5 October 2026 · 5 min read
Website cookie consent and privacy basics for small firms
Website cookie consent and privacy basics for a UK small business site: what needs a banner, what a privacy notice should say, and how to spot gaps fast.
Website cookie consent and privacy basics are rarely on a small business owner's mind. The site was built years ago, a developer added a contact form and Google Analytics, and nobody has looked at the legal side since. For a web designer, that gap is both a risk to the client and a perfectly honest reason to start a conversation. This post covers what the rules broadly expect of a UK site and how to check for problems in a few minutes.
A caveat first. This is a practical overview, not legal advice. The Information Commissioner's Office (ICO) publishes guidance on cookies and on privacy information, and it is the source to send a client to when a question gets detailed.
What a cookie banner is actually for
In the UK, the rules on cookies and similar technologies sit in PECR, the same regulations that cover cold email. The core idea is simple. If a site stores or reads information on a visitor's device, it should tell them clearly what it is doing and get their consent first. The exception is for cookies that are strictly necessary, such as the one that remembers what is in a basket or keeps a login session alive.
Analytics and advertising cookies are not in that exempt group. A plumber's site running Google Analytics and a Facebook pixel usually needs a way for visitors to agree before those load. That is why a banner exists, and why a banner that appears but changes nothing does not do the job. If the tracking scripts fire the moment the page opens, the visitor never had a say, whatever the banner says.
A site that sets no non-essential cookies at all does not need a banner. Plenty of simple brochure sites fall into that category, and an unnecessary banner just adds friction.
What a usable consent banner looks like
You do not need to memorise the guidance to spot a weak banner. These are the things worth checking.
- Are non-essential cookies held back until the visitor accepts? Open the site in a private window, decline or ignore the banner, then look at the cookies the browser has stored.
- Is declining as easy as accepting? A bright “Accept all” button next to a faint link buried in the text is a common pattern and a poor one.
- Does the banner describe the cookies in plain terms, and link to a page that lists them?
- Can a visitor change their mind later? A small link in the footer that reopens the settings is enough.
Most small sites use a plugin or a hosted consent tool for this. If the site is built on WordPress, Wix or Squarespace, there is usually a built-in option or a well-known add-on. The common fault is not the absence of a tool but a tool installed and never configured, so that the banner is decoration.
The privacy notice most sites get wrong
Cookies are the visible part. The less visible part is the privacy notice, which UK GDPR expects wherever a site collects personal data. A contact form counts. So does a newsletter sign-up or a booking request. The notice should say who the business is, what personal data it collects, why, how long it keeps it, who it shares it with, and how people can exercise their rights.
The faults are predictable. There is no notice at all. The notice is a generic block of text that names a different company. It was copied from a template and still mentions services the business does not offer. Or it exists but is not linked from the footer or from the page with the form, so nobody sees it where the data is collected.
Take a joiner in Harrogate with an enquiry form. The form collects a name, phone number and a description of the job. The privacy notice should say that, say what the joiner does with it, and say how long enquiries are kept. That is a short page, not a legal treatise. If you are curious how long is sensible for data you hold yourself, we wrote about how long you can keep a prospect's data under UK GDPR, and the same thinking applies to a client's enquiry list.
Forms and third-party scripts
Look at what else the page loads. Embedded maps, video players, chat widgets and booking tools often set their own cookies or pass data to another company. A privacy notice that does not mention them is incomplete. A map embedded on the contact page is a good example of something the owner added in two minutes and forgot.
Also check the form itself. Does it ask for more than it needs? A quote request does not need a date of birth. Is there a clear line near the button pointing to the privacy notice? These small details are easy to fix and easy to explain to a client.
Raising it with a prospect without scaring them
There is a way to get this wrong, which is to wave a fine in front of a small business owner. Do not. You cannot know how a regulator would treat a particular site, and a scare tactic sounds like exactly the sort of email they already ignore. Stick to what you saw. “The site loads analytics before a visitor has made a choice on the banner, and I could not find a privacy notice linked from the enquiry form.” Then offer a fix and a rough price.
Treat it as one finding among several, not the headline. A site with a slow homepage, a broken form and no privacy notice has three honest points to make, and the privacy one is rarely the most persuasive. It pairs well with the checks in our website audit checklist for local business sites.
Where Patchscout fits
When Patchscout audits a business's website, it looks at speed, SEO, mobile behaviour, SSL and the site builder, and uses those findings to ground the outreach email it drafts for you. Cookie and privacy checks are not part of that, so this is a manual look you add yourself. It takes about five minutes with a private browser window, and it can turn a generic email into one that shows you actually opened the site.
Whatever tool you use to find prospects, the habit is the same. Look at the real site, note what you can verify, and describe only that.