Since Brexit, UK websites follow their own versions of the EU rules: UK GDPR and the Data Protection Act 2018 for personal data, and the Privacy and Electronic Communications Regulations (PECR) for cookies. The Information Commissioner’s Office (ICO) enforces both, and the Data (Use and Access) Act 2025 updated them again.
Here is what that means for a WordPress site, and what to check. For the shared basics of consent banners and privacy notices, see our guide to GDPR and cookie compliance.
How UK Rules Differ From the EU’s
UK GDPR still mirrors the EU GDPR closely: the same principles, the same rights for individuals and the same 72-hour breach reporting window. The differences are in the details. Your regulator is the ICO, many organizations that process personal data must pay the ICO a data protection fee, and the 2025 Act changed some rules on cookies, research and automated decisions.
If you also sell to EU customers, the EU rules apply to them as well. In practice, most UK businesses build to the stricter of the two.
Cookies Under PECR
PECR requires consent before you set any cookie that isn’t strictly necessary. A shopping basket or a login session doesn’t need consent; advertising and most tracking do. The ICO’s cookie guidance explains what counts as strictly necessary.
The Data (Use and Access) Act 2025 added limited exceptions for some low-risk cookies, such as certain analytics, as long as visitors get clear information and an easy way to object. Advertising and cross-site tracking still need consent. Check the ICO’s current guidance before you relax your banner.
To audit your own site, open it in a private browser window, then use the developer tools under Application > Cookies. Anything beyond essential cookies that appears before you click Accept is a problem.
Personal Data in WordPress
Contact form entries, WooCommerce orders, user accounts and security logs all hold personal data, and backups copy it. Use Tools > Export Personal Data and Tools > Erase Personal Data to handle requests, and delete old entries you no longer need.
Anyone who can access that data on your behalf, including your host and maintenance provider, should be covered by a written data processing agreement. Ask for one before granting admin access.
Reporting a Breach Within 72 Hours
A personal data breach that risks people’s rights must generally be reported to the ICO within 72 hours of you becoming aware of it. On WordPress, that means knowing quickly when something is wrong: security monitoring, activity logs and recent backups. If it happens, our guide to what to do in the first two hours helps.
Accessibility and the Equality Act
The Equality Act 2010 requires reasonable adjustments for disabled people, and that includes websites that serve customers. Public sector sites must meet WCAG 2.2 Level AA, which is a sensible target for private businesses too. Our practical WCAG guide covers the most common WordPress fixes.
Frequently Asked Questions
Do I still need a cookie banner in the UK?
Yes, if you use any cookies beyond strictly necessary ones, such as advertising pixels. The 2025 changes eased consent for some low-risk analytics, not for marketing.
Do I have to pay the ICO a fee?
Most organizations that process personal data must, unless they are exempt. The ICO website has a short self-assessment.
Does UK GDPR apply to a small business website?
Yes. There is no small-business exemption for collecting personal data, although the ICO expects measures proportionate to your size and risk.
What is the most common cookie mistake?
Marketing tags added through a tag manager or plugin that fire before consent. Re-check after every new tracking tool.
What to Do This Week
- Load your site in a private window and check which cookies appear before consent.
- Confirm whether you need to pay the ICO data protection fee.
- Set a retention period for form entries and delete older ones.
- Test your main pages and forms with only a keyboard.
Our managed WordPress maintenance keeps the updates, backups and monitoring behind all of this running, or start with a free site audit.
This article explains the technical side for website owners. It isn’t legal advice; for decisions about your own obligations, talk to a qualified adviser.
Get a free audit covering security, updates, backups, and performance gaps. Takes 60 seconds to request and costs nothing.
