In-Depth Guide
The Complete Guide to GDPR Compliance
Our team has written a comprehensive guide covering technical specs, best practices, and the exact approaches we use on every project.
Most businesses assume their cookie banner means the job is done. It rarely does.
We’ve audited plenty of UK sites where the banner sits there looking perfectly compliant, while Google Analytics and a Facebook pixel have already fired in the background before anyone clicked a single button. That gap between what a site looks like it’s doing and what it’s actually doing is where most GDPR exposure quietly lives.
GDPR Website Requirements: The Direct Answer
Here’s the breakdown UK businesses need before assuming they’re covered.
| Requirement | What It Actually Means | Common Mistake |
|---|---|---|
| Cookie consent | Non-essential scripts must not run until consent is given | Banner present, scripts still firing early |
| Privacy policy | Must accurately describe data actually collected | Generic template that doesn’t match the site |
| Lawful basis | A documented reason for processing each type of data | No lawful basis recorded at all |
| Data subject rights | A process for handling access or deletion requests | No process exists until a request arrives |
| Third-party tools | Each tool reviewed for its own data handling | Analytics and widgets assumed to be fine |
| Consent records | Evidence kept of what a visitor agreed to | Nothing stored, no proof if ever questioned |
One thing worth being precise about, because it trips people up constantly. In the UK, cookies are governed by PECR, the Privacy and Electronic Communications Regulations, while UK GDPR sets the standard for what valid consent actually looks like. Both are enforced by the ICO. In practice that means consent has to be freely given and as easy to refuse as it is to accept, and non-essential scripts must not run before it. Auditing against the GDPR half alone leaves the part that actually gets enforced unchecked.
None of this is about ticking a legal box for the sake of it. It’s about knowing what your own website is doing with the data it collects, and most site owners genuinely don’t.
Why the Cookie Banner Is Usually the Smallest Part of the Problem
In our testing across dozens of UK client sites, the visible cookie banner is rarely where the real risk sits. It’s what happens underneath it.
We worked with a Bristol-based consultancy last year. Their banner looked correct, with clear wording. It had accept and reject options. It was also styled properly. Behind it though, three separate marketing scripts were loading the moment the page rendered, regardless of what the visitor clicked. Nobody had configured the consent tool to actually block anything. It was decorative.
That’s a genuinely common pattern. A cookie management plugin gets installed, someone ticks a few boxes, and everyone assumes the technical blocking is happening automatically. It often isn’t, unless someone has gone in and configured which script categories actually get held back before consent.
What a Proper GDPR Website Audit Actually Checks
A surface-level review looks at whether a banner exists. A proper one goes considerably further.
- Every cookie and script running on the site, mapped against whether it’s necessary, functional, analytics, or marketing
- Every form on the site, checking what data gets collected and where it’s sent once submitted
- Third-party embeds and widgets, since booking tools, chat widgets and review plugins often set their own cookies unnoticed
- The privacy policy itself, compared line by line against what the site genuinely does, not what a template assumes it does
- Data retention settings, checking how long information actually sits in storage after collection
- Lawful basis documentation, recording why each type of processing is happening, whether that’s consent, contract, or legitimate interest
Skip any one of these and you end up with a site that looks compliant on the surface while carrying real gaps underneath, the kind that only surface when someone actually asks a difficult question.
Data Protection Isn’t Separate From Site Security
There’s a piece of this that gets overlooked constantly. GDPR isn’t only about consent and paperwork; it’s also about whether the personal data your site collects is actually stored securely once it arrives.
A form that collects names, emails and phone numbers, sitting on a site with outdated plugins or weak access controls, is a data protection risk regardless of how well-written the privacy policy happens to be. We’ve seen sites with immaculate cookie consent setups running on WordPress installations several versions out of date, with the admin login wide open to brute-force attempts. If you’re unsure where your site actually stands on that front, our Website Security Audit looks specifically at those technical vulnerabilities, the kind that turn a documentation gap into an actual data breach.
Compliance Drifts Quietly Without Anyone Noticing
Here’s something we tell every client directly. A GDPR review carried out once and never revisited stops being accurate within months, sometimes weeks.
A new booking plugin gets added. A marketing team connects a fresh analytics tool. A developer drops in a chat widget to help with support enquiries. Each one of these can quietly introduce new cookies, new data flows, and new gaps between what your privacy policy says and what your site actually does. Nobody sets out to break compliance; it just erodes gradually as a site evolves.
This is exactly why we build ongoing checks into our website maintenance work rather than treating GDPR as a single project with a finish line. Sites that get regular attention catch these drift points early, before they’ve been sitting unnoticed for a year.
Where GDPR and Technical SEO Actually Overlap
This one surprises people. Cookie consent tools, when configured badly, can genuinely damage page speed and Core Web Vitals scores, because poorly built consent banners often block rendering or load heavy scripts regardless of what gets clicked.
We’ve seen sites where fixing the cookie consent implementation properly, blocking scripts correctly rather than just visually hiding a banner, improved load time noticeably as a side effect. If a wider technical review has flagged performance issues alongside compliance concerns, it’s worth looking at both together. Our technical SEO team regularly finds that consent tooling and performance problems are more connected than people expect, and fixing one properly often improves the other.
Getting This Right Without Overcomplicating It
None of this needs to be intimidating. Most gaps we find come down to a handful of recurring issues: scripts firing early, documentation that hasn’t kept pace with the site, and nobody quite owning the responsibility of checking either.
Fixing it properly means someone actually going through the site, tool by tool, form by form, rather than assuming a plugin installed years ago is still doing its job. That’s the difference between a website that looks compliant and one that genuinely is.
This guide covers website compliance. It isn’t legal advice on your wider data protection obligations.