Most UK business websites need to cover six things: a lawful approach to cookies and tracking, compliance with UK data protection law, clear company identity and contact details, fair and accurate consumer information, an accessible experience, and proper handling of intellectual property. Sites that let visitors interact with each other carry a seventh duty under the Online Safety Act. Public sector bodies have a further accessibility obligation, and every business carries a baseline accessibility duty under equality law.
Two things changed in 2026 that most guides have not caught up with. The Data (Use and Access) Act 2025 completed its rollout on 19 June 2026, and it added a duty that requires a change to your website rather than a change to your paperwork. We cover that in full below.
A short, plain note before we begin: this is general information, not legal advice. The right answer for your business depends on your sector, where your customers are, and how you collect data. If you are in a regulated industry or unsure, take specialist advice.
Which Rules Apply to Your Website?
Not every rule applies to every site. Before working through the detail, find yourself in this list.
- Brochure site, no forms, no tracking: company details, intellectual property, accessibility.
- Brochure site with a contact form or analytics: the above, plus UK GDPR, the PECR cookie rules, the ICO fee, and a complaints route.
- Online shop or any online selling: all of the above, plus consumer, pricing, and cancellation rules.
- Any site with forums, profiles, or user messaging: all of the above, plus Online Safety Act duties.
- Public sector website: all of the above, plus the WCAG 2.2 AA accessibility regulations.
Comments and reviews on your own content do not, on their own, pull you into the Online Safety Act. That distinction matters, and we explain it below.
Do You Need a Cookie Banner, and What Must It Do?
Cookies and similar tracking technologies are governed by the Privacy and Electronic Communications Regulations (PECR), enforced by the Information Commissioner's Office (ICO). The headline rule has not changed: for anything that is not strictly necessary, you must get the visitor's consent before the cookie is set.
What has changed is the detail. The Data (Use and Access) Act 2025 amended PECR, with the cookie provisions coming into force on 5 February 2026, and the ICO finalised its updated guidance on storage and access technologies on 29 April 2026. Together they set a clear standard for what a compliant consent mechanism looks like.
What a Compliant Consent Banner Looks Like
The ICO's position is that your banner must do the following:
- Tell people the cookies are there and explain, in plain terms, what each type does and why.
- Obtain consent before non-essential cookies are set, not after the page has loaded.
- Give a genuine choice, with no pre-ticked boxes and no consent assumed from continued browsing.
- Present "Accept all" and "Reject all" with equal prominence, so refusing is as easy as accepting.
Once a visitor has made their choice, you do not have to ask again on every visit, provided their preference still holds.
The part people get wrong is not the banner, it is the wiring behind it. A banner that appears while your analytics tag has already fired is not compliance, it is a claim you are not meeting. The way to check takes two minutes: open your site in a private browser window, open the network panel in your browser's developer tools, and filter for requests to google. Before you click anything, there should be none. If tracking requests appear before consent, the banner is decorative.
What Are the Cookie Exceptions in 2026?
The 2025 Act added new categories of cookie that no longer need prior consent, alongside the existing strictly necessary and communication exceptions. The most relevant for most businesses are:
- Statistical purposes: first-party analytics used only to collect information about how your site is used so you can improve it.
- Appearance: remembering display preferences a visitor has chosen, such as a dark mode setting.
- Emergency assistance: establishing a user's location to provide emergency help.
There is an important condition. For the statistical and appearance exceptions, you must still tell people what you are doing and give them a simple, free way to object. The relief is narrow, too: analytics data generally cannot be shared with third parties, and any tracking that feeds advertising or is shared with ad partners still needs full consent. If you run a Meta pixel, a LinkedIn tag, or Google Ads conversion tracking, nothing about your obligations has softened.
The Stakes for Getting It Wrong
The 2025 Act also raised the maximum fine the ICO can issue for a PECR breach, from the previous ceiling of £500,000 to £17.5 million or 4% of total worldwide annual turnover, whichever is higher, bringing it in line with UK GDPR. Several guides still quote the old £500,000 figure. It has not applied since 5 February 2026.
Beyond enforcement, a banner that nudges people toward "accept" tends to erode trust, and many visitors are wary of being tracked. A clear, even-handed banner is the safer position on both counts.
How Does UK Data Protection Law Affect Your Website?
