The General Data Protection Regulation (GDPR) comes into force on 25 May 2018, and for many UK businesses the website will be one of the most visible places where change is needed. Your site may collect enquiries, newsletter sign-ups, analytics data, cookie information, account details, job applications or event registrations. Each of these touchpoints can involve personal data, which means GDPR compliance should not be treated as a last-minute legal exercise. It is also an opportunity to build trust, improve the quality of your marketing data and make your online processes clearer for customers.
This guidance is written for business owners who rely on their website, search visibility, branding and digital marketing to generate enquiries. It is not a substitute for legal advice, but it will help you ask the right questions and prepare a sensible website action plan before the May 2018 deadline.
Why GDPR compliance matters for your website
GDPR is designed to give individuals more control over how organisations collect, store and use their personal data. For businesses, it raises the standard expected around transparency, consent, security and accountability. If your website gathers information from visitors, even through a simple contact form, you need to understand what you collect, why you collect it, how long you keep it and who has access to it.
From a digital marketing perspective, GDPR compliance is about more than avoiding penalties. Clear data practices can strengthen your brand. A visitor who understands why you are asking for their details is more likely to trust you. A cleaner email list made up of people who genuinely want to hear from you is more useful than a large list filled with weak, outdated or poorly sourced contacts. A privacy-conscious website can therefore support better conversion rates, improved customer relationships and more sustainable marketing.
For many organisations, the website is also connected to several other systems: customer relationship management software, email marketing platforms, payment gateways, analytics tools, social media advertising accounts and hosting services. Preparing properly means reviewing the full journey of personal data, not just editing a paragraph in your privacy policy.
Start with a personal data audit
Before making design or copy changes, map the personal data your website collects. This does not have to be complicated, but it should be thorough. Walk through the site as a customer would and record every point where data is captured, stored or passed to a third party.
Common examples include contact forms, quote request forms, newsletter sign-up boxes, downloadable guide forms, account registration areas, checkout pages, blog comment forms, live chat services, event booking forms, recruitment forms and analytics tracking. You should also consider server logs and any cookies that help identify behaviour or preferences.
For each item, ask the following questions:
- What personal data is being collected?
- Why is it being collected?
- What lawful basis will you rely on for processing it?
- Where is it stored?
- Who can access it?
- Is it shared with any suppliers or third-party platforms?
- How long is it kept?
- How can an individual request access, correction or deletion?
This process helps you identify unnecessary data collection. For example, if a brochure download form asks for a telephone number but your team only follows up by email, you may be collecting more information than you need. GDPR encourages data minimisation, so your forms should ask only for information that has a clear purpose.
Review your forms and consent wording
Website forms are one of the most important areas to review. Under GDPR, consent must be freely given, specific, informed and unambiguous. Pre-ticked boxes, vague statements and bundled consent are unlikely to meet the required standard. If you want to send marketing emails to someone who completes an enquiry form, make that choice clear and separate from the act of submitting the enquiry.
A sensible approach is to separate service communication from marketing permission. For example, a contact form may need a visitor’s name, email address and message so you can respond to their enquiry. If you would also like to add that person to a newsletter list, provide a separate, unticked opt-in box with wording that explains what they will receive.
Instead of using wording such as submit this form to receive updates from us and our partners, be specific. Explain whether updates are sent by email, what kind of content is included and whether data is shared. If several types of communication are available, consider separate choices. For instance, a business might allow users to opt in to monthly email news, event invitations or product updates individually.
You should also keep a record of consent. That means being able to show when and how consent was given, and what the person was told at the time. Your website and marketing systems should support this evidence where possible. If your current set-up cannot record consent clearly, plan improvements before the deadline.
Update privacy notices and make them easy to find
Your privacy notice should be written in plain English and be easy to access from relevant points across the site. A link in the footer is useful, but it is also good practice to link to the privacy notice near forms, newsletter sign-ups and account registration pages.
A strong privacy notice should explain who you are, what data you collect, why you collect it, the lawful basis for processing, how long you retain data, who you share it with, how individuals can exercise their rights and how they can complain. UK organisations should also be familiar with guidance from the Information Commissioner’s Office.
Avoid hiding important information behind dense legal language. People should be able to understand the main points without needing specialist knowledge. Good privacy communication can be part of good website design: clear headings, concise paragraphs and well-placed links all help visitors make informed choices.
Check cookies, analytics and tracking
Many business websites use analytics to measure visitor numbers, popular pages, referral sources and conversion paths. This information can be extremely valuable for SEO, content planning and paid marketing. However, you should understand what data your analytics tools collect and whether that data can identify an individual, directly or indirectly.
Review your cookie notice and cookie policy. If your website sets cookies for analytics, advertising, social media features or logged-in sessions, explain this clearly. Visitors should not be left guessing what tracking is in place or why it is used. Cookie rules already exist separately from GDPR, but GDPR raises expectations around transparency and consent where personal data is involved.
If you use remarketing or social media advertising pixels, pay close attention to how those tools operate. They can be powerful for digital marketing because they help you reach previous visitors with relevant messages. They also involve tracking behaviour across websites or platforms, so your privacy information should explain this in a clear and honest way.
From a business point of view, this is a good time to remove tracking scripts that are no longer used. Many websites accumulate old tags over time. Unused scripts can slow the site, create unnecessary data exposure and make compliance harder to document.
