UK Website Legal Requirements for Small Businesses
What UK law actually requires on a small business website, in plain English, with links to the official sources.

Short answer
A UK business website generally needs: your business identity and contact details (plus company number and registered office for a limited company, and VAT number if registered), a privacy notice under UK GDPR, cookie consent for non-exempt cookies under PECR, and, if you sell to consumers online, clear pricing, pre-contract information and cancellation rights. Many businesses also need to pay the ICO data protection fee.
UK website legal requirements for a small business come from a handful of different laws, which is why they are confusing. In short: say who you are, explain what personal data you collect, get consent for cookies that need it, and, if you sell online to consumers, give clear prices and cancellation rights. This guide sets out each requirement in plain English and links to the official source.
This is general information, not legal advice. For anything specific to your business, particularly regulated sectors, speak to a solicitor. Everything below reflects the position at the time of writing (October 2026).
Who you are: business identity and contact details
Every business website
The Electronic Commerce (EC Directive) Regulations 2002 require businesses providing services online to make certain information easily, directly and permanently accessible. In practice that means a footer or contact page showing:
- your business name (your own name, if you are a sole trader)
- a geographic address where you operate — not only a PO box
- an email address — a contact form alone is not enough
- your VAT number, if you are VAT registered
- details of any professional body or regulator, if your trade is regulated
Limited companies and LLPs
The Company, Limited Liability Partnership and Business (Names and Trading Disclosures) Regulations 2015 add specific requirements for companies. Your website must show:
- the company's full registered name, exactly as registered at Companies House
- the part of the UK where it is registered (for example, England and Wales)
- the company registration number
- the registered office address
The footer is the usual place. Check it matches Companies House exactly — trading names are fine to use in branding, but the registered name has to appear too.
Privacy: what personal data you collect
If your site collects any personal data — through a contact form, a newsletter sign-up, a booking system, an account area, or analytics that identify individuals — UK GDPR requires a privacy notice. It should explain, in clear language:
- who you are and how to contact you about data
- what personal data you collect, and from where
- why you collect it, and the lawful basis for each purpose
- who you share it with — including the email platform, CRM, booking tool and hosting provider
- whether data leaves the UK, and how it is protected if so
- how long you keep it
- people's rights, including access, correction, deletion and complaining to the ICO
The ICO's guidance for organisations includes material written for small businesses. If your website feeds data into automated tools — a CRM, AI assistants, workflow automations — GDPR and AI automation for UK businesses covers what changes.
The ICO data protection fee
Most organisations that process personal data must pay an annual data protection fee to the ICO unless an exemption applies. At the time of writing, the fee is £52 for tier 1 (micro organisations) and £78 for tier 2 (small and medium organisations), per the ICO's data protection fee page. The ICO has a self-assessment to check whether you need to pay.
Cookies: consent under PECR
Cookies and similar technologies are governed by the Privacy and Electronic Communications Regulations (PECR), which were amended by the Data (Use and Access) Act 2025. The relevant changes took effect in 2026, and the ICO finalised its guidance on storage and access technologies in April 2026.
The rule is still consent by default, with exceptions:
| Use | Consent needed? |
|---|---|
| Strictly necessary (logins, baskets, security) | No |
| Appearance and functionality the user expects (e.g. remembering preferences) | No, under the new exceptions |
| Statistical analytics to improve your own site, with a simple way to opt out | No, if the conditions in the ICO guidance are met |
| Advertising, remarketing, cross-site tracking | Yes |
| Most third-party embeds and marketing tags that track | Generally yes |
The analytics exception is narrower than it sounds. Whether a particular tool qualifies depends on how it is configured and what the provider does with the data, so check the ICO guidance against your actual setup. If you run advertising pixels or remarketing, you still need a proper consent banner with an equally easy "reject" option, and those tags must not fire before consent.
The Act also raised PECR penalties to UK GDPR levels, so this is no longer a low-stakes area.
Selling online to consumers
If customers can buy from your site, more rules apply.
Pre-contract information and cancellation
The Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 require you to give consumers key information before they buy — the main characteristics of the goods or service, the total price including taxes and delivery, your identity and address, and their cancellation rights. For most distance sales of goods, consumers have a 14-day cancellation period, with exceptions such as personalised or perishable items.
Prices, reviews and unfair practices
The consumer protection parts of the Digital Markets, Competition and Consumers Act 2024 came into force on 6 April 2025. Two points matter for most small websites:
- Headline prices must include unavoidable fees. Adding mandatory charges late in checkout ("drip pricing") is banned.
- Fake reviews are banned, including commissioning or publishing reviews that are not genuine, and businesses that publish reviews must take reasonable steps to prevent and remove fake ones.
The CMA can now enforce consumer law directly and fine businesses for breaches.
Terms and conditions
Not a single statutory requirement in themselves, but if you sell online they are where most of the required information lives: delivery, returns, cancellation, and complaints. They must be consistent with consumer law — you cannot contract out of statutory rights.
Accessibility
Private businesses are not covered by the public sector accessibility regulations, but the Equality Act 2010 requires service providers to make reasonable adjustments for disabled people, which can extend to websites. Following WCAG is the practical way to meet that. Website accessibility for small businesses explains what it involves without the jargon.
Marketing emails from website sign-ups
If your site collects email addresses for marketing, PECR rules apply to the emails you send. Sign-up consent should be clear and specific, tick boxes must not be pre-ticked, and every email needs an easy unsubscribe. Existing customers can sometimes be emailed under the "soft opt-in", but only about similar products and only if they were given a chance to opt out when their details were collected.
Keeping it current
Legal pages drift out of date quietly. Every time you add a new tool — a chat widget, a booking system, a new analytics or ad platform — the privacy notice and cookie setup may need updating. A six-monthly review is a sensible part of website maintenance. Data protection also covers what happens behind the scenes, including how backups store personal data and how the site is kept secure.
UK website legal requirements: a quick checklist
- Business name, geographic address and email address visible
- Company name, number, registered office and country of registration (limited companies)
- VAT number, if registered
- A privacy notice that matches what you actually collect
- ICO data protection fee paid, or exemption confirmed
- Cookie handling reviewed against the current ICO guidance
- Clear total pricing, pre-contract information and cancellation rights, if selling online
- No fake or incentivised-but-undisclosed reviews
- Marketing sign-ups with clear, unticked consent and an unsubscribe in every email
- An accessibility review against WCAG
If you would like your site checked against this list as part of ongoing upkeep, that review sits within the website maintenance service; for a new build, it is part of the website development service from the start. Neither replaces legal advice, but both make sure the site does what your legal pages say it does.
Related services
Related reading
Maintenance & Security
Website Maintenance: The Complete Guide for Business Owners
What keeping a business website healthy actually involves, which jobs matter most, and how to decide who should do them.
Maintenance & Security
Website Backups: What a Proper Backup Strategy Looks Like
Having backups and being able to recover are different things. Here is how to make sure you have the second.
Maintenance & Security
WordPress Security: A Practical Guide for Business Sites
Most WordPress hacks are automated and boringly preventable. Here is what actually stops them, in order of value.
Web Development
Website Accessibility (WCAG) for Small Businesses
What the law actually asks of a private UK business, what WCAG is, and the dozen checks that catch most problems.