How to Write a Privacy Policy for a UK Business Website

GenBox Free Tools (genbox.eu)

Why you need a privacy policy

If your website collects any personal information, even just a name and email through a contact form, you are expected to explain what you do with it. A privacy policy is that explanation. It is not legal boilerplate to bury in the footer; it is the page that tells visitors how their data is used and reassures them that you treat it properly. For most UK small businesses it is a short, plain-language document, not a legal essay.

What UK law expects you to tell people

Under UK data protection law, people have the right to know what personal data you collect, why you collect it, how long you keep it, who you share it with and what rights they have. Your policy should cover all of these in simple terms. Add your business name and contact details, and the date you last updated it. Keep the wording honest and specific to what you actually do, rather than copying a template that describes services you do not offer.

Cookies and analytics

Most sites use cookies, from analytics that count visitors to tools that remember preferences. If you use them, say so, and explain how people can control them. For non-essential cookies, the usual approach is to ask for consent before setting them and to make it as easy to refuse as to accept. A short cookies section, linked from the policy, keeps this clear.

Forms, newsletters and customer data

List each way you collect data and what it is for. A contact form collects details to reply to an enquiry. A newsletter sign-up collects an email to send updates, which normally needs clear consent. Booking or order data is needed to deliver the service. For each one, state the purpose, how long you keep it and the lawful basis. This turns a vague promise into a clear record of what happens.

Who else sees the data

You will use other companies to run your business: a website host, an email provider, an accounting tool or a booking system. These are your processors, and your policy should mention that data may be shared with service providers who help you operate. Keep a simple internal list of who they are. If any data leaves the UK, for example to a cloud provider abroad, note how it is protected.

Retention and people’s rights

Say how long you keep each type of data and why, then actually follow it. People have the right to ask to see their data, to have mistakes corrected and, in many cases, to have data deleted or to object to how it is used. Your policy should tell them how to make such a request, usually by contacting you, and how quickly you will respond. Being able to honour these requests matters more than the wording.

Make it findable and keep it current

Link your privacy policy from every page, typically in the footer, and from any form where you collect data. Write it in plain English so a normal customer understands it. Review it whenever your tools, forms or suppliers change, and update the date. An out-of-date policy that describes a different setup is worse than none.

When to get help

For a simple brochure site with a contact form, a clear policy plus sensible habits are usually enough. If you handle sensitive data, large volumes, or you are unsure about consent and legal bases, a short conversation with a data protection adviser is money well spent. They can check your policy and your working practices together, which is where most real problems hide.

And while you are tidying up

Getting the legal basics right is part of looking professional. The other half is being easy to find and contact. Keep your business details consistent everywhere, and make sure people who search for what you offer can actually reach you. A directory profile is a simple way to be found, so add your business to the directory and keep your contact information accurate.

Leave a comment

Your email address will not be published. Required fields are marked *