Service
GDPR-compliant websites
UK GDPR-compliant website design for small businesses. No third-party cookies, lawful forms, honest privacy notices, ICO registration guidance.

A GDPR-compliant website is one that collects only the personal data it genuinely needs, tells people plainly what happens to it, and can honour their rights over it. Under the UK GDPR and the Data Protection Act 2018 the practical obligations for a small business site are narrow but real: have a lawful basis for every form you run, publish a privacy notice that describes your actual practices rather than a template’s, obtain consent before setting any non-essential cookie, and be able to find and delete someone’s data on request. Most small business sites fail on the third point — usually because an embedded map, video or analytics script sets cookies the owner never knew about. Point28 builds with no third-party requests at all by default, which removes most of the compliance surface a small business site would otherwise be carrying without realising it. Starting prices are published in full, not quoted on request.
What makes most small business websites non-compliant?
Third-party embeds. A social feed, a hosted video player, a web font loaded from someone else’s server or a map iframe will typically set cookies or transmit the visitor’s IP address before any consent is given. The site owner is responsible for this even though they did not write the code.
How do you avoid needing a cookie banner?
By not setting non-essential cookies. Self-host the fonts, serve images and video from your own domain, and use analytics that identifies no one. That removes the consent requirement entirely — you still publish a privacy notice, but there is nothing to ask permission for.
Is a contact form personal data?
Yes. A name and an email address are personal data, so you need a lawful basis (normally legitimate interests or consent), a retention period you actually apply, and a privacy notice that says where enquiries go. If enquiries are forwarded to a third-party inbox or CRM, that has to be disclosed.
What happens if I get this wrong?
For a small business the realistic risk is not a headline fine — it is an ICO complaint from a customer, and the time cost of responding to it. The cheaper position is to collect less data in the first place.
Frequently asked questions
Does my small business website need a cookie banner?
Only if you set non-essential cookies. If you use no analytics cookies, no advertising pixels and no embedded third-party media, you do not need a consent banner at all — you still need a privacy notice. Removing the trackers is usually simpler than managing consent for them.
Do I need to register with the ICO?
Most UK organisations processing personal data must pay the ICO data protection fee, which starts at £52 a year for small organisations. Collecting enquiries through a contact form is processing personal data. Check your position with the ICO's self-assessment.
Is Google Analytics GDPR-compliant?
It can be configured to be, but it requires consent, and a consent banner suppresses a meaningful share of your data anyway. For most small businesses a cookieless analytics tool answers the same questions without the compliance burden.
What has to be in a privacy notice?
Who you are, what personal data you collect, why, on what lawful basis, how long you keep it, who you share it with, and what rights the person has. It must be written plainly. A copied template naming another company's practices is worse than none.
Ready to talk about gdpr-compliant website design uk?
Share your date and rough guest count — we will come back with next steps within one working day.