Buzz Legal
Non-reserved business legal services
Home / Guides / Website terms and privacy, done properly
Guide

Website terms and privacy, done properly

Somebody has asked what data you hold on them, and your privacy policy came off another company's website. Here is what is actually required, what you can skip, and what it costs.

Somebody has emailed asking what you hold on them, and the privacy policy on your site — the one copied from a bigger company three years ago — promises a self-service data portal you have never had. If your website collects so much as a name and an email address through a contact form, UK GDPR and the Data Protection Act 2018 require you to tell people a specified list of things about how you use it, which in practice means a privacy notice that describes what you genuinely do. Most organisations processing personal data also owe the ICO an annual data protection fee, which has been £52, £78 or £3,763 since 17 February 2025, with most small businesses on the lowest tier.

Now the part nobody tells you: what you can skip. Most small businesses do not need a data protection officer, a compliance function, or a cookie banner. The banner is only required if you set non-essential cookies, and if you set none you should not have one — this site is the example, because it runs no analytics and sets no cookies, so it has nothing to ask you about.

Getting the documents right is non-reserved work and does not need a solicitor. A terms and conditions package starts at £695 +VAT and covers one set of business terms, including website, e-commerce or SaaS terms where you sell online; the privacy notice and cookie policy sit under data protection work and are quoted separately, with the price agreed in writing before anything starts. Buzz Legal Ltd is not a firm of solicitors and is not SRA regulated. Acting as your appointed Data Protection Officer, defending an ICO investigation and security or penetration testing are all outside what we do — enforcement proceedings or litigation go to RHF Solicitors (authorised and regulated by the SRA, no. 324115).

This is general legal information for businesses in the UK, not advice on your site.

The documents your site actually needs

Not every site needs all of these, and the honest order of importance runs top to bottom:

What a privacy notice has to tell people

A notice that misses any of these is incomplete rather than merely short:

Write it in language your customers can follow. A notice nobody can read is less useful and arguably less compliant, because transparency is the entire point of the document.

Why a copied policy is worse than none

The most common failure is not a missing document. It is a published document describing a business you do not run: someone else's systems, someone else's retention periods, someone else's suppliers, and obligations you never took on, such as a data protection officer you have never appointed. Those become promises in your name that you are visibly not keeping, which is worse evidentially than silence. A short, accurate notice describing what you genuinely do beats a long borrowed one every time, and it takes less effort than people assume — most of the work is listing what your site and your systems actually touch.

In practice · illustrative example

The copied policy trap — A consultancy lifted a slick privacy policy from a large software brand. It promised users could download all their data through a self-service portal, referred to a data protection officer, and described security certifications the consultancy did not hold. When a client asked to exercise those rights, none of it existed. The policy did not protect them — it created a set of published promises they were now failing to meet, in writing, under their own name.

Picking a lawful basis

You need a lawful basis for each thing you do with personal data, and different activities can rest on different ones. In a typical business: delivering what a customer ordered rests on contract; keeping tax and accounting records rests on legal obligation; ordinary business administration often rests on legitimate interests, which requires you to weigh your interest against the individual's rights and be able to show that you did; and marketing usually rests on consent, or on the soft opt-in for existing customers.

The mistake we see most is treating consent as the answer to everything. Consent must be freely given, specific and as easy to withdraw as it was to give, which makes it a poor fit for processing you need in order to run the business — you cannot stop keeping accounting records because somebody withdrew permission. Name the basis against each purpose in your notice, and you have a document that stands up rather than one that looks the part.

Strictly necessary cookies — the ones that make the site work — do not need consent. Analytics, advertising and most third-party embeds do, under the Privacy and Electronic Communications Regulations, and that consent has to be a genuine choice: no pre-ticked boxes, and declining must be as easy as accepting, so an 'Accept all' button with the reject option buried in a settings menu does not comply. Before you decide anything, check what your site actually loads. Most owners are surprised — a chat widget, a hosted font, a map or an embedded video usually brings cookies of its own, and a site with a banner but no cookies is as wrong as a site with cookies and no banner.

The ICO fee, which most people miss

Most organisations that process personal data must pay an annual data protection fee to the Information Commissioner's Office. The fee sits in three tiers, and the amounts have been £52, £78 and £3,763 since 17 February 2025, when the Data Protection (Charges and Information) (Amendment) Regulations 2025 raised them by just under 30%. Most small businesses are tier 1 at £52, and every tier is £5 cheaper paid by direct debit. Exemptions are narrow, and the assumption that a small business is automatically exempt is usually wrong once you hold customer or employee records. Non-payment is also the easiest enforcement the ICO does, because they can see exactly who has not paid.

