Ideas for better growth
Website Privacy Compliance: A Practical Guide
Chris Content · · 5 min read

What a small website actually has to do about personal data: what you collect, consent, notices, retention, and vendor obligations - explained without legalese.
Privacy compliance is usually approached backwards: someone copies a privacy policy from another site, publishes it, and considers the job done. The policy then describes practices the business does not follow, which is worse than having no policy.
The work runs in the other direction. Find out what you actually collect, stop collecting what you do not need, then describe honestly what remains.
This is practical guidance, not legal advice. For your specific obligations, take advice on the markets you serve.
Step 1: Inventory what you collect
Walk your own site and list every point where personal data enters:
- Contact and enquiry forms
- Newsletter signups
- Account registration and login
- Checkout and payment
- Chat, WhatsApp handoffs, and callback requests
- Analytics, advertising, and heatmap tools
- Cookies and browser storage set by you and by third parties
- Server logs, including IP addresses
- Uploaded files, such as CVs on a careers page
For each, record: what is collected, why, where it is stored, who can access it, how long it is kept, and which vendors receive it.
This inventory is the foundation. Everything else depends on it.

Step 2: Delete what you do not need
The cheapest compliance measure is collecting less:
- Remove form fields nobody uses
- Turn off analytics features you never look at
- Remove tracking tags with no owner
- Set retention periods and actually delete old records
- Stop storing card details you have no reason to hold
- Avoid collecting sensitive categories unless genuinely necessary
Data you never collected cannot leak, cannot be requested, and does not need protecting.
Step 3: Understand the principles you are working to
Frameworks differ in detail, but the principles are broadly consistent across India's data protection regime, the EU and UK rules, and most others:
- Purpose limitation. Collect for a stated purpose and do not repurpose silently.
- Data minimisation. Collect only what the purpose requires.
- Notice. Tell people what you collect and why, in clear language.
- Consent or another lawful basis. For many marketing uses, consent must be explicit, informed, and withdrawable.
- Accuracy. Keep it correct and let people correct it.
- Retention limits. Do not keep it indefinitely.
- Security. Protect it proportionately.
- Rights. People can ask what you hold, correct it, and often have it deleted.
If you serve customers across borders, more than one regime may apply.
Step 4: Write a notice that matches reality
A privacy notice should be readable by a customer, not only by a lawyer:
- What you collect, in plain categories
- Why, for each category
- Who you share it with, naming the types of vendor
- How long you keep it
- What rights people have and how to exercise them
- How to contact you about data, with a route that is monitored
- The date it was last updated
Never publish a policy describing practices you do not follow. A copied policy that mentions data you do not collect, or omits data you do, is a liability rather than a protection.
Step 5: Handle consent honestly
- Marketing consent must be opt-in, never pre-ticked
- Separate transactional messages from marketing
- Record what was consented to and when
- Make withdrawal as easy as giving consent
- Re-ask when the purpose materially changes
For cookies and similar storage, see our cookie consent guide. The key point: a banner that does not actually hold non-essential scripts until consent is decoration.
Step 6: Manage your vendors
Every tool that receives customer data is your responsibility to the customer:
- List every vendor and what data each receives
- Check the contract terms cover data processing
- Know where data is stored, and whether it crosses borders
- Confirm their security posture is proportionate
- Have a plan for what happens if a vendor is breached
- Remove vendors you no longer use, and confirm deletion
Step 7: Prepare for requests and incidents
Requests. Decide in advance how you will verify identity, who handles the request, and how you will respond within the expected timeframe. Practise once with a test request.
Incidents. Write a short plan covering who is notified, how you assess scope, what you tell affected people, and any regulatory notification obligation. Deciding this during an incident is how businesses make things worse.
Step 8: Get the basics of security right
Compliance without security is paperwork:
- HTTPS everywhere
- Two-factor authentication on every admin account
- Least-privilege access, reviewed when people leave
- Encrypted backups, with a tested restore
- Patching on a schedule - see our maintenance checklist
- No production data in test environments
Common mistakes to avoid
- Copying another site's privacy policy. It describes their practices, not yours.
- Collecting data "in case it is useful". It is a liability with no owner.
- A consent banner that gates nothing.
- No retention policy. Data accumulates forever and so does the risk.
- An unmonitored privacy contact address.
Frequently asked questions
Does a small business website need a privacy policy?
If it collects any personal data - including through a contact form, analytics, or cookies - then yes. The notice should describe what you actually do, not what a template says.
What is the difference between a privacy policy and a cookie banner?
The policy is the full explanation of what you collect and why. The banner is the mechanism for obtaining consent for non-essential storage before it is set. You generally need both, and the banner must actually control what loads.
How long should I keep customer data?
Only as long as the stated purpose requires, plus any period a legal or tax obligation demands. Write the periods down, and actually delete records when they expire.
What should I do if there is a data breach?
Follow a written plan: contain it, assess what was affected, notify affected people and any regulator within the required timeframe, and document what happened and what you changed.
Next steps
Build the inventory first - every form, tag, and vendor. Delete the fields and tools nobody uses, then rewrite your notice to match what remains.
Start free and keep your consent banner and forms consistent from one place.
