GDPR Compliant Website Checklist for UK Businesses 2026

UK GDPR: A Non-Negotiable for Business Websites
Since Brexit, UK businesses follow the UK General Data Protection Regulation (UK GDPR). While similar to its EU counterpart, it is the specific legislation you must adhere to. Compliance is not just a legal formality; it is a fundamental part of building trust with your customers. Getting it wrong can lead to significant fines and damage to your reputation.
This checklist provides a practical, no-nonsense guide to the key requirements for your website in 2026. Whether you are a sole trader or a larger enterprise, these principles apply.
1. Your Privacy Policy: The Foundation of Trust
Every website that collects any personal data (even just via a contact form) must have a clear, accessible, and easy-to-understand Privacy Policy.
• What to include: State what data you collect (e.g., name, email, IP address), why you collect it, how you process it, how long you keep it, and if you share it with any third parties (like Google Analytics or a payment processor).
• User Rights: You must inform users of their rights, including the right to access, rectify, or erase their data.
• Accessibility: Link to your Privacy Policy from your website footer and from any forms where you collect data.
2. Cookie Consent: Clarity is Key
You cannot set any non-essential cookies (like those for analytics or advertising) on a user's device without their explicit, prior consent.
• The Cookie Banner: Your banner must not have pre-ticked boxes for non-essential cookies. It must give users a genuine choice to 'Accept' or 'Reject' them. A link to your Cookie Policy for more detail is also essential.
• Granular Control: Best practice is to allow users to choose which categories of cookies they accept (e.g., Analytics, Marketing).
• Consent is Not Forever: You must make it as easy for users to withdraw their consent as it was to give it.
3. Contact Forms and Marketing: Purpose and Consent
When you use a form to collect data, you must be transparent about its purpose.
• Lawful Basis: For a contact form, your lawful basis for processing is typically 'legitimate interest'. For marketing emails, it is 'consent'.
• No Bundled Consent: You cannot bundle consent for different things. If you have a contact form, you need a separate, unticked checkbox for users to opt-in to your marketing newsletter. You cannot make it a condition of submitting the form.
• Secure Data: Ensure your website uses HTTPS (the padlock icon in the browser) to encrypt any data submitted through forms.
How Ashdub Builds Compliance In
Navigating data protection law can be daunting. At ashdub, we simplify this by building compliance into the platform. When our AI generates your website, it automatically creates a draft Privacy Policy and Cookie Policy for you to review and adapt. It also includes a UK GDPR-compliant cookie consent banner as standard.
All forms are served securely over HTTPS, and the integrated CRM provides a clear record of your customer data, helping you to manage user rights requests efficiently. We handle the technical foundations of compliance, so you can focus on running your business with confidence.
Try it with your business
Say what you do and watch your website and back office build themselves. Free to start, no card needed.
Try: “a fish & chip shop in Leeds with online orders”Free to start · no card · live in minutes.


