Most UK small businesses do the same three things when they launch a website: Make it look good, write some content, try to get found on Google.
What usually gets left until “later” are the legal bits that quietly sit in the background – until there’s a complaint, a chargeback, or an email from a regulator.
This guide gives you a plain-English overview of the main rules that are likely to apply to a typical UK business website. It’s not a legal textbook and it won’t cover every niche situation, but it will help you:
- Spot obvious gaps
- Avoid common mistakes
- Work out when you should speak to a solicitor
Important: This article is for general information only and isn’t legal advice. If you’re unsure about your specific situation, always get advice from a qualified legal professional.
- Why Website Legal Regulations Matter
- Core UK Legal Requirements For Most Business Websites
- Selling Online: Key E‑Commerce And Consumer Law Points
- Data Security, Payments And Practical Standards
- Extra Rules That May Apply
- New Tools, AI And Third-Party Plugins
- What To Do Next
- Check Your Website Compliance & Accessibility
Why Website Legal Regulations Matter
1. Avoiding Fines, Hassle And Headaches
If your website doesn’t follow the rules, you’re not just breaking some abstract regulation. You could face:
- Fines or enforcement action from the ICO (Information Commissioner’s Office)
- Customer complaints, refund demands and chargebacks
- Orders to change or remove parts of your site at short notice
For a small business, even a single serious complaint can eat time, dent your reputation and make you nervous about marketing.
2. Showing You’re A Real, Trustworthy Business
The flip side: when you get the basics right, you quietly build trust.
If a visitor can quickly see:
- Who you are
- How to contact you
- A sensible Privacy Policy
- Clear terms, returns and refund information
They’re far more likely to feel comfortable filling in a form, booking a call or paying online. That’s especially important for:
- Local service businesses
- Coaches and consultants
- Manufacturers and B2B suppliers who rely on repeat work
3. Realising Not Every Rule Applies To Every Site
Part of the confusion is that different rules apply to different websites.
Almost every site will need:
- Basic company and contact details
- A Privacy Policy (if you collect personal data – and most sites do)
- A cookie notice (if you use non-essential cookies)
Extra rules kick in if you:
- Sell online to consumers (e‑commerce and consumer law)
- Send marketing emails or SMS (PECR and GDPR)
- Handle card payments on your own site (PCI DSS, the industry standard)
You don’t need to memorise every regulation. You just need to know which areas apply to your site and deal with those properly.
Core UK Legal Requirements For Most Business Websites
Company And Contact Details
Most UK business websites must clearly show who’s behind the site. This comes mainly from e‑commerce regulations and the Companies Act.
You should clearly display:
- Your business name and trading name (if different)
- Registered office address (for companies and LLPs)
- Company registration number and where you’re registered
- A contact email address and an easy way to reach you (phone number or contact form)
- Your VAT number, if you have one
Practical tip: Put this in your footer and on your Contact or About page. Make sure it matches Companies House, your invoices and any other public information.
Privacy Policy And UK GDPR
If your website collects any personal data, UK data protection law applies. That includes things like:
- Names and email addresses from contact forms
- Newsletter sign-ups
- Customer login details
- Analytics data that can identify or track individuals
The main laws here are:
- UK GDPR (General Data Protection Regulation)
- Data Protection Act 2018
In practice, you’ll usually need:
- A clear, honest Privacy Policy in plain English
- An explanation of:
- What data you collect
- Why you collect it
- How long you keep it
- Who you share it with (e.g. email marketing platforms, analytics providers)
- Your lawful basis for processing personal data, such as:
- Consent – they choose to sign up
- Contract – you need the data to provide a service
- Legitimate interests – a reasonable business reason, balanced against people’s privacy rights
- Information about people’s rights (access, correction, deletion, etc.) and how to contact you
Practical tip: Don’t copy a random Privacy Policy from another site. It almost never matches what you actually do and can create more risk, not less. At F2B Digital we partner with Termageddon, a policy generation service that creates and maintains tailored Privacy Policies for UK small businesses and keeps them updated as laws change.
Cookie Notices And Tracking Tools
Most modern websites use cookies or similar tracking technologies, such as:
- Analytics tools (e.g. Google Analytics)
- Remarketing and advertising pixels
- Social media tracking (e.g. Facebook Pixel)
- Some chat widgets and embedded content
In the UK, this is mainly covered by:
- PECR (Privacy and Electronic Communications Regulations)
- UK GDPR, for how you manage consent and personal data
For non-essential cookies (especially marketing and many analytics cookies), you’ll usually need to:
- Show a cookie banner that explains what you use and why
- Let visitors choose whether to accept or reject non-essential cookies
- Avoid placing non-essential cookies before they’ve given consent
- Have a Cookie Policy page listing cookie types, purposes and durations
Practical tip: A simple “this site uses cookies” banner isn’t enough. Use a proper consent management tool. Termageddon can also help here by managing cookie consent and keeping your notices aligned with current requirements.
If you’d rather avoid complex consent tools altogether, privacy-friendly analytics such as Fathom Analytics can help. Fathom is designed to collect less personal data and be simpler and more privacy-focused than traditional analytics platforms.
Selling Online: Key E‑Commerce And Consumer Law Points
If you sell goods, digital products or services online, extra rules apply – especially when you sell to consumers (B2C).
