Is Your Website Ready to Launch, Legally?

person using google on a laptop with hands on the trackpad

Contents:

Your website looks ready to launch - but have you completed these legal checks?

You may be ready to press the “GO” button on your website, but you need to make sure you have checked all the legal aspects and ticked all the boxes relating to UK law surrounding key elements such as website security, user data and consumer protection.

Please note: the information in this piece relates to UK legislation, not international law.

Website security

Website security is extremely important to safeguard sensitive user data, protect from cyberattacks, maintain server integrity and prevent malicious threats such as DDoS attacks or malware.

Core UK Legislation for Website Security

  • The UK GDPR and Data Protection Act 2018 > Article 32 – mandates data security and timely patching using HTTPS, encryption and access controls.
  • The Online Safety Act 2023 – targets user protection and illegal content through management of systemic risks, prevention of illegal content and enforcement of age assurance where required. Ofcom can issue penalties up to £18 million or 10% of global annual turnover for severe compliance failures.
  • Computer Misuse Act 1990 – used to enforce criminal proceedings against unauthorised access to computer materials or intentional disruption of a website.

The Information Commissioner’s Office (ICO) also expects critical software and plugin vulnerabilities to be patched promptly (typically within 14 days) and can issue regulatory fines if personal data is not kept secure.

There are a number of core protection methods to meet the requirements mandated within these different pieces of legislation:

  • SSL/TLS Encryption: Use of an SSL certificate to enable HTTPS and encrypt data in transit. Whilst there is no single UK law that denotes a business must use HTTPS, UK data protection laws do legally require organisations to keep user personal information secure. As such, HTTPS is the solution to meeting this legal need for any website handling user data.
  • Software Updates: Used to regularly patch content management systems, themes, and plugins.
  • Strong Access Control: Enforces multi-factor authentication (MFA) and role-based permissions.
  • Routine Backups: These keep automated, off-site copies of website data for fast recovery.

If a website does not use HTTPS, the majority of web browsers will notify users, forcing them to opt in to visit the website rather than loading automatically. This destroys user trust and can also incur SEO penalties, as search engines do favour secure websites.

Business information

Displaying accurate business information doesn’t only enhance trust and credibility, it also makes it clear who is legally operating the website and who the customer is doing business with. There are legal compliance requirements around what must be displayed depending on the type of business and nature of trading, as well as the type of website (ecommerce or otherwise).

It is important to remember that the legalities change depending on the type of business you are operating. For example, a sole trader doesn’t have a company registration number or registered office in the Companies House sense and therefore does not need to display this information online.

Core UK Legislation for Displaying Business Information

The rules that govern the business information that must be published on a business website go beyond just GDPR and privacy requirements.

  • The Companies Act 2006, Section 82 – gives the Secretary of State power to require companies to display specified information, including their registered name, on business communications and websites.
  • The Company, Limited Liability Partnership and Business (Names and Trading Disclosures) Regulations 2015 – denotes that UK companies must display any specific trading-disclosure obligations.
  • The Electronic Commerce (EC Directive) Regulations 2002, Regulation 6 – businesses that provide online services must ensure that key information is displayed prominently at all times.
    This includes:
    • the service provider’s name;
    • the geographic address where it is established;
    • contact details, including an email address, allowing rapid and direct communication;
    • registration details where the business is entered in a public trade or similar register;
    • relevant regulatory/supervisory details where applicable;
    • professional body/title information for regulated professions; and
    • VAT identification number where the activity is subject to VAT

Companies House also demands that businesses display their registered name online, regardless of trading names.

Limited companies must also display:

  • Full registered company name – not merely the trading name.
  • Company registration number.
  • Place of registration – for example, “Registered in England and Wales”.
  • Registered office address.
  • The fact that it is a limited company, where this is not already apparent from its registered name.

Gov.UK Guidance: Incorporation and names is a key resource to the main requirements for incorporating a company in the UK.

Consumer and User Protection

Terms and conditions

UK law does not say every website must have a page literally called “Terms & Conditions”, however there must be comprehensive and transparent information somewhere on a website to denote all contractual terms in cases where users are entering into a contract with the business. This is usually contained in a concise T&Cs page.

The legal requirements around this depend on whether the website is providing information only or selling products/services to consumers. It is important to note that you cannot overrule the statutory rights of customers, as set out in the Consumer Rights Act 2015.

Information only websites

Information only websites are not exempt from UK laws around business information, data protection, cookies, tracking, copyright etc, but do not have any specific laws to pertain to if they do not provide services or products to users, because no consumer contract is being concluded through the website.