Worth knowing

Paying the fee is not compliance, and having a privacy notice is not registration. They are two separate legal steps, and it is entirely possible to have a perfect notice and still owe the fee — or to have paid the fee for years while the notice describes another company's business.

When someone asks for their data

A subject access request is someone asking for a copy of the personal data you hold about them, and anyone can make one, in any form, without saying why. You have one month from receipt to respond, extendable by up to two further months where the request is genuinely complex or there are several of them, and it is free unless the request is manifestly unfounded or excessive. You cannot refuse because it is inconvenient or because the person is being difficult. The practical preparation is small: know where customer data actually lives — inbox, CRM, accounting software, the spreadsheet on someone's laptop — and decide in advance who handles the request.

The 72-hour clock

A personal data breach is not only a hack. A lost laptop, a mis-sent email exposing customer details, a spreadsheet attached to the wrong reply — all count. Where the breach is likely to result in a risk to people's rights and freedoms you must report it to the ICO without undue delay and within 72 hours of becoming aware of it, and where the risk is high you have to tell the individuals as well. You do not need an incident-response plan in a binder. You do need one named person who decides whether a breach is reportable, agreed now, because the clock does not pause while everyone works out whose job it is.

In practice · illustrative example

The 72-hour scramble — A six-person agency sent a client report to the wrong distribution list, exposing another client's contact details and commercial figures. Nobody knew whether it was reportable, so three days went by in indecision before anyone opened the rules. Had they agreed in advance that the operations lead assesses every breach against the ICO threshold, the decision would have taken an afternoon and the record-keeping would have been in order either way.

Selling online: terms of sale

Website terms of use and terms of sale do different jobs, and a site that sells needs both. Terms of sale carry the weight: price, delivery, payment, cancellation, refunds, warranties and liability. Selling to consumers brings rules you cannot draft away — under the Consumer Rights Act 2015 goods must be of satisfactory quality, fit for purpose and as described, and services performed with reasonable care and skill, while the Consumer Contracts Regulations 2013 require pre-contract information and a 14-day cancellation right for most online purchases, built into the checkout flow rather than mentioned in a footer. Be clear about who the customer is contracting with, show your trading name and a contact address, and confirm the order and the price before payment. Selling to businesses and consumers from the same site usually means two sets of sale terms.

What owners get wrong

Sorting it, in order

  1. List what your site actually does: forms, sign-ups, embeds, analytics, sales — anything touching personal data.
  2. Write or rewrite the privacy notice so it describes exactly that, with a lawful basis against each purpose.
  3. Check what cookies genuinely load, then either add a compliant banner or remove the one you do not need.
  4. Register and pay the ICO fee if you owe it.
  5. If you sell online, put terms of sale in place that work with consumer rights rather than against them.
  6. Name the person who handles an access request and the person who calls a breach, and write both down.
  7. Revisit the lot whenever what the business does changes.

What it costs, and where a solicitor comes in

Start free: open your own privacy notice and check three things — does it name systems you actually use, does it state real retention periods, and does it promise any right you could not deliver this week? If any answer is no, that document is a liability rather than a protection. Then book a legal review, which is a free call that ends with a straight answer on what needs fixing and what does not. A terms and conditions package starts at £695 +VAT, covering one set of business terms including website, e-commerce or SaaS terms; the privacy notice and cookie policy are data protection work, quoted separately and agreed in writing first. If a data matter has already become an ICO enforcement case or court litigation, that is reserved, contentious work and goes to RHF Solicitors (authorised and regulated by the SRA, no. 324115). For almost every small business, though, the job is simply making the published promises match the practice.

General information, not advice

This is general legal information, not advice on your situation. For advice tailored to your business, book a legal review. Buzz Legal provides non-reserved business legal support; reserved legal activities are carried out by RHF Solicitors, authorised and regulated by the SRA (no. 324115).

On this pageThe documents your site actually needsWhat a privacy notice has to tell peopleWhy a copied policy is worse than nonePicking a lawful basisCookies: only if you set themThe ICO fee, which most people missWhen someone asks for their dataThe 72-hour clockSelling online: terms of saleWhat owners get wrongSorting it, in orderWhat it costs, and where a solicitor comes in

Get the next Buzz Legal guide as it lands

One short email when a new guide is published — data protection, terms, contracts and employment. No newsletter, no selling, and you can reply to it.

