Website privacy and cookies pack for a small business

The privacy notice, cookie notice and consent guidance for a small business website, drafted for the business for a fixed fee of £595 in five working days.

Share

Website privacy and cookies pack for a small business

Buy now, £595

A small business website collects enquiries through a form, perhaps a newsletter sign-up, perhaps a booking or a purchase, and sets cookies for analytics and whatever the builder adds; the law requires a privacy notice that explains what happens to the data, a cookie notice that lists what is set, and a consent mechanism that stops the non-essential cookies until the visitor agrees. The pack is those three things, drafted for the business rather than copied from a generator, with a note on the few operational steps that make them true. The privacy notice and the cookie notice are drafted for the business, with guidance on the consent mechanism, for a fixed £595 and delivery in five working days.

Who this is for

Small businesses in England and Wales with a website, from a sole trader with a brochure site to a company with forms, bookings and a newsletter, whose current notice came from a generator or from the previous web developer.

What matters in a small business website pack

The three documents and what each does

The privacy notice tells visitors and customers what the business does with their personal data, as The controller's duty under Article 13 of the UK GDPR is to tell them; the cookie notice lists the cookies and similar technologies the site sets, by category and purpose, so that the visitor can see what they are consenting to; and the consent guidance explains how to configure the banner the website builder or a consent tool provides so that the non-essential cookies wait for consent, as regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 requires; the three are drafted together because they refer to each other, and a privacy notice that describes cookies the cookie notice does not list is the inconsistency a complaint finds.

The data a small website collects and the notice that explains it

The notice should describe what the site collects (enquiry details, account and order data where there is commerce, newsletter sign-ups, booking details, the device and usage data the analytics record) and the lawful basis for each (the contract or the steps before it under Article 6(1)(b) for orders, enquiries and bookings, legitimate interests under Article 6(1)(f) for security, analytics and the business's own administration with the interest stated, consent for marketing and cookies), the recipients, the retention and the individual's rights over their data (access, rectification, erasure, restriction, portability, objection), the process and the one-month limit, and the complaint to the Information Commissioner's Office; it should be written for the business's actual site rather than for a site it does not have.

The forms, the enquiries and the mailing list

The contact form should collect only what an enquiry needs and link to the notice; the newsletter sign-up should obtain consent by a positive action or implement the soft opt-in where the business sells and the sign-up is in the course of a sale, because consent, or the soft opt-in, is what regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 requires before marketing an individual electronically; the enquiry should not be added to the mailing list without one or the other; and the email platform the business uses is a processor whose terms the business has accepted, often hosted abroad under the safeguards Article 46 of the UK GDPR requires, which the notice should say.

The hosting, the builder and the suppliers behind the site

The notice should name the categories of supplier that receive the data: the hosting provider or website builder (a processor, with its data processing terms in its contract), the form and booking tools, the payment processor where the site sells (a controller for its own fraud and compliance purposes), the email platform, the analytics provider, the chat tool, and the business's own accounting and CRM software where enquiries are transferred into it; the business should know where each is hosted, because the notice has to state the transfers, and the guidance lists the suppliers the audit found.

Cookies, the banner and the audit

The cookie notice is produced from an audit of the live site (what fires with consent refused and with consent given, on each page type), listing the cookies by category with name, purpose, provider and duration, and the consent guidance explains how to configure the builder's banner or a consent tool so that the analytics, marketing and embedded-content cookies wait for consent, with reject as prominent as accept, no pre-ticked boxes, a way to change the choice, and records of consent kept; the Data (Use and Access) Act 2025 adds an opt-out exception for some analytics cookies once in force and where the conditions are met, and the guidance explains how to configure the site for either position.

Registration, retention and the operational steps the pack assumes

The business should be registered with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018, which the notice can say, and the note that comes with the pack lists the operational steps the documents assume: the retention periods the business will apply (enquiries that go nowhere deleted after a stated period, customer records for the period tax law requires, the mailing list cleaned of inactive subscribers), the suppliers' data processing terms held, the banner configured and tested, the forms linked to the notice, and a date for the next review; a notice that promises retention the business does not apply is the promise a subject access request exposes.

What it costs

Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

Our web developer put a privacy policy on the site. Why replace it?

Because a generated notice describes a site the business may not have and omits the suppliers, the transfers and the retention the business in fact uses, and because the cookie banner usually does not block anything. The pack is drafted for the site the business has.

Do we need to register with the Information Commissioner's Office?

Most businesses with a website and customer records do, and the fee is modest. The notice can state the registration; the note explains how to register.

It tells the business how: the mode that blocks, the categories, the prominence of reject, the records, and the test that confirms nothing fires before consent, for the builder the site uses. The business or its developer applies the settings.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.