Separately from cookies, the UK GDPR and the Data Protection Act 2018 govern how you collect, store, and share personal data, including anything gathered through contact forms, sign-ups, or accounts. The ICO enforces these rules, and the higher maximum fine is £17.5 million or 4% of total worldwide annual turnover, whichever is higher.
Collecting Data: Consent and Transparency
Where you rely on consent to collect personal data, that consent must be specific, informed, freely given, and a clear affirmative act by the person. A few practical points follow from this:
- No pre-ticked boxes. You cannot assume consent. The person has to take a positive action.
- Granular opt-in for marketing. Let people choose each channel they agree to be contacted by, such as email, telephone, or SMS, with a clear explanation of what they are agreeing to and why.
- A clear privacy policy. Publish an accessible page that explains how you collect, store, use, and share data, and who people can contact about it. Linking it site-wide from the footer is the usual approach.
One common trap is the gated download. If someone gives you an email address to receive a guide, they have consented to receive the guide. They have not consented to join your marketing list. If you want both, ask for both, separately and clearly.
Storing Data: Keeping It Secure
UK GDPR requires you to take appropriate measures to protect the personal data you hold, and to report certain breaches to the ICO. On the website itself, that points to a few basics:
- Use HTTPS with a valid TLS certificate. Often still called an SSL certificate, this encrypts the connection so data cannot be intercepted in transit. It is also expected by browsers and search engines, which flag sites served over plain HTTP as "not secure".
- Secure the hosting environment. Strong access controls, current software, and a firewall reduce the risk of a breach at the server level.
- Keep records. Because data protection covers sharing as well as holding, keep a record of who can access your systems and document your security measures.
Handling Complaints: The Rule That Changed on 19 June 2026
This is the newest obligation, and it is the one most website owners have not acted on yet.
The Data (Use and Access) Act 2025 completed its rollout on 19 June 2026. From that date, if someone wants to complain about how you use their personal data, you have to make it straightforward for them to do so. The ICO's guidance points to providing a means of complaining electronically, such as a dedicated form. You then have to acknowledge the complaint within 30 days and respond without undue delay.
For most businesses this is a website job, not a legal one. In practice it means:
- A clear route to complain, ideally a form rather than a general enquiry inbox.
- Wording in your privacy policy that names the route and sets out what happens next.
- Somewhere internally for those complaints to land, with someone responsible for the 30-day acknowledgement.
The same Act also asks anyone running an online service likely to be used by children to take children's needs into account when deciding how to use their data. If you already follow the ICO's Age Appropriate Design Code, you should meet this.
Paying the ICO Data Protection Fee
This one is missed constantly, and it is the cheapest item on the list to fix.
Under the Data Protection (Charges and Information) Regulations 2018, most organisations and sole traders that use personal information must pay an annual data protection fee to the ICO, unless an exemption applies. If your website has a contact form and you keep the enquiries, you are almost certainly processing personal data.
There are three tiers:
- Tier 1, micro organisations: maximum turnover of £632,000, or no more than 10 members of staff. The fee is £52.
- Tier 2, small and medium organisations: maximum turnover of £36 million, or no more than 250 members of staff. The fee is £78.
- Tier 3, large organisations: everyone else. The fee is £3,763.
Charities that are not otherwise exempt pay the tier 1 fee regardless of size. Paying by direct debit takes £5 off. The ICO can fine you for not paying, and its register of fee payers is public, so this is an easy thing to be caught on. The ICO publishes a short self-assessment that tells you whether you need to pay and how much. These figures are current as at August 2026 and are reviewed periodically, so check the ICO's own page before you pay.
What Company Information Must You Display?
Two sets of rules sit behind this. The Electronic Commerce (EC Directive) Regulations 2002 still apply to online services in the UK and require certain provider details to be easily, directly, and permanently accessible. For companies and limited liability partnerships, the Company, Limited Liability Partnership and Business (Names and Trading Disclosures) Regulations 2015, made under the Companies Act 2006, set specific disclosure requirements that extend to your website.
If You Are a Limited Company or LLP
Your website should make the following clear:
- Your registered company name.
- The part of the UK in which you are registered, for example England and Wales.
- Your company registration number.
- The address of your registered office.
If you are registered for VAT, it is good practice to show your VAT number. A contact form on its own is not enough under the e-commerce rules: you also need an email address that lets people reach you directly, and a geographic address. The footer is the usual home for all of this, because it has to be available from every page.
