Do I need a privacy policy on my website?
If there is a contact form, yes. What it needs to say in plain words, and the ICO fee question.
See the templatesThe short answer: if your website collects anything about a person, even a name and email through a contact form, UK GDPR says you must tell them what you do with it. A privacy policy is how. It does not need to be long or written by a lawyer. It needs to be true.
What it needs to say
- Who you are and how to contact you
- What you collect: name, email, phone, message
- Why: to reply to the enquiry, to do the job
- Where it goes: your email, your accounts software, a payment provider
- How long you keep it
- That people can ask what you hold and ask you to delete it
- Whether you use analytics or cookies, and which
For a one page site with a contact form that is half a page.
The ICO fee
Most organisations that process personal data have to pay the ICO a yearly data protection fee, £52 for the smallest tier as of October 2026. There are exemptions, and a lot of sole traders fall under them, for example if you only hold data for your own accounts, staff and marketing. The ICO has a short self assessment on its site. Take it; it takes five minutes and tells you yes or no.
What our templates do
Every template has a privacy page you switch on and fill in from our starter wording, with your business name and contact details filled in automatically. The contact form sends to your email and the site stores nothing, which keeps the policy short and true.
This is general information, not legal advice. For your own case, ask a solicitor.
Want to see yours? Pick a website template and fill it in for free. You only pay when you want it live. Already have a site? Bring it in and we fill a template from it.