A website privacy review begins with what the website actually does: the information collected, the technologies loaded and the organisations involved. A copied notice or a consent banner's default categories cannot establish that the arrangement fits the business.
This guide helps organise the technical and operational review. The responsible privacy reviewer should assess the particular processing against current UK requirements and ICO guidance. Guidance is changing following the Data (Use and Access) Act, so keep the review date and decisions recorded.
Map actual collection and sharing
Inventory enquiry forms, uploads, accounts, analytics, embedded content and connected systems. Record purposes, recipients, access and where information is stored. Include automatic transfers to email, CRM and other services rather than reviewing only the visible form.
Check the public website in different states, including before a consent choice, after refusal and after withdrawal. A first-party label, privacy-mode name or empty cookie list does not settle the assessment. Storage and access considerations extend beyond cookies.
Assess purposes and exceptions carefully
PECR exceptions have specific purposes and conditions. The statistical purposes exception is narrow and does not make every analytics setup consent-free. It concerns aggregate statistical information for improving the service, not individual tracking or advertising.
Where that exception applies, provide clear information and a simple, free way to object. Any provider must support the permitted purpose. Review actual collection, aggregation, retention and sharing with the responsible person before deciding that the configuration qualifies.
Separate an exception under PECR from the wider requirements where personal data is processed. A supplier's marketing description is insufficient evidence for the decision. Keep the implementation and the written assessment aligned.
Make consent choices usable
For technologies requiring consent, provide equally prominent acceptance and refusal options. Require a positive choice and offer suitable control over purposes. Do not infer agreement from silence or continued browsing.
Make withdrawal as easy as giving consent. Explain how people revisit their choices and check that the controls affect the actual technologies. Test keyboard use, mobile layout and the behaviour of embedded content as well as the banner's appearance.
Provide privacy information where it is needed
People need suitable privacy information when their personal data is collected. Cover the organisation, purposes, lawful basis, retention, recipients, relevant transfers, available rights and complaint route as applicable to the processing.
Layered explanations can help: a short, useful statement beside an upload field can lead to the full notice. The short explanation does not replace the wider information required. Review the notice when the purpose or recipients change.
Define justified retention
The UK GDPR does not prescribe a universal retention period for every data type. Establish periods justified by the specified purpose and relevant obligations. Distinguish enquiry records, active customer information, operational logs and other categories.
Assign owners and review dates. Apply the agreed policy across live systems, exports and other copies. Periodically review information and erase or anonymise it appropriately when it is no longer needed. Retaining everything indefinitely makes the policy ineffective.
Handle requests and supplier copies
The right to erasure is not absolute. Record requests and have the responsible person determine the appropriate response for the circumstances. A technical deletion checklist supports that decision rather than determining the legal outcome.
Include connected recipients and backup handling in the operational plan. Review processor contracts, return or deletion arrangements, expected timescales and available evidence. Do not treat a successful interface message as proof that every supplier copy has gone.
Check accuracy and authorised access
Keep sources and record status clear, and distinguish opinions from established facts. Review challenges to accuracy. An AI-generated CRM note needs appropriate checking before it is treated as reliable information.
Choose technical and organisational protections that suit the risks. Review who can access information and test whether controls work. Assign a route for staff to report errors and incidents without sending unnecessary personal details through unrelated systems.
Review checklist
- Inventory collection, sharing and technologies.
- Record purpose assessments and current decisions.
- Test refusal, withdrawal and applicable objections.
- Keep notices accurate and accessible.
- Apply justified retention and request handling.
- Review supplier copies, accuracy and authorised access.
Our email consent guide covers marketing preferences. The account access guide helps organise permissions and recovery.


