Skip to content
Maintenance & Security 6 min read Sajid Aslam

UK Website Legal Requirements for Small Businesses

What UK law actually requires on a small business website, in plain English, with links to the official sources.

Checklist of UK legal requirements for a small business website

Short answer

A UK business website generally needs: your business identity and contact details (plus company number and registered office for a limited company, and VAT number if registered), a privacy notice under UK GDPR, cookie consent for non-exempt cookies under PECR, and, if you sell to consumers online, clear pricing, pre-contract information and cancellation rights. Many businesses also need to pay the ICO data protection fee.

UK website legal requirements for a small business come from a handful of different laws, which is why they are confusing. In short: say who you are, explain what personal data you collect, get consent for cookies that need it, and, if you sell online to consumers, give clear prices and cancellation rights. This guide sets out each requirement in plain English and links to the official source.

This is general information, not legal advice. For anything specific to your business, particularly regulated sectors, speak to a solicitor. Everything below reflects the position at the time of writing (October 2026).

Who you are: business identity and contact details

Every business website

The Electronic Commerce (EC Directive) Regulations 2002 require businesses providing services online to make certain information easily, directly and permanently accessible. In practice that means a footer or contact page showing:

  • your business name (your own name, if you are a sole trader)
  • a geographic address where you operate — not only a PO box
  • an email address — a contact form alone is not enough
  • your VAT number, if you are VAT registered
  • details of any professional body or regulator, if your trade is regulated

Limited companies and LLPs

The Company, Limited Liability Partnership and Business (Names and Trading Disclosures) Regulations 2015 add specific requirements for companies. Your website must show:

  • the company's full registered name, exactly as registered at Companies House
  • the part of the UK where it is registered (for example, England and Wales)
  • the company registration number
  • the registered office address

The footer is the usual place. Check it matches Companies House exactly — trading names are fine to use in branding, but the registered name has to appear too.

Privacy: what personal data you collect

If your site collects any personal data — through a contact form, a newsletter sign-up, a booking system, an account area, or analytics that identify individuals — UK GDPR requires a privacy notice. It should explain, in clear language:

  1. who you are and how to contact you about data
  2. what personal data you collect, and from where
  3. why you collect it, and the lawful basis for each purpose
  4. who you share it with — including the email platform, CRM, booking tool and hosting provider
  5. whether data leaves the UK, and how it is protected if so
  6. how long you keep it
  7. people's rights, including access, correction, deletion and complaining to the ICO

The ICO's guidance for organisations includes material written for small businesses. If your website feeds data into automated tools — a CRM, AI assistants, workflow automations — GDPR and AI automation for UK businesses covers what changes.

The ICO data protection fee

Most organisations that process personal data must pay an annual data protection fee to the ICO unless an exemption applies. At the time of writing, the fee is £52 for tier 1 (micro organisations) and £78 for tier 2 (small and medium organisations), per the ICO's data protection fee page. The ICO has a self-assessment to check whether you need to pay.

Cookies and similar technologies are governed by the Privacy and Electronic Communications Regulations (PECR), which were amended by the Data (Use and Access) Act 2025. The relevant changes took effect in 2026, and the ICO finalised its guidance on storage and access technologies in April 2026.

The rule is still consent by default, with exceptions:

UseConsent needed?
Strictly necessary (logins, baskets, security)No
Appearance and functionality the user expects (e.g. remembering preferences)No, under the new exceptions
Statistical analytics to improve your own site, with a simple way to opt outNo, if the conditions in the ICO guidance are met
Advertising, remarketing, cross-site trackingYes
Most third-party embeds and marketing tags that trackGenerally yes

The analytics exception is narrower than it sounds. Whether a particular tool qualifies depends on how it is configured and what the provider does with the data, so check the ICO guidance against your actual setup. If you run advertising pixels or remarketing, you still need a proper consent banner with an equally easy "reject" option, and those tags must not fire before consent.

