Introduction
If your website collects data or uses tracking technologies, UK law requires you to have a Cookie Policy and a Privacy Policy.
Here’s a quick guide to what you need and why.
Cookie Policy – Do You Need One?
Yes, if your website uses cookies or similar tracking technologies. Under UK GDPR and the Privacy and Electronic Communications Regulations (PECR), you must inform users about cookie usage and obtain consent for non-essential cookies.
When is a Cookie Policy Required?
A Cookie Policy is needed if your site uses:
- Analytics cookies (e.g., Google Analytics)
[[ Note: Unless asked not too - I add a GA Code to all websites as part of the SEO setup]] - Advertising or tracking cookies (e.g., Facebook Pixel)
- Third-party cookies (e.g., embedded YouTube videos, live chat tools)
However, you don’t need a policy if your website only uses strictly necessary cookies, such as:
- Session cookies for shopping carts
- Security/authentication cookies
- Cookies required for accessibility features
What Should a Cookie Policy
- Explanation of what cookies are and why they are used.
- Types of cookies used (e.g., essential, analytics, marketing).
- Details of third-party cookies, if any.
- How users can manage and opt out of cookies.
Do You Need Cookie Consent?
Yes, if using non-essential cookies.
Users must:
✅ Actively accept cookies (no pre-ticked boxes).
✅ Choose which cookies to allow.
✅ Have the ability to withdraw consent at any time.
A cookie banner or consent tool should be installed to comply with UK law.
Privacy Policy – Do You Need One?
Yes, if your website collects or processes personal data. This is required under UK GDPR and the Data Protection Act 2018.
When is a Privacy Policy Required?
You need a Privacy Policy if you:
- Collect personal data (e.g., via contact forms, checkout pages).
- Use cookies that track personal data.
- Process eCommerce transactions.
- Collect data for email marketing.
- Share user data with third parties (e.g., Google Analytics, payment providers).
What should Privacy Policy Include
- What data you collect (name, email, IP address, etc.).
- How and why you collect it (e.g., contact forms, analytics, purchases).
- How you store and protect data (security measures, encryption).
- Who you share data with (third-party services, affiliates).
- User rights under UK GDPR, including:
- Right to access their data
- Right to request deletion
- Right to data portability
- How long data is kept before deletion.
- Your lawful basis for processing data (e.g., consent, contractual need, legitimate interest).
Where to Display Privacy Policy
✔ A dedicated Privacy Policy page (linked in your footer).
✔ On form submissions
(e.g., a checkbox linking to the policy).
✔ On sign-up pages for newsletters or accounts.
Key Takeaway
If your website collects any personal data or uses non-essential cookies, you must have both a Privacy Policy and a Cookie Policy—and obtain user consent where necessary.
Client Responsibility for Compliance
🔹 As per my Terms & Conditions, it is your responsibility to provide the correct Cookie and Privacy Policies for your website.
🔹 I am not legally responsible for their content or compliance with UK law.
🔹 While I can install a cookie consent plugin, it is your responsibility to configure it correctly and maintain legal compliance.
Free Privacy & Cookie Policy Generators
These tools create basic legal policies tailored to your website:
- Termly – Offers free policies with customisable templates. A paid version is needed for more advanced options.
- PrivacyPolicies.com – Generates free privacy and cookie policies, with the option to add clauses for GDPR and other regulations.
- GetTerms.io – Quick and simple generator for privacy and cookie policies. Free for basic policies, with premium options available.
- FreePrivacyPolicy.com – Generates a free privacy policy with cookie policy integration.