12 Jan 2018

Preparing Websites and Marketing Lists for GDPR

With GDPR due to apply from 25 May 2018, UK businesses should act now to audit website data, refine enquiry forms, update privacy and cookie notices, strengthen security and review marketing lists before the deadline.

Preparing Websites and Marketing Lists for GDPR

The General Data Protection Regulation has been agreed and will apply from 25 May 2018. For many UK businesses, that deadline is now close enough to require immediate attention. Website projects, database audits and marketing processes all take time to plan properly. If you are redesigning a website, reviewing your SEO strategy or building your email list in early 2018, GDPR should be considered from the start rather than treated as a last-minute legal exercise.

A well-prepared GDPR website is not simply about avoiding penalties. It is about building confidence with visitors, showing that your organisation is careful with personal information and making your online marketing more valuable. Clean data, clearer forms and more transparent communication can improve the quality of enquiries, reduce wasted effort and support a stronger brand reputation.

Why GDPR matters for business websites

Most business websites collect personal data in one form or another. A contact form, newsletter sign-up, live enquiry form, account registration, quote request, analytics cookie or downloadable guide can all involve information about an identifiable person. GDPR raises expectations around how that information is collected, stored, used and explained.

For website owners, the practical question is straightforward: can a visitor understand what data you are collecting, why you need it and what will happen next? If the answer is unclear, your website is likely to need attention before May 2018.

GDPR places emphasis on fairness, transparency, accountability and appropriate security. These are legal principles, but they also align with good website design. A clear form, a helpful privacy notice and a secure enquiry process make it easier for a prospective customer to trust you. Conversely, vague tick boxes and unexplained mailing list sign-ups can make a brand appear careless.

Start with a website data audit

Before changing forms or rewriting policies, list every place where your website collects or stores personal information. This is often broader than expected, particularly on older websites that have accumulated plugins, tracking scripts and forgotten forms over several years.

Useful areas to review include:

  • Contact forms and quote request forms.
  • Newsletter, event and brochure download sign-ups.
  • Customer account areas and login systems.
  • Comments, reviews and user-submitted content.
  • Payment, booking or enquiry systems that pass data to another provider.
  • Analytics, advertising and remarketing tags.
  • Cookie notices and cookie-setting behaviour.
  • Back-end form notification emails sent to staff.
  • Stored entries inside a content management system.
  • Databases connected to customer relationship management or email marketing systems.

For each item, record what data is collected, why it is needed, where it is stored, who can access it and how long it is kept. This does not need to be overly complicated, but it should be clear enough for a business owner or manager to understand. The exercise often reveals data that is no longer required, forms asking for unnecessary information or enquiries being copied to too many people.

Design forms with clarity and restraint

One of the most visible parts of a GDPR website is the web form. Forms should ask for the information needed to respond to the user, not every detail that might be useful one day. If somebody is requesting a call back, for example, a name, telephone number and short message may be enough. Asking for a postal address, date of birth or company turnover without a clear reason can create unnecessary risk and reduce conversions.

Review each form field and ask whether it is essential. If it is not essential, either remove it or make it optional. A shorter, clearer form is usually better for both compliance and user experience.

Where you use tick boxes, keep them specific. A contact form should not quietly add someone to a newsletter unless that is made clear and handled appropriately. A person asking for a quotation is not necessarily agreeing to receive regular marketing emails. Separate the action they are taking from any additional marketing permission you want to request.

Example wording for a newsletter sign-up might be:

Tick this box if you would like to receive occasional email updates from us about our services, news and useful guidance. You can unsubscribe at any time.

The exact wording should suit your organisation and should be checked against your wider privacy approach, but the principle is important: make the choice understandable at the point of collection.

Your privacy notice should be easy to find, written in plain English and connected to the areas of the site where data is collected. Many older websites hide a dense legal page in the footer and never refer to it on forms. GDPR encourages clearer, more accessible information.

A useful privacy notice should explain the types of data you collect, the purposes for which you use it, whether it is shared with service providers, how long it may be retained and how people can contact you about their information. It should also cover marketing communications and any relevant use of cookies or tracking technologies.

Cookies are already covered by UK rules under the Privacy and Electronic Communications Regulations. GDPR does not remove the need to think carefully about cookie transparency. If your site uses analytics, advertising tags or remarketing, your cookie information should not be an afterthought. Explain the categories of cookies you use in language a normal customer can understand.

From a design perspective, cookie messages should be visible without being disruptive. Avoid covering the whole screen with a confusing message. A simple notice that links to fuller information is usually more user-friendly, provided it gives people meaningful information and does not mislead them.

Make security part of the website brief

Security is a central part of responsible data handling. For a business website, this begins with the basics: secure hosting, careful administration, maintained software and controlled access. If you are planning a new website in 2018, security should be included in the specification rather than added afterwards.

HTTPS is increasingly important for any site that collects information. Search engines have encouraged secure connections for some time, and browsers are becoming more visible in warning users when pages request sensitive details over ordinary HTTP. If your site has contact forms, logins, payments or account areas, moving to HTTPS should be treated as a priority.

Content management systems also need regular attention. Keep themes, plugins and core software updated. Remove unused plugins and old user accounts. Use strong passwords and restrict administrative access to people who genuinely need it. If form submissions are stored in the website database, make sure you know how long they are kept and who can see them.

