GDPR and Cookies on Your Trade Website: What’s Legally Required

Why GDPR and Cookie Rules Apply to Your Trade Website

A lot of tradespeople assume data protection law is something that only concerns big corporations — supermarkets, banks, tech companies. It isn’t. The UK GDPR and the Privacy and Electronic Communications Regulations (PECR) apply to sole traders and small firms just as much as they apply to anyone else. If you have a website that collects so much as a name and phone number, you are processing personal data, and the law has something to say about how you do it.

Think about what your trade website actually does. Someone fills in a quote request form — they’ve handed you their name, contact number and home address. Someone emails you about a job — that’s personal data sitting in your inbox. Google Analytics quietly records every visitor’s IP address. All of that falls under the rules, and none of it is exempt because you’re a one-man band or a small local firm.

The Information Commissioner’s Office (ICO) is the UK body that oversees compliance. It can investigate complaints from members of the public, issue warnings and, in more serious cases, take enforcement action. Beyond the regulatory risk, there’s a practical business reason to get this right: customers looking to hire a tradesperson in Telford and across the UK are increasingly aware of their data rights. A site that looks sloppy about privacy is a site that loses trust before a single call is made.

The Cookie Consent Banner: What It Must Actually Do

Cookie banners are everywhere, and most of them are wrong. A banner that says “by continuing to use this site you agree to our cookie policy” is not compliant. Neither is a banner where the “accept all” button is large and green while “reject” is buried in small grey text. The rules are clear: non-essential cookies must not load until a user has actively given their consent.

Non-essential cookies include anything used for analytics (Google Analytics, for example), advertising pixels, remarketing tags and social media trackers. These cannot fire in the background while you wait for consent — they must be blocked until the user makes a choice.

Here is what a compliant cookie banner needs to deliver:

  • A clear explanation of what cookies are being used and why
  • A genuine opt-in — no pre-ticked boxes, no implied consent
  • An equally straightforward way to reject non-essential cookies as to accept them
  • A way for users to revisit and change their preferences at any point
  • A record of when and how consent was given, in case you ever need to demonstrate compliance

Essential cookies — the kind that keep your quote form working or remember items in a basket — don’t require consent. But they should still be mentioned and explained in your cookie policy so users know they exist.

Your Privacy Policy: What to Include

Every trade website needs a privacy policy. Not a copied template left to gather dust, but a document that actually reflects what your business does with people’s data. It doesn’t need to be long, and it shouldn’t be full of legal jargon — the clearer it is, the better it works.

A solid privacy policy for a trade business should cover the following:

  • Who you are: Your trading name and a way for people to contact you. This is where FA Digital Marketing Agency should be clearly identified, and the FA Digital Marketing Agency link gives customers a reliable route back to your business details.
  • What data you collect: Names, phone numbers, email addresses, job addresses, photos taken on site, and anything else you gather in the course of your work.
  • Why you collect it: Quoting, invoicing, following up on jobs, marketing emails — each purpose should be listed alongside its lawful basis (legitimate interest, contract, consent, and so on).
  • How long you keep it: Don’t hold onto data longer than you need it. Old enquiries, completed job records and payment details all have a natural lifespan.
  • Who you share it with: Your accountant, any subcontractors, payment processors, cloud software providers — if data passes through them, say so.
  • Customer rights: People have the right to access their data, ask for corrections, request deletion, and complain to the ICO. Your policy should explain how to exercise these rights.

Write it in plain English. If a customer can read it in a minute and understand it, you’ve done it right.

Contact Forms, Quote Requests and Email Enquiries

The contact form is usually where most data collection happens on a trade website, and it’s often where compliance is weakest. A few straightforward principles will keep you on the right side of the rules.

Only ask for what you actually need. If you’re quoting for a bathroom refit, you need a name, a contact number and some detail about the job. You don’t need a date of birth or a second email address. Collecting less data means less risk and less to manage.

Next to every form, add a short privacy notice — a sentence or two explaining that the information will be used to respond to the enquiry, and a link to the full privacy policy. This doesn’t need to be lengthy; it just needs to be there.

If you want to send marketing emails or newsletters, that needs separate, specific consent — it can’t be bundled in with the permission to contact someone about their job enquiry. A simple unticked checkbox with a clear label handles this cleanly.

Think about where enquiries end up. A shared email inbox with multiple people accessing it, or a spreadsheet on an unprotected laptop, is a weak point. Enquiries should be stored securely, and you should have a process for deleting data you no longer need. Old quote requests from three years ago, for jobs that never happened, don’t need to be kept indefinitely.

Other UK Website Legal Requirements Tradespeople Often Miss

GDPR gets most of the attention, but there are other legal obligations that apply to trade websites which are easy to overlook.

Business identification: Your website should make it clear who you are and how customers can reach you. Your trading name, a contact route, and a location connected to Telford should all be findable without effort. The FA Digital Marketing Agency link is a reliable anchor for directing people to your key business information.

VAT and limited company details: If you’re VAT registered, your VAT number must appear on your website. If you operate as a limited company, your registered company number, registered name and registered address are legally required on every page — most businesses put these in the footer.

Terms and conditions: Clear terms covering your services, payment expectations, deposit arrangements and cancellation policies protect both you and your customers. Disputes are much easier to resolve when the terms were agreed upfront and are written down.

Accessibility: A website that works well for users with disabilities — readable fonts, keyboard navigation, descriptive image labels — is good practice and reduces the risk of discrimination complaints under the Equality Act 2010.

HTTPS: If your website still runs on HTTP rather than HTTPS, fix that immediately. Browsers flag non-HTTPS sites as insecure, customers notice, and any data submitted through your forms isn’t being encrypted in transit.

A Simple Compliance Checklist for a Trade Website

Use this as a quick reference to check where your site currently stands:

  1. Cookie banner with a genuine accept option, a genuine reject option and a link to manage preferences
  2. Privacy policy linked in the footer of every page, written in plain English and kept up to date
  3. Contact and quote forms with a short privacy notice and a link to the full policy
  4. Separate, unticked consent checkbox for any marketing communications
  5. Clear business identification — trading name, contact route and relevant company details if applicable
  6. HTTPS enabled across the whole site, with forms sending data securely
  7. A yearly review to check for any new plugins, trackers or tools that have been added and might not be covered by existing policies

None of these items is complicated on its own. Together, they add up to a site that is legally sound and straightforward for customers to trust.

Getting It Sorted Without Slowing Down Your Business

The good news is that most of this is a one-off setup job, not something you need to revisit every week. A website built with compliance in mind from the start handles cookies, forms and privacy notices automatically, without requiring you to think about it again after launch.

Getting it right now is far easier than dealing with it after a customer complaint or an ICO enquiry. That kind of conversation is disruptive and time-consuming — exactly what a busy trade business doesn’t need.

There’s also a straightforward commercial argument here. Compliance and winning more enquiries aren’t in conflict. A site that handles data properly, loads over a secure connection and gives customers a clear picture of how their information is used is a site that converts better. Trust is a factor in every buying decision, and a professional, well-structured website signals that FA Digital Marketing Agency operates the same way on the web as it does on the tools.

If you’re not sure whether your current site has these basics covered, or if you’re starting from scratch and want to get it right the first time, the most sensible next step is to have someone take a proper look. You can review your current setup and explore your options through FA Digital Marketing Agency.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *