17 Apr 2018

Why Consent and Privacy Notices Matter Online

Clear privacy notices and consent choices help UK businesses prepare for GDPR, explain data use across websites and marketing, and build customer confidence online.

Why Consent and Privacy Notices Matter Online

Privacy notices are no longer a small legal footnote at the bottom of a website. For UK businesses, they are an important part of how customers understand, trust and choose to engage with an organisation online. Whether you are collecting enquiries through a contact form, building an email marketing list, using website analytics, running a social media campaign or registering a domain name, people need to know what happens to their personal information and why.

With the General Data Protection Regulation due to apply from 25 May 2018, many organisations are reviewing how they ask for consent and how they explain their use of personal data. This is not simply a compliance exercise. Clear privacy information can improve confidence, reduce friction, support better marketing practice and help protect the long-term reputation of your brand.

What is a privacy notice

A privacy notice is the information you give people about how your business collects, uses, stores and shares their personal data. It should be easy to find, easy to read and specific enough to be useful. In practice, it often appears as a privacy policy page on a website, supported by shorter notices beside forms, sign-up boxes and other points where data is collected.

Personal data is broader than many business owners realise. It can include a name, email address, telephone number, postal address, account login, IP address, social media handle, enquiry message, order history or information gathered through cookies and similar technologies. If that data can identify a living person, directly or indirectly, it should be treated with care.

A good privacy notice should explain who you are, what information you collect, why you collect it, how you use it, who you may share it with, how long you keep it and what rights people have. It should also explain how someone can contact you about their data and, where appropriate, how they can complain to the Information Commissioner’s Office.

The best privacy notices are written for real people, not just lawyers. If a visitor needs to read a sentence three times to understand it, the wording is probably too complex. Plain English, short paragraphs and clear headings make privacy information more useful and more credible.

Consent is one of the most discussed areas of data protection, particularly for email marketing, newsletters, downloads, competitions and lead generation campaigns. In February 2018, businesses should already be preparing for a higher standard of consent under the GDPR. Consent needs to be freely given, specific, informed and unambiguous. It should involve a clear positive action, such as ticking an unticked box or selecting an option.

This means pre-ticked boxes, vague statements and bundled permissions should be avoided. For example, a contact form should not automatically add someone to a marketing list simply because they asked for a quote. If you want to send marketing emails, ask for that separately and clearly explain what the person is signing up to receive.

A simple example might be a newsletter sign-up box that says: “Yes, I would like to receive occasional email updates about digital marketing, website design and related services.” This is clearer than a broad statement such as “Submit your details to hear from us.” The first version helps the user understand the nature of the communication, while the second leaves too much room for confusion.

It is also sensible to keep a record of consent. Your systems should be able to show when someone signed up, what wording they saw at the time and how they gave permission. This is useful if a subscriber later queries why they are receiving emails. It also encourages your team to maintain a clean, engaged database rather than relying on outdated or uncertain contacts.

Consent must also be easy to withdraw. Marketing emails should include a clear unsubscribe option. If someone contacts you directly to opt out, that request should be acted upon promptly. From a business perspective, this is not a loss. A smaller list of genuinely interested subscribers is usually more valuable than a large list of people who never wanted to hear from you.

Privacy notices as part of good website design

Privacy should be considered during website planning, not added as an afterthought just before launch. Every form, tracking script, booking feature, payment process and downloadable guide can involve personal data. A well-designed site makes the privacy journey clear without overwhelming visitors.

Your main privacy notice should be linked from the website footer and any other relevant areas, such as account registration pages, enquiry forms and checkout steps. Short, contextual wording beside a form can also be helpful. For instance, beneath a brochure download form, you might write: “We will use your details to send the requested guide and, if you opt in, occasional marketing emails. Read our privacy notice for more information.”

This approach is often called layered information. The user sees a short, relevant explanation at the point of data collection, with the option to read the full privacy notice if they want more detail. It works well on mobile devices, where long blocks of text can make forms difficult to use.

Design also affects trust. A privacy notice hidden in tiny text, written in dense legal language or placed only at the very bottom of a long page can make visitors suspicious. By contrast, clear wording, consistent branding and thoughtful placement can reassure users that your organisation takes data protection seriously.

Businesses should also consider accessibility. Privacy information should be readable on different screen sizes, work properly with assistive technologies and avoid unnecessary jargon. If your audience includes consumers rather than only business contacts, the wording should be especially straightforward.

Website technology, cookies and tracking

Most modern business websites use some form of analytics to understand visitor behaviour. Many also use tracking pixels, remarketing tags, embedded maps, video players, live chat, booking tools or third-party form services. These technologies may collect personal data or place cookies on a user’s device.

Under the Privacy and Electronic Communications Regulations, website owners should provide clear information about cookies and, where required, obtain consent. A basic cookie banner that simply says “we use cookies” may not be enough if visitors cannot understand what types of cookies are being used and why. Your cookie information should explain, in practical terms, whether cookies are used for analytics, essential website functions, advertising, social media sharing or other purposes.

If your site uses remarketing, this should be made clear. A visitor who browses a service page and later sees related advertising elsewhere should not be surprised to learn that tracking technology was involved. Transparent cookie and privacy information helps set expectations and reduces the risk of complaints.

