Legal requirements for business websites in the UK


Originally published 2013 • Last updated August 2026

UK business websites are subject to a number of legal requirements: displaying your registered company information correctly, obtaining informed consent before setting non-essential cookies, publishing a privacy policy, and should you sell online then consumer protection rules covering everything from terms and conditions to genuine reviews.

When you commission a new website, compliance isn’t usually the first thing on your mind, nor should it have to be. That’s where we, along with other specialists, can advise.

Every website Rubber Duckiee builds is delivered with the functionality for you to abide by your legal obligations. Not as an add-on, but built in from the start, the way it should be. Here’s what that means in practice, what’s actually required, and why it matters to your organisation.

What your website needs to display

Every UK business website needs to make certain information easy to find; it doesn’t need to be on every page, but a footer or “About” / “Contact” page is the usual home for it:

  • Your registered company name, exactly as it appears at Companies House
  • Your company registration number
  • The part of the UK you’re registered in (England & Wales, Scotland, or Northern Ireland)
  • Your registered office address
  • A working contact method, this can be an email address, and ideally a phone number
  • Your VAT number, if you’re VAT registered
  • Details of any trade body or regulator you’re registered with, where relevant

Sole traders and partnerships should display the address of their main place of business instead of a registered office. This isn’t optional guidance; it’s set out under the Companies Act 2006 and the Electronic Commerce Regulations 2002. We tend to recommend this information is included in the footer so it’s easy to find, rather than buried in a page nobody visits.

The legal requirements for websites

Privacy Policy

While a website does not need its own privacy policy it is the place you should display your organisation’s privacy policy. This should cover: what data you collect, why you collect it, and what you do with it. This is a legal requirement under UK GDPR, not optional. We build your site so a privacy policy can be clearly displayed and properly linked to, and we’ll advise on what it needs to cover. Writing the policy itself is a job for your legal team or a specialist (we can recommend if you wish and the Information Commissioner’s Office has templates suitable for most SMEs), but we make sure the right structure is in place from day one.

Cookie Consent

If your website uses cookies, and these days it’s unusual not to then you need to obtain informed consent from visitors before those cookies are set. We build a compliant cookie banner into every site as standard, customised to match your brand so it feels like part of the design rather than an afterthought. You’re covered from day one. Find out more about how we handle cookies here.

Selling online: terms, consumer rights and genuine reviews

If your website sells products or services, a few extra requirements apply. You’ll need terms and conditions covering payment, delivery and returns, and liability as well as a clear returns/cancellation policy, since customers buying online have a legal right to cancel most orders within 14 days. Product and service descriptions need to be accurate, not just persuasive.

Since 2024, there’s also a specific rule worth knowing about: under the Digital Markets, Competition and Consumers Act, fake reviews and hidden incentives (among other things) for reviews are prohibited. If you publish reviews or feedback on your website then you’re obliged to have policies in place setting out how you prohibit fakes and, if you provide incentives for reviews how these are managed as well as take steps to prevent fake reviews appearing on your website.

For service-led organisations that don’t sell online, simpler terms of use which cover how your content can and can’t be used can still worth having. Drafting the terms themselves is something your legal advisers should own, but we’ll make sure the right pages exist and are properly linked so nothing’s buried or missing.

Accessibility

Public sector organisations are legally required to meet accessibility standards (known as WCAG 2.2 AA). For everyone else, it’s best practice, an increasing commercial expectation and, certainly for any organisation providing a service to the public still a legal duty not to discriminate against disabled users. We build to WCAG 2.2 AA as a baseline regardless of sector, because it’s the right way to build, not just a compliance minimum.

If you sell into the EU, the European Accessibility Act adds a further layer from 2025 onwards, covering things like e-commerce and digital services more explicitly. It’s a narrower requirement than it sounds for most UK-only businesses, but worth flagging if any part of your customer base is EU-based.

In practice, meeting a proper standard means things like: every image built with working alt text so it can be described to screen readers, colour contrast checked against the standard, and full keyboard navigation alongside mouse. It’s the kind of detail that’s invisible when it’s done right, and a problem when it isn’t.

Legal Notice and site security

Beyond the registered information above, an SSL certificate is a baseline security requirement, a Google ranking signal, and a visible trust marker (that padlock in the browser bar), every site we deliver is secured with SSL as standard.

Staying compliant after launch

GDPR guidance evolves, accessibility standards update, consumer protection rules tighten. As your web partner, we’ll keep an eye on what’s changing and flag anything that might affect your site and which your organisation should be aware of.

Common questions
  1. Does every website need a privacy policy? If you collect any personal data, even just through a contact form, yes. Most websites do this without realising it.
  2. Do I need cookie con sent if I only use analytics cookies? Generally yes, unless the cookie is strictly necessary for a service the visitor has directly requested (like remembering items in a basket). Analytics cookies almost always require consent.
  3. What happens if my website isn’t compliant? This very much depends with what you’re not compliant with.  A complaint can trigger an ICO enquiry, a customer dispute can escalate faster without the right terms in place, and accessibility gaps can turn into lost business quietly, without ever being reported.
  4. Do I need to worry about this if I’m a small business? Yes, is the short answer here. Company registration disclosures, privacy notices and cookie consent apply regardless of size. The scale of what’s required grows with what your site does (selling online, collecting more data), not with how big your business is.

The bottom line

You hired a web partner because you want things done properly. That means delivering a website that performs well, looks right, and doesn’t needlessly expose your organisation to legal or reputational risk.

We’re not lawyers, and we always recommend taking legal advice specific to your organisation and sector. What we can do is make you aware of what you need to know long before your site goes live so you have one less thing on your plate.

Get in touch to talk about your website.