If You Are a Sole Trader or Partnership
If you trade under a name that is not your own name or the names of all the partners, the business names rules can require you to disclose who is behind the business and an address where documents can be served. This is worth reflecting on your website as well as your stationery, so take advice on what applies to your set-up.
If You Work in a Regulated Sector
Some sectors have to publish their regulatory status as well as their company details. The common ones:
- Financial services: FCA authorisation details and firm reference number.
- Legal services: SRA number and regulatory status.
- Healthcare providers: CQC registration details.
- Estate and letting agents: membership of an approved redress scheme, and client money protection details.
- Charities: registered charity number.
Finance, gambling, alcohol, and adult content also carry sector-specific advertising and content rules, and sites aimed at children carry additional obligations. If your site touches a regulated area, take specialist legal advice on what applies rather than working from a general guide.
Are Your Terms, Pricing, and Marketing Lawful?
If you sell goods, services, or digital content, consumer law shapes what you can say and how you must say it. The biggest recent change is the Digital Markets, Competition and Consumers Act 2024, which from 6 April 2025 revoked the old Consumer Protection from Unfair Trading Regulations 2008 and restated the rules on unfair commercial practices. The Competition and Markets Authority (CMA) now enforces these directly, without going to court, with fines of up to 10% of worldwide turnover for serious breaches.
Get Your Descriptions and Prices Right
- Accurate descriptions. Goods and services must be as described, fit for purpose, and of satisfactory quality, so review your product copy for anything misleading.
- Transparent pricing. The total price a consumer must pay, including any mandatory fees such as booking fees or compulsory delivery charges, has to be shown at the earliest point you show a price. Revealing compulsory charges only at the checkout, known as drip pricing, is no longer allowed.
- Honest reviews. Fake reviews are banned outright, and so is concealing that a review was paid for or incentivised. If you publish reviews, you carry a positive duty to take reasonable and proportionate steps to prevent and remove fake ones. Copying a testimonial onto a page with no way of verifying it is now a risk rather than a shortcut.
Distance Selling and Order Confirmation
The Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 apply to most online sales. Before a purchase, you must give consumers clear information about the product, the total price, delivery, and their cancellation rights. For most goods bought online, consumers have a 14-day cancellation period and do not have to give a reason. If you do not tell them about this right, the period can extend by up to 12 months. Provide written confirmation of the order, and if you run an online store, check that your automatic confirmation emails actually send and contain the right detail. It is sensible to reflect all of this in your terms and conditions.
Be Clear When a Chatbot Is Not a Person
If you run an AI assistant on your site, do not present it as a named member of staff. Misleading a consumer about who or what they are dealing with sits squarely inside the unfair commercial practices rules, and the fix costs nothing. Label the assistant as automated, and say how someone reaches a human.
Does the Online Safety Act Apply to Your Website?
Most business websites are outside the Online Safety Act 2023, and a lot of coverage is vague on why. The scope is narrower than the headlines suggest, so it is worth being precise.
The Act regulates user-to-user services and search services. Schedule 1 exempts services with limited functionality, and the exemption specifically covers sites where the only thing users can do in relation to your own content is post comments or reviews on it, share those comments elsewhere, apply a like or dislike, react with an emoji, vote yes or no, or rate the content. If that describes the full extent of interaction on your site, you are exempt.
You are likely in scope if your site lets users interact with each other rather than only with your content. Forums, user profiles, direct messaging, community groups, dating and social features, and file sharing all point that way.
If you are in scope, the duties are substantial: an illegal content risk assessment, a children's access assessment, safety measures and record keeping, and further children's risk assessment duties where children can access the service. Ofcom enforces this, with fines of up to 10% of qualifying worldwide revenue or £18 million, whichever is greater. Ofcom publishes a free tool that walks you through whether the rules apply to your service, and it is the sensible first stop.
A brochure site with a blog and a comments section is almost certainly out of scope. A site with a members' forum is a different conversation, and worth taking advice on.
Does Website Accessibility Apply to Your Business?
This is where the legal duty and good practice diverge, so it is worth being precise.
The Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018 require public sector websites and apps to meet the WCAG 2.2 AA standard and to publish an accessibility statement. These regulations do not apply to private businesses.
Every UK business, however, remains subject to the Equality Act 2010, which requires reasonable adjustments so that disabled people are not put at a substantial disadvantage. There is no fixed technical standard attached to this for private sites, but a disabled user who cannot use your site could bring a discrimination claim, so an inaccessible site is a real risk as well as a barrier to customers.