Ecommerce or Service websites

For an ecommerce or service website selling to consumers, the main rules come from:

  • The Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 – mainly protect consumers before and immediately after an online purchase. For many online purchases, they also provide a 14-day cancellation period, alongside rules around refunds, additional charges and contract confirmation.
  • The Consumer Rights Act 2015 – protects consumers against unfair contract terms and in cases where goods may not be of satisfactory quality/fit for purpose.

Consumer protection requirements (ecommerce websites)

As above, ecommerce sites have additional obligations under UK consumer law that go far beyond just displaying clear T&Cs.

  • Website security – ecommerce businesses handling customer names, addresses, account details and other personal information must comply with the UK GDPR and Data Protection Act 2018.
  • Transparency: Before somebody places an online order, the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 require traders to provide specified information clearly.
    • This must include:
    • Trader’s identify
    • Contact information
    • Total price
    • Additional charges
    • Delivery arrangements
    • Payment options
    • Applicable cancellation rights
  • The Digital Markets, Competition and Consumers Act 2024 (DMCC Act) was created to strengthen the UK’s consumer-protection regime, including rules relating to unfair commercial practices. Ecommerce businesses should therefore avoid displaying misleading prices, fake or misleading reviews, hidden charges, deceptive countdown timers and other practices capable of influencing consumers unfairly.
  • Contractual rights: The Consumer Rights Act 2015 gives consumers statutory rights that website T&Cs cannot simply remove.
    • Goods must be of satisfactory quality, fit for a particular purpose made known to the trader and as described.
    • Services must be performed with reasonable care and skill, while digital content must also meet statutory standards.


Refunds, returns and cancellation
– these are governed by two different sets of rights that ecommerce businesses need to understand.

 

  • For many online purchases, the Consumer Contracts Regulations 2013 provide a 14-day cooling-off period because the purchase was made at a distance. For goods, the cancellation period will ordinarily run for 14 days from the day after the consumer receives the goods. There are exceptions – for example, certain personalised, perishable or sealed goods – so a blanket “14-day return on everything” statement isn’t quite accurate.
  • This cooling-off right is separate from the customer’s rights when something is faulty. Under the Consumer Rights Act 2015, consumers buying faulty goods can have much stronger rights. In particular, the Act establishes a 30-day short-term right to reject qualifying faulty goods and obtain a refund. Beyond that period, consumers may have rights to repair or replacement and, depending on the circumstances, a price reduction or final right to reject.

Data Protection & Privacy

Whilst the laws that govern data protection do overlap with consumer and user protection, they are more concerned with how data is used and kept secure as opposed to customer rights and purchase protection.

UK GDPR compliance

UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 primarily work to protect website users’ personal data. These have both been amended by the Data (Use and Access) Act 2025 (DUAA), although neither Act has been replaced.

UK GDPR becomes relevant whenever the website processes personal data – this can be as simple as a user filling in a simple form, or something as complex as an online purchase. There are many user events which fall under GDPR law so it is essential that all websites adhere to GDPR requirements.

In practical website terms, this means you should consider things such as:

  • Lawful basis: establish why you’re legally entitled to process each type of personal data. Consent is only one lawful basis; depending on the circumstances, contract, legal obligation or legitimate interests may be appropriate.
  • Privacy information: clearly tell users what information you collect, why you collect it, your lawful basis, who you share it with, how long you retain it and what rights individuals have.
  • Data minimisation: don’t make a website form collect information that isn’t genuinely required.
  • Security: use appropriate technical and organisational measures to protect personal information.
  • Retention: don’t keep website enquiries, abandoned accounts or other personal data indefinitely without justification.
  • Individual rights: have procedures for dealing with rights such as access, rectification, erasure, restriction and objection.
  • Third parties: understand where data goes when using CRMs, email marketing platforms, analytics services, payment processors, hosting providers and other integrations.
  • International transfers: check the rules if personal information is transferred outside the UK.
  • Accountability: document how and why personal information is processed rather than simply publishing a privacy policy and considering the job done.

Key resource: ICO Guide to the data protection principles

PECR compliance

The Privacy and Electronic Communications (EC Directive) Regulations 2013 (PECR) sit alongside UK GDPR as well as the Data Protection Act to outline legalities around tracking, cookies and electronic direct marketing such as texts and emails.

PECR mandates that users must be told about storage/access technologies, what they do and, unless an exception applies, prior consent meeting the UK GDPR standard must be obtained.

PECR guidance covers a wide range of electronic information and technologies including:

  • Cookies
  • Tracking pixels
  • Device fingerprinting technology
  • Web storage
  • Scripts
  • Tags
  • Navigation

In summary:

  • UK GDPR = what you’re allowed to do with people’s personal data.
  • PECR = specific privacy rules concerning electronic communications and technologies such as cookies/tracking.

