All articles

Privacy policies and cookie banners, explained without the panic

August 25, 2026 6 min read Semalt Team Small businessWeb Design

It sounds scarier than it is

The word privacy spelled out in letter tiles
Data protection applies to small sites too, but the basics for a simple business site are manageable.

Few things make a small business owner's eyes glaze over faster than data protection. GDPR, cookie consent, privacy policies, it sounds like a legal minefield built for big corporations, and the temptation is to ignore it and hope. That is a mistake, because the rules do apply to small websites too. But the good news is that for a simple business site, the practical basics are quite manageable, and this guide walks through them in plain English.

One honest note first: this is a general, practical overview, not legal advice, and rules vary by country and change over time. If your situation is complex, or you handle a lot of sensitive data, get proper advice. For a typical small business brochure site, though, understanding a few basics gets you most of the way there.

Why it applies to you

The core idea behind data protection rules is simple and reasonable: if you collect people's personal information, you have a duty to handle it responsibly and be honest about it. Personal information means anything that identifies someone, a name, an email address, a phone number. And here is the key point for small sites: even a basic contact form collects personal data, because a name and email are exactly that. So the moment your site has a contact form, an enquiry form, or gathers any visitor details, these responsibilities apply to you, even if you never thought of yourself as a business that handles data.

This is not something to fear; it is something to handle sensibly. The rules mostly ask you to do things a decent business would want to do anyway: be clear about what you collect, use it only for what you said, keep it reasonably safe, and respect people's wishes about it.

The privacy policy: say what you collect and why

Person handling data carefully on a laptop
A plain privacy policy simply tells visitors what you collect, why, and how you look after it.

The main thing your site should have is a privacy policy: a page that plainly explains what personal information you collect, why, what you do with it, and how someone can ask about or delete their data. It sounds formal, but for a simple site it is straightforward. You might explain that when someone fills in your contact form you collect their name and email to respond to their enquiry, that you do not share it with anyone, and how they can contact you to have it removed.

Write it honestly and in plain language rather than dense legalese; a clear, truthful policy serves visitors better than a copied wall of jargon. Link to it from your site, typically in the footer so it appears on every page, and from near your contact form. The point is transparency: telling people, before they hand over their details, what will happen to those details. That honesty is most of what the rules are really asking for.

Cookie consent: only when you actually need it

Cookies are small files a website can store on a visitor's device, and some of them, particularly the ones used for analytics and advertising, count as tracking that needs the visitor's consent. That is where the cookie banner comes from: the pop-up asking you to accept or manage cookies. Here is the nuance many miss: you need a consent banner when your site uses non-essential cookies, like analytics or marketing trackers, not simply because every site seems to have one.

So it depends on what your site actually does. If you add analytics to track your visitors, or embed things that track people, you generally need a cookie banner that lets visitors accept or decline the non-essential ones, and you should not fire those trackers until they agree. If your site is genuinely simple and uses only essential cookies, your obligations are lighter. Either way, the principle is the same as the privacy policy: be honest about tracking, and let people opt out of the non-essential kind.

If you use a banner, make it a fair one

If you do need a cookie banner, do it in a way that respects visitors rather than tricking them, because a sneaky banner both annoys people and increasingly falls foul of the rules. A fair banner gives a genuine, equally easy choice: declining non-essential cookies should be as simple as accepting them, not hidden behind extra clicks while a big "Accept all" button glows invitingly. Avoid the dark patterns that pressure people into agreeing, since regulators are cracking down on them and visitors resent them. Keep the wording plain, let people accept, reject, or choose, and make sure that if they decline, the trackers genuinely do not run. Done this way, the banner is a small, honest courtesy rather than an obstacle, and it keeps you on the right side of both the law and your visitors' goodwill. A good platform or consent tool can set this up for you so the fair version is the default.

Handling the data you collect

Beyond the policy and the banner, treat the information people give you with basic care. Use it only for the purpose they gave it, so an email left to enquire about a job should not be dumped into a marketing list without their agreement. Keep it reasonably secure, which is another reason HTTPS and sensible passwords matter. Do not keep it forever with no reason; delete enquiries you no longer need. And if someone asks what data you hold on them or asks you to delete it, respond and do so. These are not onerous demands; they are just handling people's details the way you would want your own handled.

Keep it proportionate

It is easy to either ignore this entirely or to panic and over-engineer it, and neither is right. For a typical small business site with a contact form and maybe some analytics, being compliant mostly means three things: have a clear, honest privacy policy; use a cookie banner if and only if you run non-essential tracking; and handle the details people give you responsibly. That is a realistic, proportionate approach for a small brochure site, and it is genuinely achievable without a legal department. As your data handling grows more involved, take proper advice, but do not let the scary reputation of the subject stop you from covering these sensible basics.

A site that makes the basics easy

Covering these essentials is far simpler when your platform helps. With Semalt you get a complete site in minutes with room for a privacy policy page, footer links so it appears everywhere, and straightforward handling of contact form data, plus HTTPS as standard to keep that data secure in transit. You add a clear, honest privacy policy, set up cookie consent if you use tracking, and publish.

It is free to try, and you can go live straight away or connect your own domain later. Be honest about what you collect, ask consent for non-essential tracking, look after people's details, and handle the privacy basics calmly rather than fearfully.

Keep reading