The Act also raised PECR penalties to UK GDPR levels, so this is no longer a low-stakes area.

Selling online to consumers

If customers can buy from your site, more rules apply.

Pre-contract information and cancellation

The Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 require you to give consumers key information before they buy — the main characteristics of the goods or service, the total price including taxes and delivery, your identity and address, and their cancellation rights. For most distance sales of goods, consumers have a 14-day cancellation period, with exceptions such as personalised or perishable items.

Prices, reviews and unfair practices

The consumer protection parts of the Digital Markets, Competition and Consumers Act 2024 came into force on 6 April 2025. Two points matter for most small websites:

  • Headline prices must include unavoidable fees. Adding mandatory charges late in checkout ("drip pricing") is banned.
  • Fake reviews are banned, including commissioning or publishing reviews that are not genuine, and businesses that publish reviews must take reasonable steps to prevent and remove fake ones.

The CMA can now enforce consumer law directly and fine businesses for breaches.

Terms and conditions

Not a single statutory requirement in themselves, but if you sell online they are where most of the required information lives: delivery, returns, cancellation, and complaints. They must be consistent with consumer law — you cannot contract out of statutory rights.

Accessibility

Private businesses are not covered by the public sector accessibility regulations, but the Equality Act 2010 requires service providers to make reasonable adjustments for disabled people, which can extend to websites. Following WCAG is the practical way to meet that. Website accessibility for small businesses explains what it involves without the jargon.

Marketing emails from website sign-ups

If your site collects email addresses for marketing, PECR rules apply to the emails you send. Sign-up consent should be clear and specific, tick boxes must not be pre-ticked, and every email needs an easy unsubscribe. Existing customers can sometimes be emailed under the "soft opt-in", but only about similar products and only if they were given a chance to opt out when their details were collected.

Keeping it current

Legal pages drift out of date quietly. Every time you add a new tool — a chat widget, a booking system, a new analytics or ad platform — the privacy notice and cookie setup may need updating. A six-monthly review is a sensible part of website maintenance. Data protection also covers what happens behind the scenes, including how backups store personal data and how the site is kept secure.

  • Business name, geographic address and email address visible
  • Company name, number, registered office and country of registration (limited companies)
  • VAT number, if registered
  • A privacy notice that matches what you actually collect
  • ICO data protection fee paid, or exemption confirmed
  • Cookie handling reviewed against the current ICO guidance
  • Clear total pricing, pre-contract information and cancellation rights, if selling online
  • No fake or incentivised-but-undisclosed reviews
  • Marketing sign-ups with clear, unticked consent and an unsubscribe in every email
  • An accessibility review against WCAG

If you would like your site checked against this list as part of ongoing upkeep, that review sits within the website maintenance service; for a new build, it is part of the website development service from the start. Neither replaces legal advice, but both make sure the site does what your legal pages say it does.

Related services

Related reading

FAQ

Questions about this

If yours isn't here, send it over — I reply within one working day.

If the website collects any personal data — a contact form, an email sign-up, analytics that identify visitors — then yes. UK GDPR requires you to tell people what you collect, why, on what lawful basis, how long you keep it and what their rights are. Being a sole trader does not change that duty.

It depends on the cookies. Since the Data (Use and Access) Act 2025 changes took effect, some low-risk uses, including certain first-party analytics with an easy opt-out, no longer need prior consent. Advertising, cross-site tracking and most third-party marketing tags still do. If you use any of those, you still need a proper consent mechanism.

You should not. It may be copyright material, and more importantly it describes someone else's data processing, not yours. A privacy notice has to reflect what your site and business actually collect and do. Templates are a reasonable starting point, provided you edit every section to match reality.

Usually a complaint or a regulator's letter first, rather than an immediate fine. But penalties exist: the ICO can fine for data protection and PECR breaches, Trading Standards enforce disclosure and consumer rules, and the CMA can now fine directly for consumer law breaches. Non-compliance also undermines trust with the customers who notice.