Free initial consultation · Flexible ongoing and project-based services Speak to our team: 020 3048 4048

WordPress GDPR Compliance: What UK Businesses Need to Have in Place

By Published 1 July 2026 9 min read
Quick answer: If your WordPress site has a contact form, cookies, analytics, or a newsletter signup, UK GDPR and PECR both apply to it. Compliance means having eight things in place: a proper privacy policy, working cookie consent, opt-in checkboxes, data processing agreements, an SSL certificate, controlled admin access, a documented lawful basis for the data you collect, and a retention and deletion policy. None of it needs a legal team, but it does need to actually be checked rather than assumed.

Most WordPress business sites are collecting personal data without the owner giving it much thought, a name and email on a contact form, an IP address logged by an analytics tool, a newsletter signup stored in a mailing list. None of that is a problem in itself. What matters is whether your site is set up to handle it lawfully, and whether you could show your working if the Information Commissioner’s Office ever asked.

£17.5m or 4%maximum UK GDPR fine, whichever is higher
72 hoursdeadline to report a reportable breach to the ICO
8core requirements for a typical WordPress business site
Ongoingcompliance is a maintained state, not a one-off task

The £17.5 million or 4% of global annual turnover figure is the statutory maximum under UK GDPR and the Data Protection Act 2018, set out directly by the regulator (ICO, maximum fine under UK GDPR and DPA 2018). In practice, very few businesses are ever fined anywhere near that. The ICO takes a proportionate approach with small organisations, but its own enforcement record shows it still hands out multi-million-pound penalties for security failures when something goes seriously wrong, so “we’re too small to matter” is not a safe assumption.

What Does UK GDPR Mean for Your WordPress Site?

UK GDPR applies to any UK business that collects or processes personal data, which covers virtually any page with a contact form, a cookie, a newsletter opt-in, or analytics tracking running in the background. Personal data includes names, email addresses, phone numbers, and IP addresses, effectively any information that can identify an individual. Unless your site is entirely static with no forms, no tracking, and no third-party scripts, UK GDPR applies to you.

GDPR and PECR: Two Regulations, Not One

This is a detail a lot of guides skip. UK businesses have to comply with two separate sets of rules: UK GDPR, and PECR, the Privacy and Electronic Communications Regulations. UK GDPR requires a lawful basis for processing personal data. PECR goes further for cookies specifically and requires explicit, informed consent before you set non-essential cookies on someone’s device, including analytics cookies such as Google Analytics, not just advertising trackers.

That means “by using this site you agree to cookies” buried in small print does not meet the PECR standard. Your cookie banner has to give visitors a genuine choice, and non-essential cookies have to stay blocked until they actively consent.

What Your WordPress Website Needs to Have

Here is what UK GDPR and PECR compliance actually looks like for a typical WordPress business site.

  • A proper privacy policy. Explaining what data you collect, why, how long you keep it, and who you share it with. WordPress has a built-in generator under Settings > Privacy as a starting point, but it needs customising to cover every plugin and third-party service you actually use.
  • A cookie consent banner that works. Non-essential cookies blocked until someone actively consents, with a genuine “reject all” or “manage preferences” option alongside “accept all”. Pre-ticked boxes or banners that only inform without offering a real choice don’t meet the PECR standard.
  • Opt-in checkboxes on forms. Any marketing consent checkbox on a contact, booking or newsletter form must be unchecked by default. Burying agreement in your terms of service doesn’t count as consent.
  • Data Processing Agreements with third parties. Every plugin or service that handles personal data on your behalf, Mailchimp, Google Analytics, Stripe and similar, is a “data processor” and needs a formal DPA, usually accepted through your account settings rather than assumed to be automatic.
  • An SSL certificate. Encrypts data sent through your forms and is a baseline expectation from users and search engines alike. If your site still shows “http://” rather than “https://”, fix this first.
  • Controlled access to your WordPress admin. Review your user list regularly and remove accounts belonging to former employees, past agencies, or developers who no longer work with you.
  • A documented lawful basis for each type of data you collect. Contact form enquiries, newsletter signups and analytics tracking don’t all rely on the same lawful basis, and you should be able to say which applies to each.
  • A data retention and deletion policy. Personal data shouldn’t sit in your database indefinitely. Decide how long you keep enquiry forms, old customer records and mailing list entries, and actually delete them once that period has passed.

If you already run a managed WordPress support service, ask whether these are being checked as part of your plan, since most maintenance contracts cover updates and backups but not privacy policy accuracy or DPA paperwork.

Where businesses usually fall down: Not the privacy policy or the cookie banner, both are easy to set up once and forget about. It’s DPAs and lawful basis documentation, because nobody revisits them when a new plugin or marketing tool gets added six months later.

