25 Mar 2018

GDPR Changes How Businesses Handle Website Data

With GDPR taking effect in May 2018, UK business websites should review how they collect, store and use personal data across forms, privacy notices, analytics, email marketing, social media tracking and domain records.

GDPR Changes How Businesses Handle Website Data

From 25 May 2018, the General Data Protection Regulation will change the way UK businesses collect, store and use personal information online. For many organisations, this is not simply a legal exercise; it is an opportunity to improve trust, tidy up marketing processes and build a website that treats customer data with the same care as any other valuable business asset. GDPR data protection affects contact forms, email sign-ups, analytics, advertising, social media activity, domain ownership details and the systems behind a website, so it deserves attention early rather than as a last-minute policy update.

The good news is that GDPR is not designed to stop businesses from marketing themselves. It is designed to make data use clearer, fairer and more accountable. If your website is well planned, transparent and secure, GDPR can support better digital marketing by encouraging cleaner lists, more relevant communications and stronger relationships with people who genuinely want to hear from you.

What GDPR means for business websites

GDPR applies to personal data, which means information that can identify a living person either directly or indirectly. On a website, that may include a name, email address, telephone number, postal address, IP address, account login, enquiry details, order information or other identifiers collected through forms, cookies and tracking technologies.

For UK business owners, the first practical step is to understand where personal data enters your website and where it goes afterwards. A simple brochure website may only collect data through a contact form. An e-commerce website, membership site or booking system will usually process much more information. Marketing websites may also collect data through newsletter sign-ups, downloadable guides, analytics platforms, remarketing tags and social media advertising tools.

Under GDPR, businesses must have a lawful basis for processing personal data. Consent is one lawful basis, but it is not the only one. For example, you may need to process someone’s details to respond to an enquiry, provide a quotation, fulfil an order or meet a legal obligation. The key is to know your basis, explain it clearly and avoid collecting more information than you need.

Why GDPR data protection can add business value

It is tempting to see GDPR as a compliance burden, but a clearer approach to data can make digital marketing more effective. Many businesses have old mailing lists, unclear sign-up routes and duplicate contact records spread across email accounts, spreadsheets and customer systems. Reviewing these now can reduce waste and help teams communicate with greater confidence.

Customers are increasingly aware of how their information is used. A website that explains data collection plainly can feel more trustworthy than one that hides important details in vague wording. Trust supports conversion. If a visitor is considering sending an enquiry, requesting a callback or opening an account, they are more likely to proceed when the website feels professional, secure and transparent.

GDPR can also improve internal decision-making. When a business maps its data, it often discovers unnecessary forms, outdated fields, unprotected exports or unclear access rights. Removing these weak points reduces risk and makes day-to-day work simpler. A cleaner marketing database can also improve email engagement because it is made up of people who have a clearer relationship with the business.

Website design changes to consider before May 2018

Good website design in 2018 should include privacy by design. This means thinking about data protection at the planning stage, not adding a policy page after everything else is finished. If you are redesigning your website, launching new landing pages or adding online forms, GDPR should be part of the brief.

Review every form

Contact forms, quotation forms, booking forms and newsletter sign-ups should ask only for information that is genuinely needed. If a first enquiry can be handled with a name, email address and message, avoid asking for unnecessary personal details. The shorter form may also improve conversion by reducing friction for the user.

Where a form is used for marketing consent, the wording should be specific and unambiguous. Pre-ticked boxes should not be used for consent. If someone is signing up to receive email updates, they should actively choose to do so, and the form should explain what type of communication they can expect.

Make privacy notices clear

A privacy notice should be easy to find and written in plain English. It should explain what data is collected, why it is collected, how it is used, who it may be shared with, how long it may be kept and how individuals can exercise their rights. These rights include access, correction, deletion in certain circumstances, objection and restriction of processing.

A privacy notice does not need to be frightening or overly complicated, but it must be accurate. Avoid copying generic wording that does not reflect how your business actually works. If your website sends enquiries into a customer relationship system, email marketing platform or order management system, the notice should reflect that.

Improve security signals

Security is part of data protection. If your website collects personal information, it should use HTTPS so that data is encrypted in transit. In 2018, visitors are becoming more familiar with secure browser indicators, and search engines have been encouraging secure websites for some time. HTTPS is not only about trust; it is a sensible baseline for any modern business website.

Website administrators should also review passwords, user roles, software updates, form storage and backup procedures. If multiple staff members can access website enquiries or customer records, each person should have an appropriate level of access rather than a shared login used by everyone.

Cookies, analytics and tracking

Many websites use analytics to understand visitor behaviour, popular pages, traffic sources and conversion paths. Analytics data can be extremely useful for search marketing and website improvement, but it still needs to be considered as part of your GDPR preparation, particularly where identifiers, IP addresses or advertising features are involved.

Businesses should review the tracking scripts and cookies installed on their websites. Some may be essential for the site to function, while others support analytics, advertising or social media features. It is important to understand the difference and to explain cookie use clearly. Existing UK cookie rules under PECR remain relevant, so cookie notices and consent approaches should not be ignored while preparing for GDPR.

If you use analytics to measure enquiries, downloads or sales, make sure the data being passed into reports is appropriate. Avoid sending names, email addresses or telephone numbers into analytics reports through page URLs, form fields or search query data. Keep reporting useful, but do not turn analytics into an unnecessary store of personal data.