Cookie policies and ensuring users consent to the use of cookies fall under the Privacy and Electronic Communications (EC Directive) Regulations 2013 (PECR) and the Data (Use and Access) Act 2025.

 

A cookie banner should do more than simply tell visitors that cookies are being used. Where consent is required, non-exempt cookies and tracking technologies should not be activated before the user has made a valid choice.

Marketing consent

“Marketing consent” refers to the act of ensuring that a user has clearly agreed that a business can use their contact details to send them direct marketing, such as promotional emails or text messages. It is important to obtain marketing consent, as collecting someone’s details through a website does not automatically give a business permission to send them marketing.

The legal requirements around obtaining marketing consent are governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), alongside the UK GDPR standard of consent. PECR is the main law for email and SMS marketing and requires either:

  • the recipient’s prior consent
  • the business to meet all the conditions of the soft opt-in exemption.

The “soft opt in” exemption allows a business, under certain circumstances, to send electronic marketing to someone without obtaining prior consent. This would be viable in scenarios such as:

  • the business obtained the person’s contact details during the course of a sale or negotiations for a sale;
  • the marketing concerns the business’s own similar products or services;
  • the person was given a simple opportunity to opt out when their details were collected
  • they are given a simple opportunity to opt out in every subsequent marketing communication.

It’s important to note that UK GDPR also states that users must be able to withdraw consent at any time. An obvious unsubscribe link is the normal solution in emails, texts and any other electronic communications.

Privacy policy / privacy notice

This is where you should state how the website collects, uses, stores and shares a user’s personal data, and what rights the business has over that data. The information contained in a privacy policy is governed by Articles 13 and 14 of UK GDPR as well as the Data Protection Act 2018.

Even very simple websites should have a clear and concise privacy policy or notice, as even a basic contact form acts as a way to capture user data.

Contact and enquiry forms

As with T&Cs, there is no specific law that covers contact forms, however the information they gather is governed by the laws as discussed above – UK GDPR and the Data Protection Act. It is important to follow the guidance set out as to the type of information that can be captured and why.

Contact forms should:

  • Only collect information the business actually needs. This follows the UK GDPR principle of data minimisation. If you only need a name, email and message to answer an enquiry, asking for date of birth or home address without a good reason would be difficult to justify.
  • Have a lawful basis for processing the information: This doesn’t necessarily mean asking the person to tick a GDPR consent box. Depending on the enquiry, legitimate interests or taking steps at the individual’s request before entering into a contract may be more appropriate.
  • Tell the person what will happen to their data. Relevant privacy information should be provided when the information is collected. In practice, this is why you’ll often see a short privacy statement and link to the full privacy notice immediately below a contact form.
  • Keep the information secure. UK GDPR requires appropriate technical and organisational security measures. This applies not just to the form itself, but also to where submissions subsequently go – for example, email inboxes, the website database or CRM.
  • Only retain information for as long as necessary. Form submissions shouldn’t simply remain stored indefinitely without a legitimate reason.
  • Be careful with third-party systems. If enquiries are automatically sent into a CRM, email platform or other service, the business needs to consider its data-protection responsibilities regarding those processors and any international transfers.

Third-party services and international data transfers

The laws around data concerning third-party services and international data transfers are mainly governed by UK GDPR and the Data Protection Act 2018, with important changes to the international-transfer regime made by the Data (Use and Access) Act 2025.

Third party services

Using third party services on your website, such as  live chat/chatbot services, CRM systems, embedded content, booking systems Google tracking cookies or payment processors mean that the data you are collecting could be at risk of being accessed by a different company.

Article 28 of UK GDPR requires an appropriate contract governing the processing. The controller must also use processors that provide sufficient guarantees that they can meet UK GDPR requirements.

International data transfers

There are adequacy arrangements, IDTA, UK Addendum and Binding Corporate Rules to bear in mind if your website allows UK personal data to be transferred overseas.

  • UK adequacy regulations mean the UK Government has formally decided that a particular country, territory, sector or international organisation provides an adequate level of protection for personal data. If the transfer is covered by an adequacy regulation, the organisation generally does not need an IDTA or transfer risk assessment for that transfer.
  • The International Data Transfer Agreement (IDTA) is a standard UK contract that can be put in place between the UK organisation sending personal data and the overseas recipient. It contains contractual protections intended to ensure that people’s information continues to receive an appropriate level of protection after leaving the UK.
  • The UK Addendum performs a similar role but is designed to be added to the EU Standard Contractual Clauses (EU SCCs). It is particularly useful where an organisation already uses the EU SCCs for European data transfers and also needs those arrangements to cover UK GDPR requirements.
  • Binding Corporate Rules (BCRs) are mainly relevant to large multinational groups. Rather than signing a separate standard contract for every internal international transfer, an international group can establish an approved set of legally binding data-protection rules covering transfers between companies within that group. They are therefore unlikely to be something the average small UK website owner deals with directly.

