Support & compliance
GDPR & Cookie Compliance in Mansfield
Most small business websites have a privacy policy copied from somewhere else, describing data handling that does not match what the site actually does. That is worse than not having one.
UK GDPR and PECR apply to every business website that collects anything — a contact form, analytics, a newsletter signup. The practical requirements are not onerous, but they are specific, and copying a policy off another site satisfies none of them.
We are not solicitors and we do not give legal advice. What we do is the technical side: making the website actually behave the way a compliant privacy policy says it does.
That distinction matters. A perfect policy on a site that loads analytics before consent is not compliance, it is documentation of a breach.
What you get
A cookie banner that genuinely works
Nothing non-essential loads until consent is given. Reject must be as easy as accept — a banner with only an "accept" button is not compliant, and that describes most of them.
An audit of what you actually set
Most sites load more third-party trackers than the owner realises: embedded maps, fonts, chat widgets, review carousels, social embeds. We list them and categorise them.
Consent mode wired into analytics
GA4 and ad platforms configured to respect consent, with modelling filling some of the measurement gap. Compliant and still useful.
Policies that match reality
Privacy policy and cookie policy written from what your site genuinely does, not a template listing services you have never used.
Forms handled correctly
Lawful basis identified, no pre-ticked boxes, data retention decided rather than accidental, and submissions stored somewhere you can find and delete them on request.
A subject access process
A simple, documented route for handling someone asking what you hold on them, which you must answer within a month.
The mistakes we find most often
- Analytics loading before consent is given, which is the most common breach by a distance
- A cookie banner with an accept button and no equally prominent reject
- A privacy policy naming services the business has never used, because it was copied
- Pre-ticked marketing consent boxes, which have been non-compliant for years
- Form submissions sitting in an inbox forever with no retention policy
- Embedded maps and fonts setting third-party cookies before any consent
What actually happens if you ignore it
Realistically, the ICO is not going to raid a Mansfield plumber over a cookie banner. Enforcement against small businesses is rare and usually starts with guidance rather than a fine.
The likelier consequences are mundane: a customer complains, a larger client asks about your data handling before signing a contract and you have nothing to show them, or a competitor reports you. Getting it right costs £145 once and removes the question entirely.
What affects the price
From £145 is a genuine starting point, not a teaser. Here is what moves it, so you can work out roughly where you would land before you ring us.
- How many tracking and marketing tools are in use
- Whether policies need writing from scratch or reviewing
- Whether forms and data flows need reworking
- Ecommerce sites, which handle considerably more personal data
Why local matters here
GDPR & Cookie Compliance — the Mansfield picture
The businesses most likely to be asked about this locally are the ones tendering for public sector or larger corporate work. Councils, NHS trusts and larger firms increasingly ask about data handling as part of procurement, and "we have not really looked at it" is not a good answer at that point.
If you are chasing that kind of work, having this sorted is worth more than the compliance itself.
Also asked for as
People describe this in a lot of different ways. If you searched for any of these, you are in the right place — it is the same service.
- cookie consent Mansfield
- privacy policy Mansfield
- data protection website Mansfield
- UK GDPR compliance Mansfield
- cookie banner Mansfield
GDPR & Cookie Compliance — your questions
Do I need a cookie banner?
If your site sets any non-essential cookies — analytics, advertising, embedded video, most chat widgets — then yes. If it genuinely sets none, you do not. A surprising number of sites could remove the banner entirely by removing two scripts nobody uses.
Can I just copy a privacy policy?
You can, and it will be wrong, because it describes another company’s data handling. It also usually breaches the copyright of whoever wrote it. Ours are written from what your site actually does.
Do I need to register with the ICO?
Most businesses processing personal data need to pay the data protection fee, which is £40 to £60 a year for small organisations. There are exemptions. Check on the ICO’s own site — it takes five minutes.
Is this legal advice?
No. We handle the technical implementation and write policies that describe what your site does. For anything genuinely contested, speak to a solicitor — and we can recommend local ones.
You might also need
Website Security
Hardening, monitoring, and cleaning up when something has already gone wrong.
From £95Google Analytics Setup
GA4 configured so it answers questions instead of producing charts.
From £95Web Design
Websites that load fast, rank well and turn visitors into enquiries.
From £250Website Accessibility
Making the site work for everyone, which also happens to help it rank.
From £195Online Reputation Management
Building reviews, handling criticism, and dealing with what appears when people search your name.
From £95/monthDigital Training for Mansfield Businesses
Teaching you to do it yourself, when that is the sensible answer.
From £95Fancy a straight answer about your website?
Tell us what you are trying to do and we will tell you what it takes, what it costs, and whether it is even worth doing. No pitch deck, no pressure.