Email marketing is one area where GDPR has prompted many questions. The essential principle is that people should understand what they are signing up to and should not be misled. If you rely on consent, it must be freely given, specific, informed and unambiguous. You should also be able to demonstrate when and how that consent was obtained.

For new sign-ups, this means using clear wording near the sign-up form. For existing lists, businesses should check whether their records are reliable and whether the basis for contacting people is still valid. A list built from unclear sources, old competitions or purchased data may create more risk than value. A smaller, better-quality list is often more useful than a large list full of people who are unlikely to engage.

Every marketing email should make it easy for recipients to opt out. Unsubscribe requests should be acted upon promptly, and suppression records should be managed carefully so that people who have opted out are not accidentally added back into active campaigns.

Social media marketing and advertising

Social media remains an important route for brand awareness, community building and paid advertising, but GDPR affects how businesses use personal data in this area too. If you upload customer email addresses or telephone numbers to create advertising audiences, you need to be confident that you have an appropriate lawful basis and that your privacy notice explains this type of processing.

Tracking pixels and social sharing tools should also be reviewed as part of your website audit. These technologies can support remarketing and campaign measurement, but they must be used responsibly. Business owners should ask what data is being collected, why it is being collected and whether visitors are given clear information.

For organic social media activity, staff should be reminded not to publish personal information about customers, competition entrants or employees without appropriate permission. A simple internal social media policy can help prevent accidental disclosure and keep brand communications consistent.

Domain registration and business ownership details

Domain names are often overlooked during digital reviews, yet they are an important part of online governance. Your domain should be registered in the correct legal or business name, with accurate contact details and clear internal ownership records. If an employee, supplier or former contractor is listed as the registrant without proper documentation, it can cause serious problems later.

As part of GDPR preparation, review the personal data connected with domain registration and administration. Keep records accurate, use appropriate business contact details where possible and ensure that access to domain management is controlled. Do not rely on one individual’s personal email address as the only route for renewals or administrative changes.

Businesses should also keep a secure record of domain renewal dates, registrar access, DNS settings and authorised contacts. This is not only a data protection matter; it is good digital housekeeping. Losing control of a domain can disrupt email, website traffic, search visibility and customer trust.

SEO, content and trust signals

GDPR does not replace search engine optimisation, but it does influence the quality and trustworthiness of a website. Search marketing depends on useful content, clear structure, technical reliability and positive user experience. A website that feels secure, transparent and easy to use gives visitors more confidence to enquire, subscribe or buy.

From an SEO perspective, businesses should make sure important policy pages are accessible without creating clutter. Privacy notices, cookie information and terms should be linked sensibly, commonly from the footer and near relevant forms. These pages should be written for real users, not stuffed with legal phrases or keywords.

Content marketing should also respect data protection. If you publish case studies, testimonials, photographs or customer stories, confirm that you have permission to use the personal information involved. Where a testimonial includes a name, job title, photograph or company details, keep a record of the approval. If consent is withdrawn and the circumstances require removal, make sure your website team knows how to update the content quickly.

Technology, suppliers and accountability

Many websites rely on third-party suppliers, including hosting providers, web developers, email marketing systems, payment processors, analytics services and customer management tools. GDPR expects businesses to take responsibility for how personal data is processed, including by suppliers acting on their behalf.

Ask each supplier what data they process, where it is stored, what security measures are in place and what contractual terms apply. For higher-risk activities, written agreements should set out responsibilities clearly. If your website agency manages hosting, forms, backups or support access, make sure the arrangement is documented and understood by both sides.

Accountability is a central part of GDPR. This means being able to show what you have done, not merely saying that you take privacy seriously. Useful records may include data maps, consent logs, privacy notice versions, supplier agreements, retention schedules and internal procedures for handling requests from individuals.

GDPR website checklist for 2018

  • List all website forms and remove unnecessary data fields.
  • Check that consent wording is clear, specific and not based on pre-ticked boxes.
  • Update the privacy notice so it accurately reflects your website and marketing activity.
  • Review cookies, analytics scripts, advertising tags and social media tracking.
  • Use HTTPS across the website, especially on pages that collect personal data.
  • Check where form submissions are stored and who can access them.
  • Review email marketing lists and record the basis for contacting subscribers.
  • Make opt-out and unsubscribe routes simple and reliable.
  • Confirm that domain registration details and access controls are accurate.
  • Document supplier responsibilities for hosting, support, email, analytics and marketing platforms.
  • Create a process for responding to data access, correction or deletion requests.
  • Set retention periods so personal data is not kept indefinitely without reason.

Preparing without panic

GDPR preparation can feel demanding, especially for smaller businesses without a dedicated compliance team. The best approach is to be practical and systematic. Start with the website, because it is often the main point where prospects first share their information. Then follow the data into email, sales, customer service and marketing systems.

Do not treat GDPR as a one-off wording exercise. A privacy policy is important, but it only works if it reflects real practice. The aim should be to build a clear, manageable and honest process for personal data. When that process is supported by good website design, secure technology and thoughtful marketing, GDPR data protection becomes part of a stronger digital strategy.

For UK business owners planning a new website or improving an existing one in 2018, now is the right time to review data collection, consent, content and supplier arrangements. A well-prepared website can help reduce risk, strengthen trust and create a better experience for the people your business wants to reach.

Privacy & Compliance