If you run a website or online business, you handle personal data (names, emails, addresses, payment details, browsing data) and that means the UK GDPR and Data Protection Act 2018 apply to you. The good news is that compliance for a typical online business comes down to a manageable set of steps. Here is how to get it right in England and Wales.
1. Know what data you hold and why
Start with a simple data map: what personal data you collect (at sign-up, checkout, via cookies and forms), why, where it is stored, who you share it with, and how long you keep it. You cannot protect or document what you have not identified.
2. Identify a lawful basis
For each use of data, you need a lawful basis under the UK GDPR, commonly consent, contract (necessary to fulfil an order), or legitimate interests (with a balancing test). Direct electronic marketing (such as email or SMS) to individual subscribers generally requires prior consent under PECR, unless the soft opt-in applies; other channels (such as postal marketing) may rely on other lawful bases, and different rules apply to corporate subscribers (see below).
3. Publish a clear privacy notice
Your website must have an accessible privacy notice telling people what data you collect, why, your lawful basis, who you share it with, how long you keep it, where it goes (including any international transfers), and their rights. Make it easy to find.
4. Get cookies and marketing right (PECR)
- Cookies: under PECR, you need consent before setting non-essential cookies (analytics, marketing). Use a compliant cookie banner where "reject" is as easy as "accept", and only strictly necessary cookies run without consent.
- Marketing: email/text marketing to individuals generally needs consent, subject to the limited soft opt-in for existing customers. Always offer an easy unsubscribe.
5. Respect individuals' rights
Be ready to handle requests (access, correction, erasure, objection) within one month. Have a simple internal process so a request does not catch you out.
6. Keep data secure
Apply appropriate security: encryption, access controls, strong passwords/MFA, secure payment processing, and staff awareness. Most breaches come from human error, so training matters.
7. Manage suppliers and transfers
Where suppliers process data for you (hosting, email, analytics), put data processing agreements in place, and check whether data is transferred outside the UK (and covered by appropriate safeguards such as the IDTA).
8. Be ready for breaches
Have a breach plan: you must usually notify the ICO within 72 hours of a breach that risks people's rights, and tell affected individuals where the risk is high.
Key takeaways
- Map your data, pick a lawful basis, and publish a clear privacy notice.
- Get cookies and marketing consent right under PECR.
- Handle rights requests within a month and keep data secure.
- Use data processing agreements, cover international transfers, and have a 72-hour breach plan.
Sources
- UK GDPR and Data Protection Act 2018 (lawful basis, transparency, rights, security, breach notification)
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (cookies and marketing)
- ICO guidance for online businesses and SMEs
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.