It is also worth reviewing how form enquiries are emailed internally. Many websites send full enquiry details to several addresses, including shared mailboxes or old staff accounts. A cleaner approach is often to send only what is needed to the right person and avoid unnecessary copies.

Clean up marketing lists before you rely on them

Marketing lists are one of the areas most likely to cause concern under GDPR. Many businesses have email databases built from years of enquiries, exhibitions, networking, website downloads and previous customers. Some records may be well documented, while others may have little evidence showing how the person joined the list or what they expected to receive.

Early 2018 is a sensible time to review these lists if you have not already done so. Do not leave the work until the final weeks before GDPR applies. Start by separating customers, prospects, suppliers and general newsletter subscribers. Then look at the source of each record, the date it was added and the type of communication the person receives.

Questions to ask include:

  • Do we know how this person joined the list?
  • Were they told they would receive marketing emails?
  • Is the content we send relevant to the reason they gave their details?
  • Can they easily unsubscribe?
  • Are bounced, inactive or duplicate records being removed?
  • Do we have records of preferences or permissions where needed?

Cleaning a list may reduce its size, but it can improve its value. A smaller list of people who understand why they are hearing from you is more useful than a large database of uncertain origin. Better data also improves reporting, email engagement and the quality of sales follow-up.

Connect GDPR preparation with SEO and conversion

GDPR preparation should not sit apart from search marketing and website performance. The same improvements that make a site more transparent can also help users take action with greater confidence. Clear calls to action, concise forms, secure pages and helpful copy can all support conversions.

From an SEO perspective, trust and usability matter. A website that loads well, works on mobile devices, provides useful information and makes contact easy is better positioned to earn enquiries from organic search. While a privacy notice alone will not improve rankings, a trustworthy website experience supports the wider signals that influence user behaviour.

Landing pages should be reviewed in the same way as the rest of the site. If you run paid search campaigns, social advertising or downloadable guide campaigns, check that each landing page explains what the user will receive and what will happen to their details. Avoid burying important information in small print or making people agree to unrelated marketing simply to access a resource.

Review social media marketing and advertising data

Social media marketing often involves personal data, even when the data is handled through a platform. If you upload customer or prospect lists for advertising, build custom audiences or use tracking pixels on your website, you should understand what data is being used and whether your privacy information explains it clearly.

Social campaigns should also respect the difference between engagement and permission. A person liking a post, following a page or entering a competition is not automatically agreeing to receive unrelated email marketing. If you want to collect email addresses through a social media campaign, the sign-up process should be clear about the purpose.

Competition and lead generation forms deserve particular care. Tell people who is collecting the information, what they are entering or requesting and whether they will receive further communication. If another organisation is involved, explain that relationship plainly. Good social media marketing is built on audience trust, and GDPR preparation is an opportunity to strengthen that trust.

Do not overlook domains and ownership records

Domain registration is often forgotten during website planning, but it can raise practical data and business continuity issues. Check who legally controls your domain name, which email address is used for renewals and whether the registration details are accurate. A domain registered to an old employee, former supplier or personal email account can create avoidable risk.

For UK businesses, the domain name is a core digital asset. It should be registered using appropriate business details and managed through an account that the organisation controls. Keep renewal reminders going to monitored addresses and record who has authority to make changes. If your domain portfolio includes variations, campaign domains or older domains that redirect to your main site, include them in your audit.

Where personal information appears in registration records or administrative contacts, consider whether the details remain appropriate. The aim is not to hide legitimate business ownership, but to make sure that records are accurate, necessary and under proper control.

Build GDPR into new website projects

If you are commissioning a new website or redesign in 2018, include GDPR preparation in the brief. This will save time later and reduce the chance of expensive reworking. Designers, developers, copywriters and marketing teams should all understand how data collection affects their part of the project.

A strong brief might cover:

  • Which forms are required and what each field is for.
  • How consent or marketing preferences will be requested where appropriate.
  • Where privacy and cookie information will be displayed.
  • Whether HTTPS will be used across the whole site.
  • How submissions will be stored, emailed and deleted.
  • Which analytics, advertising and social tracking scripts will be installed.
  • Who will maintain software updates and security after launch.
  • How email marketing sign-ups will connect to your chosen mailing system.

This approach encourages privacy by design, which is one of the ideas running through GDPR. It also leads to a better user experience because the website is planned around clear journeys rather than patched together with conflicting forms and messages.

Practical next steps for UK business owners

GDPR can feel complex, but the first steps are manageable. Begin with your website and marketing lists because they are visible, active and directly connected to lead generation. Map the data you collect, remove what you do not need, improve your explanations and strengthen your security.

It is also sensible to involve the right people early. Website managers, marketing staff, directors, IT support and legal advisers may all have a role. A web designer can improve the forms and user journey, but the business itself must decide why it collects information and how it intends to use it.

For many organisations, the biggest benefit will be focus. GDPR preparation encourages better quality data, clearer communication and more respectful marketing. That is good for compliance, but it is also good for customers. A GDPR-ready website should help people understand your business, contact you with confidence and remain in control of how they hear from you.

With only months before the new rules apply, now is the right time to review your website, email lists, social media campaigns and domain arrangements. Treat GDPR as part of your digital strategy for 2018, and your business will be in a stronger position when the regulation takes effect.

Privacy & Compliance