential because it makes implementation easier. If a tool exists to measure marketing performance, it is unlikely to be essential to the visitor receiving the service they requested.
Make your privacy information useful
A privacy notice is a clear explanation of your processing, not a document to hide in the footer and forget. It should describe what data you collect, why you use it, your lawful bases, who receives it, any international transfers, retention periods and the rights available to individuals. It should also say how people can contact the organisation about privacy concerns and, where applicable, the details of the data protection officer.
The wording should match the system. If the notice says data is kept for 12 months but old form entries remain indefinitely in the database, the notice is not the problem. The process is.
Layered information works well for busy users. A brief explanation beside a form can explain why particular fields are needed, while the full privacy notice provides the wider detail. This improves transparency at the point a person is deciding whether to share information.
Build rights requests and retention into operations
Individuals can ask for access to their personal data, request corrections, object to some processing and, in certain cases, ask for deletion. These requests do not arrive neatly labelled. They may come through a support inbox, social channel or account manager.
Decide who receives them, how identity is checked, where data may be held and who approves the response. Most subject access requests must be handled within one month, so a request process that depends on finding a former developer or searching multiple unconnected systems is not reliable.
Retention matters just as much. Keeping every lead forever because storage is cheap creates unnecessary exposure. Set practical retention rules for form enquiries, unsuccessful job applications, customer records, backups and analytics data. Some records may need to be kept for contractual, tax or legal reasons. The point is to make a conscious decision and apply it consistently.
Check suppliers, security and ownership
Website compliance extends beyond the organisation’s own server. Hosting providers, form tools, CRM platforms, payment processors, analytics suppliers and support partners may process personal data on your behalf. Where a supplier acts as a processor, the contract needs the appropriate data processing terms. Where data is transferred outside the UK, assess the transfer mechanism and the supplier’s safeguards rather than assuming a familiar brand has resolved the issue for you.
Security is part of GDPR compliance, not a separate technical concern. The proportionate controls vary by risk, but common basics include multi-factor authentication, least-privilege access, software updates, encrypted connections, secure backups, activity logging and tested recovery procedures. A high-volume e-commerce platform or portal containing sensitive information needs more than a brochure site with a basic enquiry form.
Ownership is equally important. Know who controls the domain, hosting account, analytics account, tag manager, consent platform and backups. Fragmented ownership makes it difficult to respond to an incident or rights request under pressure. It also turns a routine rebuild into a risky handover.
Treat compliance as part of website maintenance
A compliant launch can become outdated quickly. A new tracking pixel, form field, recruitment plug-in or AI support tool can alter the data picture. Include privacy checks in change control: ask what data a change collects, where it goes, whether the privacy information needs updating and whether the consent settings still work.
For organisations without an in-house technical lead, this is where an accountable development and maintenance partner earns its place. FullyCoded approaches these checks as part of operating a live system: practical documentation, controlled updates and clear ownership rather than a one-off compliance exercise.
The most useful next step is usually modest: map one complete customer journey, from first visit to the point their data is deleted. It will show whether your website’s privacy promises can stand up to the way the business actually works.