What About Selling into the EU?
If you sell to consumers in the EU, the European Accessibility Act, which applies from 28 June 2025, may reach you regardless of where your business is based. It covers e-commerce and many digital services, and it leans on the same WCAG principles. If you have EU customers, it is worth checking whether the rules apply to you.
In practice, building to WCAG 2.2 AA is the sensible target for any business. It satisfies the public sector standard, supports your Equality Act duty, aligns with the European Accessibility Act, and tends to improve usability and search performance for everyone. The common failures are unglamorous: low contrast text, images without alt text, and a site you cannot navigate with a keyboard alone. If you want help auditing or improving your site, our web design and web development teams can build accessibility in from the start.
Are You Handling Intellectual Property Correctly?
Intellectual property law protects the trademarks, images, and content on your site, both yours and other people's. Two duties follow.
First, only use content you are entitled to use. License any stock images correctly, check the terms of any logos or product images from third parties, and confirm usage rights with manufacturers where there is doubt. Image owners routinely use crawling tools to find unlicensed use, and the first you hear of it is usually a demand for a licence fee.
Second, protect your own work. A clear copyright notice signals ownership, and if you hold registered trademarks you can display the registered symbol to mark their protected status. This supports your brand and your ability to act if someone copies you.
Common Questions
Is a Cookie Banner a Legal Requirement in the UK?
If your site uses any cookies or trackers that are not strictly necessary, then yes, you must get consent before they are set, and that normally means a banner. As of 2026, a narrow set of analytics and appearance cookies no longer needs prior consent, but you still have to tell people and let them object. Advertising and cross-site tracking still need full consent.
What Changed for Websites on 19 June 2026?
The Data (Use and Access) Act 2025 finished coming into force. The change that affects websites most directly is the requirement to give people a straightforward way to complain about how you use their personal data, such as an electronic form, to acknowledge complaints within 30 days, and to respond without undue delay.
Do I Have to Pay the ICO to Have a Website?
Not for having a website, but if you process personal data, which includes storing contact form enquiries, you almost certainly have to pay the ICO data protection fee unless you are exempt. It is £52 for most micro organisations, £78 for most small and medium organisations, and £3,763 for large ones.
What Is the Maximum Fine for Breaking UK Data and Cookie Rules?
For both UK GDPR and PECR, the higher maximum fine is £17.5 million or 4% of total worldwide annual turnover, whichever is higher. The PECR ceiling was raised from £500,000 to match UK GDPR on 5 February 2026.
Do I Legally Need a Privacy Policy and Terms and Conditions?
If you collect any personal data, UK GDPR effectively requires a privacy policy explaining how you use it. Terms and conditions are not always strictly mandatory, but if you sell online you must provide specific pre-contract information and company details, and a terms page is the practical way to do it.
Does the Online Safety Act Apply to My Business Website?
Only if users can interact with each other. Comments and reviews on your own content are specifically exempt under Schedule 1 of the Act. Forums, user profiles, messaging, and community features bring you into scope, and the duties that follow are significant.
Does My Small Business Website Have to Be Accessible by Law?
The accessibility regulations only bind public sector bodies, but every business has a duty under the Equality Act 2010 to make reasonable adjustments for disabled users. Building to WCAG 2.2 AA is the safest and most useful way to meet that duty, and it becomes a firmer requirement if you sell into the EU.
What Company Details Must Appear on My Website?
A limited company should show its registered name, registration number, place of registration, and registered office address, plus its VAT number if registered. You also need a direct email address and a geographic address, as a contact form alone does not satisfy the e-commerce rules.
Where to Start
The law here is detailed, but the practical version is manageable. Work down this list:
- Check your cookie banner actually blocks tracking before consent, using a private browser window and the network panel.
- Confirm your ICO fee is paid and current.
- Add a data protection complaints route and reflect it in your privacy policy.
- Put your full company details in the footer, with a direct email address.
- Check your pricing shows the total up front, and that any reviews you publish are verifiable.
- Run an accessibility check against WCAG 2.2 AA.
- If users can interact with each other, work through Ofcom's scope tool.
Our website launch checklist covers the practical build steps alongside these legal ones. If you would like a review of where your website stands, or help building these foundations in properly, get in touch.

.avif)