What the ICO Can Do If You Don’t Comply

The maximum fine under UK GDPR is £17.5 million or 4% of global annual turnover, whichever is higher (ICO, maximum fine under UK GDPR and DPA 2018). Independent analysis of the ICO’s 2025 enforcement record found it issued fewer penalties overall than the year before, but the fines it did issue for poor security following data breaches were substantially larger, with total penalties reaching roughly £21.7 million across the year, several times the total fined in 2024.

The pattern is consistent: the ICO takes a proportionate approach with small businesses that make a genuine effort and fix problems quickly, but it pursues organisations with known gaps that go unaddressed, particularly around security. Running a WordPress site that hasn’t been updated in months, with plugins known to have vulnerabilities and no privacy policy in place, is a hard position to defend if a breach happens and a complaint is made.

Data Breaches and Your 72-Hour Obligation

A data breach on your WordPress site is not just a technical headache. If personal data is exposed, you may have a legal obligation to report it to the ICO within 72 hours of becoming aware of it, and failing to report a reportable breach can be treated as a separate infringement on top of the original incident (ICO, 72 hours: how to respond to a personal data breach).

Keeping WordPress, your theme, and every plugin updated reduces this risk considerably. Most WordPress vulnerabilities that lead to breaches trace back to outdated, unpatched plugins. A managed WordPress support service handles those updates and monitors your site for unusual activity, so problems get caught before they turn into breaches. If your site has already been compromised, our WordPress malware removal service can help you recover, remove injected code, and get the site back to a clean state.

GDPR Compliance Is Not a One-Off Task

This is the part most businesses miss. Passing a review in January doesn’t mean you’re still compliant in November. New plugins, new forms, new marketing integrations, and changes to how you work with customers all introduce data processing activities that your privacy policy may not yet cover.

Every time you add something to your site that touches personal data, check two things: does your privacy policy reflect it, and do you have a DPA with the new provider. It takes minutes when you’re setting things up and considerably longer to untangle after the fact. A WordPress care plan covers routine maintenance, security updates and backups; pairing that with a periodic review of your data processing activities is a sensible approach for most UK small and medium-sized businesses. Data protection and cyber security overlap here too, since a large share of GDPR breaches start as a security incident rather than a paperwork failure.

Frequently Asked Questions

Does GDPR apply to my WordPress website if I don’t sell anything online?

Yes. If your site has a contact form, analytics tracking, or a newsletter signup, you’re collecting personal data and UK GDPR applies. The regulation isn’t limited to e-commerce; any website processing information about identifiable individuals is in scope.

Do I need a cookie consent banner on my WordPress site?

Yes. Under PECR, you must get explicit, informed consent before placing non-essential cookies on a visitor’s device. A banner that only informs visitors without offering a genuine accept or reject option doesn’t meet the standard. A dedicated cookie consent plugin is the most practical solution for most WordPress sites.

What counts as a data breach on a WordPress website?

Any security incident that leads to the accidental or unlawful destruction, loss, alteration, or disclosure of personal data. That includes a hacked site that exposed contact form submissions, a plugin vulnerability that leaked customer email addresses, or an admin account taken over by an attacker.

Do I need a Data Processing Agreement with every WordPress plugin I use?

Only with plugins or services that process personal data on your behalf, email marketing tools, analytics platforms, payment processors, and live chat systems, for example. Most reputable services offer a standard DPA that you formally accept, usually through your account settings.

Can the ICO fine a small UK business for GDPR non-compliance?

Yes, though it applies a proportionate approach. Small businesses that make a genuine effort to comply and respond quickly to problems are treated more leniently than those that ignore their obligations. If you know there are gaps on your site, addressing them now is the safer route.

Not Sure Your WordPress Site Is Compliant?

Get a free consultation and find out exactly where your site stands against UK GDPR and PECR, in plain English.

Get a Free Consultation

Getting your WordPress site GDPR-compliant doesn’t require a legal team or a large budget. It requires knowing what data you collect, being clear about it in your privacy policy, giving visitors a genuine choice about cookies, and keeping the site itself maintained and secure. Work through the eight items above, note what you can’t confidently tick, and use that as the brief for whoever handles your WordPress site next.

About the author

Kevin Marshal

Kevin Marshal is a content writer at UK IT Services, a UK-based IT support, cyber security and digital agency. He turns complex technology topics into clear, practical guidance that business owners and decision-makers can actually use. Drawing on the expertise of the wider UK IT Services team, Kevin writes about managed IT support, cyber security, Microsoft 365, web design and development, and digital marketing, always with a focus on what works for small and medium-sized UK businesses. His goal is simple: help organisations make smarter, safer technology decisions without the jargon.

Latest insights

Talk to a UK-based IT specialist

Managed IT support, cyber security and digital services for businesses across the UK.

Get a Free Consultation
Call Us Free Consultation