Your website may collect more personal information than you realise. From contact forms and cookies to analytics and third-party tools, there are seven key areas every business should review to reduce privacy risk and build trust with your customers.
1. Check your privacy notice
Your privacy notice should be easy to find, up to date and written in clear language. It should explain what information you collect, why you collect it, the lawful basis you rely on, who you share information with, how long you keep it and how people can exercise their rights. A notice copied from another website is unlikely to accurately describe how your own business operates.
2. Review your cookies and tracking technologies
Check which cookies, analytics tools, advertising technologies and other trackers operate when someone visits your website. Non-essential cookies should not normally be placed before the visitor has given the appropriate consent. Your cookie information should also accurately describe the technologies in use.
3. Look at your cookie banner
A banner should give visitors a genuine choice. Accepting non-essential cookies should not be easier than refusing them, and consent should be freely given, specific and informed. The banner also needs to work technically: declining cookies should actually prevent the relevant technologies from loading.
4. Review your online forms
Contact, enquiry, booking and newsletter forms often collect personal information. Only ask for information you genuinely need, explain what will happen to it and avoid automatically adding people to marketing lists without an appropriate basis.
5. Check third-party services
Booking platforms, payment providers, chat tools, analytics services and embedded content can all involve personal data. Understand which providers receive information through your website and whether your privacy information reflects those arrangements.
6. Check website security
Your website should use appropriate security measures, including HTTPS and sensible access controls for administrative accounts. Security should reflect the nature of the information you collect and the risks involved.
7. Keep the website under review
Compliance is not a one-off exercise. Websites change, new plugins are installed and marketing tools are introduced. Review your privacy arrangements whenever there is a significant change and periodically even when there is not.
In summary
A compliant website is not simply about having a privacy policy in the footer. The notices, cookies, forms, technology and actual data flows all need to work together.
Website Privacy Review
Practical support from S.R Legal Services tailored to your organisation.




