Most WordPress business sites are collecting personal data without the owner giving it much thought, a name and email on a contact form, an IP address logged by an analytics tool, a newsletter signup stored in a mailing list. None of that is a problem in itself. What matters is whether your site is set up to handle it lawfully, and whether you could show your working if the Information Commissioner’s Office ever asked.
The £17.5 million or 4% of global annual turnover figure is the statutory maximum under UK GDPR and the Data Protection Act 2018, set out directly by the regulator (ICO, maximum fine under UK GDPR and DPA 2018). In practice, very few businesses are ever fined anywhere near that. The ICO takes a proportionate approach with small organisations, but its own enforcement record shows it still hands out multi-million-pound penalties for security failures when something goes seriously wrong, so “we’re too small to matter” is not a safe assumption.
What Does UK GDPR Mean for Your WordPress Site?
UK GDPR applies to any UK business that collects or processes personal data, which covers virtually any page with a contact form, a cookie, a newsletter opt-in, or analytics tracking running in the background. Personal data includes names, email addresses, phone numbers, and IP addresses, effectively any information that can identify an individual. Unless your site is entirely static with no forms, no tracking, and no third-party scripts, UK GDPR applies to you.
GDPR and PECR: Two Regulations, Not One
This is a detail a lot of guides skip. UK businesses have to comply with two separate sets of rules: UK GDPR, and PECR, the Privacy and Electronic Communications Regulations. UK GDPR requires a lawful basis for processing personal data. PECR goes further for cookies specifically and requires explicit, informed consent before you set non-essential cookies on someone’s device, including analytics cookies such as Google Analytics, not just advertising trackers.
That means “by using this site you agree to cookies” buried in small print does not meet the PECR standard. Your cookie banner has to give visitors a genuine choice, and non-essential cookies have to stay blocked until they actively consent.
What Your WordPress Website Needs to Have
Here is what UK GDPR and PECR compliance actually looks like for a typical WordPress business site.
- A proper privacy policy. Explaining what data you collect, why, how long you keep it, and who you share it with. WordPress has a built-in generator under Settings > Privacy as a starting point, but it needs customising to cover every plugin and third-party service you actually use.
- A cookie consent banner that works. Non-essential cookies blocked until someone actively consents, with a genuine “reject all” or “manage preferences” option alongside “accept all”. Pre-ticked boxes or banners that only inform without offering a real choice don’t meet the PECR standard.
- Opt-in checkboxes on forms. Any marketing consent checkbox on a contact, booking or newsletter form must be unchecked by default. Burying agreement in your terms of service doesn’t count as consent.
- Data Processing Agreements with third parties. Every plugin or service that handles personal data on your behalf, Mailchimp, Google Analytics, Stripe and similar, is a “data processor” and needs a formal DPA, usually accepted through your account settings rather than assumed to be automatic.
- An SSL certificate. Encrypts data sent through your forms and is a baseline expectation from users and search engines alike. If your site still shows “http://” rather than “https://”, fix this first.
- Controlled access to your WordPress admin. Review your user list regularly and remove accounts belonging to former employees, past agencies, or developers who no longer work with you.
- A documented lawful basis for each type of data you collect. Contact form enquiries, newsletter signups and analytics tracking don’t all rely on the same lawful basis, and you should be able to say which applies to each.
- A data retention and deletion policy. Personal data shouldn’t sit in your database indefinitely. Decide how long you keep enquiry forms, old customer records and mailing list entries, and actually delete them once that period has passed.
If you already run a managed WordPress support service, ask whether these are being checked as part of your plan, since most maintenance contracts cover updates and backups but not privacy policy accuracy or DPA paperwork.
What the ICO Can Do If You Don’t Comply
The maximum fine under UK GDPR is £17.5 million or 4% of global annual turnover, whichever is higher (ICO, maximum fine under UK GDPR and DPA 2018). Independent analysis of the ICO’s 2025 enforcement record found it issued fewer penalties overall than the year before, but the fines it did issue for poor security following data breaches were substantially larger, with total penalties reaching roughly £21.7 million across the year, several times the total fined in 2024.