Security is another important part of the privacy conversation. If your website collects personal data through forms, logins or payment pages, it should use HTTPS. By 2018, visitors are increasingly familiar with browser security indicators, and search engines have been encouraging secure websites for some time. A secure connection does not solve every data protection issue, but it is a basic sign of responsible website management.

Behind the scenes, businesses should review where form submissions go. Are enquiries sent to a shared inbox? Are they stored in the website database? Are they passed into a customer relationship management system? Who can access them? How long are they kept? These are practical operational questions as much as legal ones.

Social media campaigns and data collection

Social media marketing can create additional privacy considerations. A business might run a competition, collect leads through an advert, invite users to download a guide or encourage customers to send direct messages. Each of these activities can involve personal information.

If you collect entries for a competition, explain what the data will be used for. If the entry form also includes an option to receive marketing emails, make that choice separate from the competition entry. People should not have to agree to unrelated marketing in order to take part unless that is genuinely necessary and clearly explained.

Lead generation adverts on social platforms can be convenient because the user’s details are often filled in automatically. However, convenience should not replace transparency. The short privacy wording on the advert should match your full privacy notice, and your internal team should understand how quickly those leads are contacted, where they are stored and whether they are added to a mailing list.

Some businesses also upload customer email addresses to social platforms to create advertising audiences. If you intend to use customer data in this way, your privacy notice should say so clearly. Customers may not expect their email address to be used for targeted advertising unless you have explained that possibility.

Domain registration and personal information

Domain names are another area where privacy can be overlooked. When a domain is registered, certain registrant details may be held in public or semi-public records, depending on the domain type, registrant category and registry rules. For sole traders, partnerships and small businesses, this can raise practical questions about personal addresses, telephone numbers and email addresses.

Before registering a domain, consider what contact details will be associated with it. Using a personal home address or an individual employee’s email address may create problems later. If the employee leaves, renewal notices and important administrative messages could be missed. If a home address is displayed publicly, it may create unnecessary privacy concerns.

Where appropriate, use official business contact details and keep them up to date. Some domain types and registration arrangements may allow privacy or proxy options, though availability varies. The key point is to understand what information is being provided, who controls the domain account and how renewal and transfer communications will be handled.

Domain ownership is also a brand protection issue. The organisation should know who has administrative access, where the domain is registered, when it renews and which email address receives important notices. A privacy-aware approach to domain registration can prevent avoidable disruption as well as protect personal information.

How privacy notices support SEO and digital strategy

Privacy notices do not work like a direct search ranking trick, and they should not be written for search engines at the expense of users. However, they do form part of a trustworthy, professional website. Search marketing is increasingly connected to user experience, brand credibility and the quality of the overall site.

If a visitor lands on your website from an organic search result and is asked to complete a form, they may look for signs that your business is legitimate. A clear privacy notice, secure connection, professional design and sensible form wording can all support that confidence. This can improve enquiry quality and reduce hesitation, particularly for services that require a considered purchase.

Privacy information can also help align your marketing channels. Your website, email sign-up forms, social media campaigns and downloadable resources should all use consistent language. If your advert promises helpful updates, your sign-up page should explain what those updates are. If your privacy notice says you send occasional marketing emails, your email programme should reflect that promise.

Good digital strategy is not only about attracting traffic. It is about attracting the right people, earning trust and building relationships that last. Clear privacy notices help create that foundation.

Practical steps for UK businesses

If your business has not reviewed its privacy information recently, now is a sensible time to do so. Start by mapping the places where you collect personal data. This might include website forms, email subscriptions, event registrations, customer accounts, online payments, social media campaigns, telephone enquiries, live chat and offline sign-up sheets that are later added to a database.

Next, identify why you collect each type of data and what you do with it. Avoid collecting information just because it might be useful one day. If a newsletter sign-up only needs an email address, think carefully before asking for a telephone number. Shorter forms are often better for conversion and better for privacy.

  • Review every website form and make sure the privacy wording is clear.
  • Use unticked opt-in boxes where consent is required for marketing.
  • Keep records of when and how consent was obtained.
  • Make unsubscribe and opt-out options easy to find and use.
  • Check which third-party tools process personal data on your behalf.
  • Update cookie information so visitors understand tracking and analytics.
  • Use HTTPS on pages that collect or display personal information.
  • Keep domain registration details accurate and under proper business control.
  • Train staff so that privacy promises made online are followed internally.

It is also worth reviewing suppliers. Web developers, email marketing providers, hosting companies, analytics tools, booking systems and customer management platforms may all handle data connected to your business. You should know what each supplier does, where data is stored where relevant, and what contractual arrangements are in place.

A clearer approach builds confidence

Consent and privacy notices matter because they shape the relationship between your business and the people who interact with it. They tell visitors whether you are careful, transparent and respectful. They also help your own team make better decisions about data, marketing and technology.

For UK business owners, the most useful approach is practical rather than fearful. Review what you collect, explain it clearly, ask for consent properly where needed and make sure your website design supports transparency. When privacy is built into your digital presence, it becomes part of a stronger brand experience.

A well-written privacy notice will not make a poor website successful on its own. But combined with good design, secure technology, relevant content and thoughtful marketing, it can remove uncertainty and encourage the right people to take the next step with confidence.

Privacy & Compliance