Your address is used to send what you asked for and nothing else. See the privacy policy.

Common questions

Do I legally need a privacy policy on my website?

If your site collects any personal data — and a contact form asking for a name and email does — you must give people specified information about how you use it, under UK GDPR and the Data Protection Act 2018. In practice that means a privacy notice, and almost every business website needs one. It has to cover who you are, what you collect, why, on what lawful basis, who you share it with, how long you keep it, what happens if it leaves the UK, and what rights people have, including the right to complain to the ICO. Missing any of those makes the notice incomplete rather than merely short.

Do I have to pay the ICO fee?

Most organisations that process personal data must pay the annual data protection fee, which has been £52, £78 or £3,763 since 17 February 2025 depending on size and turnover, with most small businesses at the lowest tier. Exemptions are narrow, and the common assumption that a small business is automatically exempt is usually wrong once you hold customer or employee records. Check your position rather than assume it: non-payment is the easiest enforcement the ICO does, because they can see precisely who has not paid, and the fee is trivial next to the penalty. One caveat worth stating plainly — paying the fee is not compliance. It is a fee for processing data, not permission to do it badly.

Can I copy another company's privacy policy?

You can, and it is a bad idea for a reason people underestimate. A copied notice describes someone else's systems, retention periods and suppliers, so it becomes a set of published promises you are not keeping — which is worse evidentially than having nothing, because it is written down and published in your name. It also tends to import obligations you have not taken on, such as naming a data protection officer you have never appointed. A short, accurate notice describing what you genuinely do is both safer and more compliant than a long, borrowed one that describes a business you do not run.

Do I need a cookie banner?

Only if you set non-essential cookies. Analytics, advertising and most third-party embeds require consent under the Privacy and Electronic Communications Regulations, and that consent must be freely given — declining has to be as easy as accepting, so an “Accept all” button with the reject option hidden behind a settings menu does not comply. Strictly necessary cookies that make the site work do not need consent. Before deciding, check what your site actually loads; most owners are surprised, because a chat widget, a font service or an embedded video usually brings cookies of its own. If you set nothing non-essential, you do not need a banner at all.

What lawful basis should I use?

Match it to the reason, and use different bases for different activities. Delivering something a customer asked for usually rests on contract. Keeping tax and accounting records rests on legal obligation. Ordinary business administration and improving your service often rest on legitimate interests, which requires you to balance your interest against the individual's rights and to be able to show that you did. Marketing frequently rests on consent, or on the soft opt-in for existing customers. Name the basis against each purpose in your privacy notice. Relying on consent for everything is the most common error, because it is the hardest basis to hold — it can be withdrawn at any time.

What is the difference between website terms and terms of sale?

Website terms of use govern browsing: acceptable use, intellectual property in the site's content, disclaimers about accuracy and availability, and links to third parties. Terms of sale govern buying: price, delivery, payment, cancellation, warranties, liability and what happens when something goes wrong. They do different jobs, and a site that sells needs both. If you sell to consumers online you also need the pre-contract information and the 14-day cancellation right under the Consumer Contracts Regulations 2013 built into the checkout flow rather than mentioned somewhere in a footer. Selling to businesses and consumers from the same site usually means two sets of sale terms.

What does this cost to get done properly?

Privacy notices, cookie policies and website terms are drafted as data protection and terms work, all of it non-reserved, so no solicitor is required. A terms and conditions package starts at £695 +VAT and covers one set of business terms, including website, e-commerce or SaaS terms where you sell online; the privacy notice and cookie policy sit under data protection work and are quoted separately, as are separate sets of terms for different product lines or customer types. Every price is agreed in writing before anything starts. What is not included: acting as your appointed Data Protection Officer, defending an ICO investigation, and any security or penetration testing, which is an IT job.

Get legal sorted before it bites.

Book a legal review

Clear scope · fixed fees available. Buzz Legal Ltd is not a firm of solicitors and is not regulated by the SRA.

Buzz Legal Ltd — non-reserved business legal services. Reserved legal work carried out by RHF Solicitors, SRA no. 324115. Buzz Money Coach · Privacy · Cookies · Complaints · Terms · · Developed by Chivvy
Chat with us on WhatsApp