ICO registration/data protection fee

Not all businesses will have to pay this, however it will apply in cases where an organisation is acting as a data controller and processing personal information, unless one of the statutory exemptions applies.

In real world terms, a business is most likely to have to pay this fee is personal data is being used as part of providing services to individuals, maintaining customer or client records beyond basic accounting, operating CCTV for crime prevention, conducting research or profiling, or carrying out professional/advisory work involving personal information. The ICO says organisations, including sole traders, that use personal information generally need to pay unless exempt.

There are, however, important exemptions. If the organisation processes personal data only for specified purposes such as staff administration, its own advertising/marketing/public relations, or basic accounts and records, it may not have to pay the fee. If your website is basic, operates only a simple contact form, keeps customer details solely for internal use such as invoicing and staff details purely for internal admin/payroll, then you may be eligible for an exemption.

That being said, the wider activities of the business may still take it outside these exemptions. For example, the ICO specifically says CCTV used for crime prevention commonly triggers the fee, and many professional services processing clients’ personal information also need to pay. In short, businesses should assess all of their data-processing activities, not just those carried out through the website.

Key resource: ICO Information and communication sector page

Copyright law and intellectual property matter on a website because they determine what content you are legally allowed to publish and who owns the assets that make up the site. Website owners should only publish material that they own, or have permission to use, or are legally entitled to use with an accompanying licence or exception. Copyright infringement can result in fines that can be extensive, depending on circumstance.

For UK websites, the main law governing copyright is the Copyright, Designs and Patents Act 1988 (CDPA). It protects original literary, artistic, musical and other works, including many of the things that appear on websites such as written copy, photographs, illustrations, videos, graphics, software and databases. Copyright generally arises automatically; you do not have to register it in the UK.

Intellectual property goes beyond copyright and into registered trademarks, business names, logos and other registered brand identifiers. Registered trademarks are governed primarily by the Trade Marks Act 1994.

One particularly important issue at website launch is who actually owns commissioned content. If a freelancer, photographer, designer or developer has produced material for the website, paying for the work does not always automatically mean every underlying IP right has transferred to the business. Contracts should therefore make clear whether copyright is being assigned to the client or whether the client is being granted a licence to use the work.

Website accessibility

Website accessibility has long been an important aspect of making sales, however more recently it has also become something governed by UK law.

The requirements differ significantly between private-sector websites and public-sector websites, so skip to the section that best describes your business.

Private sector/business websites

The key legislation that governs website accessibility in the UK is the Equality Act 2010. It works to prohibit discrimination against disabled people and places service providers under a duty to make reasonable adjustments where disabled people would otherwise be placed at a substantial disadvantage. Government guidance also makes clear that service providers should anticipate barriers rather than simply wait for a disabled customer to complain.

For websites, this means businesses should consider whether aspects of their digital service create barriers for disabled users. Examples might include navigation that cannot be operated using a keyboard, forms that cannot be used with assistive technology, images conveying essential information without text alternatives, poor colour contrast, or video content without appropriate alternatives.

The Equality Act does not simply say “all private-sector websites must meet WCAG 2.2 AA.” The legal obligation is centred on avoiding disability discrimination and making reasonable adjustments. The explicit WCAG 2.2 AA requirement applies more directly to public-sector websites under separate regulations.

Public-sector websites

Public-sector organisations have much more explicit website requirements under the Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018.

Public-sector websites and mobile apps generally need to:

  • meet WCAG 2.2 Level AA
  • make their content perceivable, operable, understandable and robust
  • test and address accessibility problems
  • publish an accessibility statement explaining how accessible the website/app is
  • keep that statement reviewed and updated

These regulations work alongside the Equality Act 2010, rather than replacing it.

It must be noted here that not every website legally needs an accessibility statement, but public-sector websites covered by the 2018 Accessibility Regulations generally have a legal requirement to publish one.

How Page1st Can Help

We work with many clients who are launching new websites and need a little support to ensure they are not only technically sound but legally sound, too.

If you would like to chat a little more about your options, get in touch with us here

We also have a handy checklist you can download for free here.

Contact & Onwards

Worried your content might not be ticking all the right boxes?

Or just interested in learning more? Our highly skilled SEO team can help.

Putting your page.1st

© 2026  Page Online Marketing Agency

VAT: 15 44 20 338 | Registered: England No. 80 49 481

Website Development by OYNK