The pattern is consistent: the ICO takes a proportionate approach with small businesses that make a genuine effort and fix problems quickly, but it pursues organisations with known gaps that go unaddressed, particularly around security. Running a WordPress site that hasn’t been updated in months, with plugins known to have vulnerabilities and no privacy policy in place, is a hard position to defend if a breach happens and a complaint is made.
Data Breaches and Your 72-Hour Obligation
A data breach on your WordPress site is not just a technical headache. If personal data is exposed, you may have a legal obligation to report it to the ICO within 72 hours of becoming aware of it, and failing to report a reportable breach can be treated as a separate infringement on top of the original incident (ICO, 72 hours: how to respond to a personal data breach).
Keeping WordPress, your theme, and every plugin updated reduces this risk considerably. Most WordPress vulnerabilities that lead to breaches trace back to outdated, unpatched plugins. A managed WordPress support service handles those updates and monitors your site for unusual activity, so problems get caught before they turn into breaches. If your site has already been compromised, our WordPress malware removal service can help you recover, remove injected code, and get the site back to a clean state.
GDPR Compliance Is Not a One-Off Task
This is the part most businesses miss. Passing a review in January doesn’t mean you’re still compliant in November. New plugins, new forms, new marketing integrations, and changes to how you work with customers all introduce data processing activities that your privacy policy may not yet cover.
Every time you add something to your site that touches personal data, check two things: does your privacy policy reflect it, and do you have a DPA with the new provider. It takes minutes when you’re setting things up and considerably longer to untangle after the fact. A WordPress care plan covers routine maintenance, security updates and backups; pairing that with a periodic review of your data processing activities is a sensible approach for most UK small and medium-sized businesses. Data protection and cyber security overlap here too, since a large share of GDPR breaches start as a security incident rather than a paperwork failure.
Frequently Asked Questions
Does GDPR apply to my WordPress website if I don’t sell anything online?
Yes. If your site has a contact form, analytics tracking, or a newsletter signup, you’re collecting personal data and UK GDPR applies. The regulation isn’t limited to e-commerce; any website processing information about identifiable individuals is in scope.
Do I need a cookie consent banner on my WordPress site?
Yes. Under PECR, you must get explicit, informed consent before placing non-essential cookies on a visitor’s device. A banner that only informs visitors without offering a genuine accept or reject option doesn’t meet the standard. A dedicated cookie consent plugin is the most practical solution for most WordPress sites.
What counts as a data breach on a WordPress website?
Any security incident that leads to the accidental or unlawful destruction, loss, alteration, or disclosure of personal data. That includes a hacked site that exposed contact form submissions, a plugin vulnerability that leaked customer email addresses, or an admin account taken over by an attacker.
Do I need a Data Processing Agreement with every WordPress plugin I use?
Only with plugins or services that process personal data on your behalf, email marketing tools, analytics platforms, payment processors, and live chat systems, for example. Most reputable services offer a standard DPA that you formally accept, usually through your account settings.
Can the ICO fine a small UK business for GDPR non-compliance?
Yes, though it applies a proportionate approach. Small businesses that make a genuine effort to comply and respond quickly to problems are treated more leniently than those that ignore their obligations. If you know there are gaps on your site, addressing them now is the safer route.
Not Sure Your WordPress Site Is Compliant?
Get a free consultation and find out exactly where your site stands against UK GDPR and PECR, in plain English.
Getting your WordPress site GDPR-compliant doesn’t require a legal team or a large budget. It requires knowing what data you collect, being clear about it in your privacy policy, giving visitors a genuine choice about cookies, and keeping the site itself maintained and secure. Work through the eight items above, note what you can’t confidently tick, and use that as the brief for whoever handles your WordPress site next.


