For many small business owners, GDPR and cookie rules feel like a fog of legal jargon and looming fines. The reality is calmer than the headlines suggest. A small, honest website needs a handful of sensible things in place, not a legal department. This guide explains, in plain English, what a small UK website actually needs to get right. It is general guidance rather than legal advice, but it will help you understand the essentials.
What these rules are really about
Strip away the acronyms and data protection law comes down to one fair idea: if you collect information about people, you should be honest about it, keep it safe, and use it only for what you said you would. GDPR, and the UK version that applies here, exists to protect ordinary people’s personal information. It is not designed to trip up small businesses acting in good faith.
Personal data means anything that can identify someone: a name, an email address, a phone number, in some cases even an IP address. If your website collects any of that, through a contact form, a newsletter signup or an online order, these rules apply to you, whatever your size.
The privacy policy
The cornerstone is a clear privacy policy: a page that explains what information you collect, why, how you use it, how long you keep it and who you share it with. It should be written plainly, so a normal visitor can understand it, and be easy to find, usually linked in your footer. This is the single most important document for compliance, and every site that collects any personal data should have one.
Cookies and consent
Cookies are small files that websites store in a visitor’s browser. Some are essential: they make the site work, remembering what is in a basket, for example. Others track behaviour for analytics or advertising, and it is these that the rules focus on.
The principle is consent: for non-essential cookies, you should ask before you set them, not after. In practice that means a cookie banner which genuinely lets people accept or decline, rather than one that only offers “accept”. Declining should be as easy as agreeing. If your site uses analytics, or any advertising or social media tools, this applies to you.
Lawful basis, in plain terms
The rules ask you to have a good reason, called a lawful basis, for using someone’s data. For most small business situations this is refreshingly common-sense. If someone fills in your contact form, using their details to reply is an obvious and legitimate reason. If you want to add them to a marketing newsletter, though, you generally need their clear consent first, which is why a signup box that is ticked by default is not allowed.
A short checklist
- Publish a plain-English privacy policy and link to it from your footer.
- Add a cookie banner that lets visitors decline non-essential cookies as easily as they can accept them.
- Only collect what you need, and be clear about why you are collecting it.
- Get consent before marketing, and never pre-tick the box.
- Keep personal data secure, which starts with a site served over HTTPS.
- Let people ask what you hold about them, or to have it deleted, and respond when they do.
Security is part of compliance
Keeping personal data safe is not just good manners, it is part of the law. The most basic step is encrypting your site with HTTPS, so anything a visitor types, an enquiry, an order, their details, cannot be read in transit. A site still running without it is failing the simplest test of all.
Every Lucid Cloud Platform plan includes free SSL, so your site is encrypted by default, along with the reliable, well-maintained hosting that keeps the data you hold protected. Compliance is ultimately about treating your visitors’ information with respect, and the right foundations make that far easier to do.

