Support & compliance

GDPR & Cookie Compliance in Mansfield

Most small business websites have a privacy policy copied from somewhere else, describing data handling that does not match what the site actually does. That is worse than not having one.

UK GDPR and PECR apply to every business website that collects anything — a contact form, analytics, a newsletter signup. The practical requirements are not onerous, but they are specific, and copying a policy off another site satisfies none of them.

We are not solicitors and we do not give legal advice. What we do is the technical side: making the website actually behave the way a compliant privacy policy says it does.

That distinction matters. A perfect policy on a site that loads analytics before consent is not compliance, it is documentation of a breach.

What you get

A cookie banner that genuinely works

Nothing non-essential loads until consent is given. Reject must be as easy as accept — a banner with only an "accept" button is not compliant, and that describes most of them.

An audit of what you actually set

Most sites load more third-party trackers than the owner realises: embedded maps, fonts, chat widgets, review carousels, social embeds. We list them and categorise them.

Consent mode wired into analytics

GA4 and ad platforms configured to respect consent, with modelling filling some of the measurement gap. Compliant and still useful.

Policies that match reality

Privacy policy and cookie policy written from what your site genuinely does, not a template listing services you have never used.

Forms handled correctly

Lawful basis identified, no pre-ticked boxes, data retention decided rather than accidental, and submissions stored somewhere you can find and delete them on request.

A subject access process

A simple, documented route for handling someone asking what you hold on them, which you must answer within a month.

The mistakes we find most often

  • Analytics loading before consent is given, which is the most common breach by a distance
  • A cookie banner with an accept button and no equally prominent reject
  • A privacy policy naming services the business has never used, because it was copied
  • Pre-ticked marketing consent boxes, which have been non-compliant for years
  • Form submissions sitting in an inbox forever with no retention policy
  • Embedded maps and fonts setting third-party cookies before any consent

What actually happens if you ignore it

Realistically, the ICO is not going to raid a Mansfield plumber over a cookie banner. Enforcement against small businesses is rare and usually starts with guidance rather than a fine.

The likelier consequences are mundane: a customer complains, a larger client asks about your data handling before signing a contract and you have nothing to show them, or a competitor reports you. Getting it right costs £145 once and removes the question entirely.

What affects the price

From £145 is a genuine starting point, not a teaser. Here is what moves it, so you can work out roughly where you would land before you ring us.

  • How many tracking and marketing tools are in use
  • Whether policies need writing from scratch or reviewing
  • Whether forms and data flows need reworking
  • Ecommerce sites, which handle considerably more personal data

Why local matters here

GDPR & Cookie Compliance — the Mansfield picture

The businesses most likely to be asked about this locally are the ones tendering for public sector or larger corporate work. Councils, NHS trusts and larger firms increasingly ask about data handling as part of procurement, and "we have not really looked at it" is not a good answer at that point.

If you are chasing that kind of work, having this sorted is worth more than the compliance itself.

Also asked for as

People describe this in a lot of different ways. If you searched for any of these, you are in the right place — it is the same service.

  • cookie consent Mansfield
  • privacy policy Mansfield
  • data protection website Mansfield
  • UK GDPR compliance Mansfield
  • cookie banner Mansfield

GDPR & Cookie Compliance — your questions

Do I need a cookie banner?

If your site sets any non-essential cookies — analytics, advertising, embedded video, most chat widgets — then yes. If it genuinely sets none, you do not. A surprising number of sites could remove the banner entirely by removing two scripts nobody uses.

Can I just copy a privacy policy?

You can, and it will be wrong, because it describes another company’s data handling. It also usually breaches the copyright of whoever wrote it. Ours are written from what your site actually does.

Do I need to register with the ICO?

Most businesses processing personal data need to pay the data protection fee, which is £40 to £60 a year for small organisations. There are exemptions. Check on the ICO’s own site — it takes five minutes.

Is this legal advice?

No. We handle the technical implementation and write policies that describe what your site does. For anything genuinely contested, speak to a solicitor — and we can recommend local ones.

Fancy a straight answer about your website?

Tell us what you are trying to do and we will tell you what it takes, what it costs, and whether it is even worth doing. No pitch deck, no pressure.

Call 01623 272050 Get a quote