Start with a data and technology inventory
List every form, analytics product, embedded video, map, chat tool, booking system, advertising tag, payment service, security tool, and third-party widget. Record what information it collects, why, where it goes, how long it is kept, and who can access it.
Do not assume a simple brochure site collects nothing. Server logs, contact forms, spam protection, analytics, and embedded services can all process information or access a user's device.
Write a privacy notice that describes reality
The notice should explain who the organisation is, what personal data it uses, why, the lawful basis relied on, who receives it, retention, rights, contact routes, and other required information relevant to the processing.
Use the ICO's small-organisation guidance and tools as a starting point. Copying another company's notice is risky because its systems, purposes, and suppliers are unlikely to match yours.
Understand when a cookie control is needed
The rules cover cookies and other storage or access technologies. Some tools are strictly necessary for a service the user requests; others, including many analytics, personalisation, and advertising tools, may require consent or another specific assessment under current rules.
The exact answer depends on the technology and purpose. Review current ICO guidance rather than relying on an old plugin's default categories.
Make consent a genuine choice
Where consent is required, do not set the non-essential technology before the choice is made. Make reject and accept routes comparably clear, avoid pre-selected options, explain categories in plain language, and let people change their choice later.
A banner that says continued browsing means consent is not a substitute for a properly implemented choice. The interface and the underlying script behaviour both matter.
Treat forms and enquiries carefully
Collect only the information needed for the next step, secure it in transit and at rest, limit inbox and system access, and define a retention approach. Do not ask for health, financial, or other sensitive detail in a general contact form without a justified and secure process.
Tell people how their enquiry will be used close to the form and link to the full privacy notice. Marketing consent should be handled separately from replying to the requested enquiry.
Review the setup when the website changes
A new analytics tag, booking platform, video embed, advertising campaign, or chat widget can change the data picture. Make privacy review part of adding a supplier rather than an annual paperwork exercise.
The ICO updated storage and access technology guidance in 2026 following legal changes, which is another reason to work from current primary guidance and obtain professional advice when the use is complex.
Takeaway — The trustworthy approach is to understand the website first, then write the notice and consent experience around what it actually does.
Sources
- Privacy notices and cookies — Information Commissioner's Office
- Cookies and privacy notices in detail — Information Commissioner's Office