Design for transparency and trust
GDPR compliance should not be bolted on awkwardly. It should be considered as part of website design, user experience and content strategy. If a visitor is asked for personal details, the surrounding page should answer a simple question: why should I trust this organisation with my information?
Several practical design improvements can help. Keep forms short and purposeful. Place privacy links close to data collection points. Use readable font sizes and clear labels. Avoid confusing double negatives in consent boxes. Show confirmation messages that explain what happens next. If someone signs up to a newsletter, tell them to expect an email and remind them that they can unsubscribe.
Security also contributes to trust. Websites that collect personal data should use a valid SSL certificate so information is transmitted over HTTPS. Visitors are becoming more aware of browser security indicators, and search engines have already encouraged the move towards secure websites. HTTPS is not a complete GDPR solution, but it is a sensible baseline for any modern business site handling enquiries or customer information.
Clear branding matters too. A professional, consistent website reassures visitors that they are dealing with a legitimate organisation. If your forms look outdated, your privacy notice is hidden or your checkout feels unpolished, users may hesitate. Compliance and conversion are not opposing goals; both benefit from clarity, consistency and confidence.
Email marketing and social media considerations
Many businesses are reviewing email lists ahead of May 2018. If you cannot show how someone joined your list or what they agreed to receive, you may need to refresh permission or remove that contact. This can feel uncomfortable, particularly if the list has taken years to build, but quality is more important than quantity. A smaller, engaged list is usually better for enquiries, brand reputation and deliverability.
For future sign-ups, your website should make subscription choices clear. State what the subscriber will receive and how often, where practical. Include an unsubscribe option in marketing emails and make sure removal requests are handled promptly. If your sales team manually adds contacts to a mailing list after meetings or enquiries, review that process as well.
Social media marketing also requires care. Publicly available information is not a free pass to process personal data without thought. If you run competitions, lead generation adverts or campaign landing pages, explain how entrant or lead data will be used. If information is passed from a social platform to your business, include that flow in your data audit.
When planning campaigns, involve both marketing and whoever is responsible for data protection within your organisation. The goal is not to stop creative activity, but to ensure campaigns are designed responsibly from the outset.
Domain registration and ownership details
Domain names are often overlooked during compliance projects, but they can contain or display personal information. If a domain is registered using an individual’s home address, personal email address or direct telephone number, that data may be visible through public registration records depending on the domain type and registration settings.
Review the contact details associated with your domains. Make sure the registrant information is accurate and that ownership sits with the correct business or individual. Use appropriate business contact details where possible, such as a role-based email address rather than an employee’s personal address. This helps with continuity if staff change and reduces unnecessary exposure of personal information.
It is also wise to check who has access to your domain account, renewal settings and administrative emails. Losing control of a domain can affect email, website availability, search visibility and brand reputation. GDPR preparation is a useful prompt to tidy up these records and strengthen your wider digital governance.
Work with suppliers and document responsibilities
Your website may involve several suppliers, including designers, developers, hosting providers, email marketing platforms, payment processors, analytics tools and external marketing consultants. Under GDPR, it is important to understand which organisations process personal data on your behalf and what responsibilities they have.
Ask suppliers what data they can access, where it is stored, how it is protected and how they deal with deletion or access requests. You may need appropriate contractual terms in place with processors. If a developer can access form submissions, customer accounts or databases, that access should be controlled and justified.
Documentation is a key theme of GDPR. Keep records of decisions, audits, supplier reviews and changes made to your website. If you update a form, privacy notice or consent mechanism, note when it was changed and why. This creates an audit trail and helps your team stay consistent.
Create a practical website action plan
Preparing for GDPR compliance can feel broad, so it helps to break the work into manageable steps. Start with the areas that create the greatest risk or affect the largest number of people, then work through the rest systematically.
- Audit every place your website collects or tracks personal data.
- Remove unnecessary fields from forms and improve consent wording.
- Update your privacy notice in clear, accessible language.
- Review cookies, analytics, remarketing tags and social media tracking.
- Check HTTPS, form security and admin access controls.
- Review email marketing permissions and unsubscribe processes.
- Check domain registration details and ownership records.
- Confirm supplier responsibilities and document key decisions.
- Train staff who handle enquiries, marketing lists or website data.
- Schedule regular reviews after the May 2018 deadline.
Do not wait until the deadline is close. Website changes can take longer than expected, particularly if your site uses older software, custom forms or multiple connected marketing systems. Early preparation gives you time to make thoughtful decisions rather than rushed edits.
A better website for customers and for your business
GDPR compliance should be viewed as part of building a better digital presence. A website that explains itself clearly, protects visitor data, uses purposeful forms and respects marketing preferences is more likely to earn trust. It can also help your team work more efficiently by reducing poor-quality enquiries, outdated mailing lists and confusion around data handling.
For UK businesses investing in website design, SEO, branding or digital strategy, data protection now needs to be part of the planning conversation. It affects how landing pages are built, how campaigns are measured, how leads are followed up and how customer relationships are maintained.
The businesses that prepare properly will be in a stronger position when GDPR comes into force. More importantly, they will be showing customers that their information is treated with care. That is not just a compliance requirement; it is good business practice.


