Website privacy and cookies pack for a professional services firm

The privacy notice, cookie notice and consent guidance for a professional services firm's website, drafted for the firm for a fixed fee of £595 in five working days.

Share

Website privacy and cookies pack for a professional services firm

Buy now, £595

A professional firm's website collects enquiries from prospective clients, hosts a portal where existing clients upload documents, runs a newsletter and events programme aimed at business contacts, and carries the pixels and tag managers a marketing team installs without telling anyone. The pack gives the firm the website privacy notice (which is not the same as the client privacy notice in the engagement letter), the cookie notice from an audit of what the site sets, and the consent guidance, written for a firm whose regulator expects transparency and whose clients expect confidentiality. Drafting for the business, I deliver the privacy notice, the cookie notice and guidance on consent in five working days for a fixed £595.

Who this is for

Accountancy, consultancy, architecture, surveying, financial advisory, recruitment and other professional firms in England and Wales with a website that generates enquiries and hosts client-facing tools.

What matters in a professional firm's website pack

The website notice and the client notice as different documents

Article 13 of the UK GDPR requires the business, as controller, to tell the people whose data it collects what it does with it, and a firm collects data on its website (visitors, enquirers, newsletter subscribers, event registrants, portal users) and in its engagements (clients and the people whose data the client's matter involves), which are different data for different purposes under different bases; the website notice covers the first, the client privacy notice in the engagement terms covers the second, and the two should be consistent and cross-refer, because a prospective client who reads the website notice and then receives engagement terms with a different one notices.

Enquiries, the client portal and the data a firm collects online

The enquiry form collects the prospective client's details and a description of their matter (which may include special category data or other people's data, and the notice should say how it is handled and that it is not advice until the engagement starts), the client portal collects documents and messages under the engagement (as part of the client relationship, with the portal provider as a processor and the firm's confidentiality obligations applying), and the online booking of consultations collects what a booking needs; the notice should describe each with its basis (the steps before a contract under Article 6(1)(b) for enquiries, the engagement for the portal, legitimate interests under Article 6(1)(f) for the firm's administration and security) and the conflict check the firm runs on an enquiry, which is a legitimate interest the notice should state.

Business-to-business marketing, events and the firm's newsletter

Regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 allows electronic marketing to individuals only with consent or under the soft opt-in, which covers sole traders and partnerships, while marketing to named individuals at corporate subscribers may rest on legitimate interests with an opt-out, which is the basis most firms use for their newsletters, event invitations and updates; the notice should state the basis for each audience, the sources of the contacts (clients, enquirers, networking, professional networks, event registrations, with Article 14 requiring the firm to tell people whose data it obtained elsewhere), the opt-out in every message, and the event platforms and the email platform as processors, often hosted abroad under the safeguards Article 46 of the UK GDPR requires.

The pixels, the tag manager and the tracking a marketing team installs

Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 makes consent a precondition for non-essential cookies and similar technologies, and professional firms' sites commonly carry a tag manager loading analytics, advertising pixels, visitor identification tools (which match a visitor's address to a company and sometimes to a named contact) and heat-mapping or session recording, each needing consent and each disclosing to its provider which firms and people are reading which pages; the cookie notice is produced from an audit of the live site, the consent guidance covers the tag manager's consent mode and the banner's configuration (reject as prominent as accept, nothing non-essential before consent, records kept), and visitor identification tools should be reviewed against the notice, because a prospective client who learns that the firm knew they were reading the insolvency page is a complaint.

Regulated firms and the transparency their regulator expects

Where the firm is regulated (by a professional body or a statutory regulator), its regulator may require particular transparency on the website (the firm's regulatory status, complaints information, the regulator's logo, fee information in some professions) and may have rules on confidentiality and client data that the notice should reflect, and the firm's anti-money laundering supervision under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 where it applies means client due diligence data is processed under legal obligation and retained for the period the regulations require; the notice should state the regulator, the obligations that affect the data, and the firm's registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018.

The processors, the transfers and the professional confidentiality that sits on top

The notice should name the categories of processor behind the site and the firm's online tools (hosting, the portal, the booking system, the email and event platforms, the CRM, the document and e-signature tools, the analytics), the international transfers under Article 46 of the UK GDPR, the retention (enquiries that do not become engagements for a stated period, newsletter data until withdrawal, portal data under the engagement's retention), and how an individual exercises the rights of access, correction, erasure, restriction, portability and objection, the one-month limit on the response, and the right to go to the Information Commissioner's Office; it should also say that the firm's duty of confidentiality to clients applies to everything a client sends through the site, which is the assurance a professional firm's prospective clients read the notice for.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Our engagement letter has a privacy notice. Do we need one on the website too?

It does, because the website collects different data (enquiries, newsletter, portal, cookies) for different purposes. The two notices should be consistent and cross-refer, and the pack drafts the website one to match the client one.

Our marketing team installed a tool that tells us which companies visited the site. Is that allowed?

It needs cookie consent and disclosure in the notice, and where it identifies named contacts it is processing their data on a basis the firm must state. The audit finds it and the notice and banner are drafted to cover it, or the firm removes it.

Named individuals at limited companies, on legitimate interests with an opt-out; sole traders and partnerships, with consent or the soft opt-in. The notice states the basis for each audience.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.