Information You Must Show Before A Customer Buys
The main laws here are:
- Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013
- Consumer Rights Act 2015
Before a customer places an order, you must clearly show:
- The total price, including taxes and any extra fees
- Delivery costs and estimated timescales
- A clear description of what’s included (and what isn’t)
- Who they are contracting with (your legal business name)
- Payment terms, subscription details and any ongoing charges/renewals
If you hide fees or bury important details, you’re much more likely to face disputes, refunds and complaints.
Cancellation Rights, Returns And Refunds
For most online consumer purchases, customers get a 14‑day cooling-off period. There are exceptions, including:
- Bespoke or personalised items
- Some digital content once it’s been downloaded or accessed
- Urgent services that customers explicitly ask you to start straight away
You should:
- Explain when customers can cancel and how to do it
- Have a clear, fair Returns/Refunds or Cancellation Policy page
- Make sure your policy matches what the law allows – not stricter, not vague
Practical tip: Use simple language and real examples. Spell out when someone can change their mind and when they can’t, using everyday scenarios.
Fair Terms And Clear Disclaimers
Your website terms and any contracts must be fair and easy to understand.
Typically, you’ll want:
- Website Terms of Use covering acceptable use, intellectual property (IP) and limits on your liability (within the law)
- No hidden charges or nasty surprises buried in dense paragraphs
- Clear disclaimers where content is general information, not tailored advice – especially for:
- Health
- Finance
- Legal
- Business advice
For example, a coach or consultant might explain that their blog content is for general information only and doesn’t replace one-to-one advice.
Data Security, Payments And Practical Standards
Keeping Customer Data Secure
Under UK GDPR, you must take “appropriate technical and organisational measures” to keep personal data safe. That sounds heavy, but for most small sites it means doing the basics well:
- Use HTTPS across your whole site (an SSL certificate)
- Use strong passwords and, ideally, two-factor authentication for logins
- Keep your CMS, plugins and themes up to date
- Limit who has access to customer data and use role-based access where possible
- Back up your site regularly and check you can restore it
Plenty of security issues can be avoided with simple housekeeping and not sharing logins too widely.
PCI DSS And Online Payments
PCI DSS (Payment Card Industry Data Security Standard) is an industry standard from card providers like Visa and Mastercard. It isn’t UK law, but most banks and payment providers expect you to comply if you handle card data.
Most small businesses reduce their risk by:
- Using trusted third-party payment processors such as Stripe, PayPal or Shopify Payments
- Avoiding storing card details on their own servers
- Completing any PCI DSS self-assessment forms their payment provider asks for
If you’re considering a custom checkout that directly handles card numbers, talk to a specialist first. The security and compliance burden jumps significantly.
Extra Rules That May Apply
Email Marketing And Electronic Communications
If you send marketing emails, SMS or similar messages, both PECR and UK GDPR apply.
For most small businesses, this means:
- You usually need consent to send marketing to individuals, unless the narrow “soft opt-in” for existing customers applies
- Every marketing email must have an easy unsubscribe link
- You should clearly identify your business in the message
Practical tip: Use double opt-in for newsletters (they confirm their email before being added). Keep a record of when and how each person subscribed.
Accessibility And Equality Law
The Equality Act 2010 says businesses must not discriminate against disabled people when providing services. It doesn’t name websites specifically, but your site is part of how you deliver your services.
Reasonable steps to improve accessibility include:
- Good colour contrast and readable font sizes
- Alt text for important images
- Forms and buttons that work with a keyboard and screen readers
Accessible websites are easier for everyone – older visitors, busy people on mobiles, and users with poor connections all benefit.
Sector-Specific And Higher-Risk Areas
Some sectors have additional rules, for example:
- Financial services: FCA rules on promotions, risk warnings and clear wording
- Health and medical: Strict rules on claims, evidence and patient information
- Websites aimed at children: Extra care with privacy, consent and advertising
If you’re in a regulated industry, check your regulator’s guidance before launching new pages or campaigns.
New Tools, AI And Third-Party Plugins
Many small businesses now add:
- Chatbots
- AI tools
- Pop-ups and marketing plugins
Each new tool can collect or share user data, which can change your legal responsibilities.
Before adding something new, ask:
- What personal data does it collect or track?
- Where is that data stored (UK, EU or elsewhere)?
- Do my Privacy and Cookie Policies need updating?
- Do I need to change my cookie consent settings?
Tools like Fathom Analytics can help you reduce the amount of personal data you collect in the first place, which often makes compliance simpler overall.
What To Do Next
You don’t need to sort everything in one go. A steady, practical approach works well:
- Review your current website
- Are your company details easy to find?
- Do you have up-to-date Privacy and Cookie Policies?
- Are your terms, returns and disclaimers clear and visible?
- Tidy up the basics
- Add or update key pages and footer information
- Check your forms, analytics and plugins match what your policies say
- Improve basic security and accessibility where you can
- Get help where it makes sense
- Speak to a solicitor for complex or higher-risk issues
- Work with a trusted web partner to handle technical changes
At F2B Digital, we can help with:
- Website audits to spot common compliance gaps and accessibility issues
- New builds and rebuilds that bake in good practice from day one. This includes setting up and integrating tools like Termageddon and Fathom Analytics to simplify your policies and tracking
Check Your Website Compliance & Accessibility
Curious about your website’s compliance with key laws? As part of our website audit service, we check compliance. We also check accessibility on our consultation and detailed reviews.
