GDPR isn't just for big tech. If your website serves customers in the UK or EU — even a single booking form — a few basic obligations apply. The reassuring news: for a typical local business, compliance is straightforward and mostly a one-time setup. It also builds trust, because customers increasingly look for it.
Why this applies to a local business
The moment your website collects personal data — a name and email on a contact form, a phone number for a booking, or analytics cookies that track visitors — you're processing personal data. GDPR (and the UK equivalent) sets out how you must handle it: lawfully, transparently, and only for what you actually need.
This guide explains the practical shape of compliance so you know what to put in place. For anything specific to your business, have your policies reviewed by a qualified professional.
The cookie banner — done properly
If your site uses non-essential cookies (analytics, ad pixels, embedded maps or videos), visitors must be able to accept or decline them before they load. A banner that only says "we use cookies, OK" isn't compliant — declining has to be as easy as accepting.
What good looks like
- Clear choice: Accept / Reject / Manage.
- Non-essential cookies don't fire until the visitor consents.
- A link to your cookie or privacy policy.
Your privacy policy
A privacy policy is a plain-language page explaining what data you collect, why, how long you keep it, who you share it with, and how someone can request or delete their data. It should be linked in your footer on every page.
Contact and booking forms
Every form that collects personal data should say, briefly, what you'll do with the information — for example, "We'll use your details only to respond to your enquiry." Avoid pre-ticked marketing boxes; consent to marketing must be a separate, active choice.
What to keep and what to delete
- Collect only what you genuinely need — every extra field is extra risk
- Keep data only as long as it's useful, then delete it
- Store it securely; don't email spreadsheets of customer data around
- Be able to find, export or delete a person's data if they ask
Businesses that handle data respectfully get rewarded with it — people are far more willing to share a phone number or email when it's obvious you'll look after it.
Common questions
I only have a contact form. Do I really need all this?
You need a privacy policy and to handle that data responsibly. If you also run analytics or ad pixels, you need a proper cookie banner too. A simple contact-only site is a light lift.
Does GDPR apply if I'm only in the US?
GDPR applies to EU/UK residents' data. If you never serve them, it may not apply — but similar US state laws (like CCPA in California) increasingly do, and the good practices overlap.
Are Google Analytics cookies "essential"?
No. Analytics and advertising cookies are non-essential and require consent before they load.
Want this handled for you? Run a free audit and ranker.bot will find the issues, prioritise them, and fix the ones you approve — in plain English, no agency retainer.