Start your 7-day free trial, card not charged until it ends

Compliance

Website Compliance in Plain English: What to Check and How to Keep Checking

· 9 min read

Compliance is not a launch-day checkbox, it is a state websites drift out of silently. What UK law actually expects from your site, and which checks you can automate.

By the TLDTrack team, part of FullyCoded, a working UK web agency.

Website compliance has a reputation as a launch-day chore: write the privacy policy, add the cookie banner, tick the box, move on. The reality is less convenient. Compliance is a state your website is in, and websites drift out of it constantly, quietly, and without anyone deciding to. A new marketing tag sneaks past the cookie banner. A redesign loses the terms page. A form starts collecting emails with no privacy notice in sight.

This guide covers what website compliance actually involves for a UK business, in plain English, why sites fall out of compliance after launch, and which checks can be automated so it stays handled. One honest caveat before we start: this is practical guidance, not legal advice; for anything high-stakes, talk to a solicitor.

What "website compliance" actually covers

Privacy and data protection (UK GDPR)

If your website collects any personal data, and analytics, contact forms and newsletter signups all count, you need a privacy policy that says what you collect, why, on what lawful basis, how long you keep it, and how people can exercise their rights. It needs to be findable, current, and accurate about what the site really does. Most organisations processing personal data also need to be registered with the ICO and pay the data protection fee; it is a small annual cost and an easy thing to let lapse.

Cookies and consent (PECR)

UK rules are stricter than most cookie banners suggest: non-essential cookies and trackers must not fire until the visitor consents. That means analytics and advertising scripts load after the Accept click, not before; rejecting must be as easy as accepting; and pre-ticked boxes do not count as consent. The ICO has been increasingly vocal about non-compliant banners, and this is the compliance area where drift is almost guaranteed, because every new tag added to the site is a fresh chance to bypass the consent gate.

Company information (Companies Act 2006)

A UK limited company's website must state the registered company name, company number, registered office address and place of registration, and VAT-registered businesses should show the VAT number. Somewhere findable, the footer is the convention. It is the easiest requirement on this list and one of the most commonly missed, especially after redesigns.

Selling online (consumer law)

E-commerce adds a layer: clear total pricing including VAT and delivery, honest delivery times, and the information the Consumer Contracts Regulations require, including the 14-day cancellation right for most distance sales and how to exercise it. Get the cancellation information wrong and the window extends dramatically in the customer's favour.

Accessibility

The Equality Act 2010 expects reasonable adjustments so disabled users are not locked out, and WCAG 2.2 AA is the de facto benchmark for what "accessible" means. Public sector sites have explicit legal duties, and if you sell into the EU, the European Accessibility Act has applied to many consumer-facing digital services since June 2025. Beyond risk, the practical case is simple: accessible sites work better for everyone and tend to rank better too.

Security as a legal duty

UK GDPR requires "appropriate technical and organisational measures" to protect personal data. In website terms that starts with working HTTPS, patched software and no known malware. An expired certificate or a compromised CMS is not just an operational failure; on a site that handles personal data it is a compliance failure as well.

Why compliant websites stop being compliant

  • New trackers bypass the consent banner. Someone adds a pixel for a campaign, pastes it into the template, and it fires before consent. The banner still looks fine; the site is no longer compliant.
  • The banner itself breaks. A JavaScript error stops the consent gate working, and every script loads unconditionally. Nobody notices, because the page looks normal.
  • Redesigns lose pages. Privacy policy and terms URLs change or vanish, and every link to them 404s.
  • Policies go stale. The site starts using a new CRM, chat widget or analytics tool, and the privacy policy still describes the stack from two years ago.
  • Forms appear without notices. A landing-page builder makes it easy to ship a new lead form, and no one adds the privacy information.
  • Details rot. The company moves office, the footer does not. The ICO registration quietly expires.

The pattern is the same one we keep meeting across content monitoring and DNS: the change is silent, and the symptom, if one ever appears, shows up somewhere else, months later, as a complaint, a regulator letter or a lost deal with a due-diligence checklist.

What an automated checking tool can (and cannot) do

No tool can read a privacy policy and certify it lawful; that judgement stays human. What automation does brilliantly is watch for the drift, the gap between the compliant site you launched and the site that exists today:

  • Key pages exist and say what they must. Content rules that check the privacy policy and terms pages are reachable and that required text, the company number, the VAT number, the cancellation notice, is still present. This is exactly what content monitoring rules are for.
  • Tracker inventory. A continuously updated list of which scripts and trackers each page loads, with an alert when a new one appears. That alert is your cue to check consent gating and update the privacy policy while the change is one day old, not one audit cycle old.
  • Client-side error monitoring. JavaScript errors on pages with a consent banner are exactly how you find out the banner broke before the regulator-relevant weeks pass.
  • Security basics on watch. Certificate expiry warnings weeks ahead, malware and blacklist checks, and scheduled security scans covering the "appropriate measures" baseline.
  • Change alerts on legal pages. Any edit to the privacy policy or terms triggers a notification, so accidental deletions and unauthorised changes surface immediately.

TLDTrack runs all of the above across every site you add, which for an agency is the difference between "we checked compliance at launch" and "we can show you what changed, and when, on every client site". That evidence trail matters: demonstrating you monitor and respond is itself part of what regulators look for.

A practical starting checklist

  1. Privacy policy: present, linked site-wide, and accurate about today's tools and forms.
  2. Cookie banner: nothing non-essential fires before consent, reject is one click, and consent actually gates the scripts (test it, do not trust it).
  3. Footer: registered name, company number, registered office, VAT number.
  4. ICO registration: current, renewal date diarised.
  5. Selling online: pricing, delivery and cancellation information matching the regulations.
  6. Accessibility: run an automated WCAG scan for the obvious issues, then fix the biggest human-verified ones (alt text, contrast, keyboard navigation).
  7. HTTPS everywhere, certificate expiry monitored.
  8. Put the drift on watch: content rules on legal pages, tracker-change alerts, error monitoring, so points 1 to 7 stay true without a quarterly panic.

Compliance done once is a snapshot. Compliance monitored is a state. If you look after client sites, fold these checks into the same monitoring stack as everything else, it is the same discipline we describe in our complete guide to monitoring client websites, pointed at the pages your clients' lawyers care about.

01 · Questions

Frequently asked questions

What happens if a website isn't GDPR compliant?

Enforcement is a ladder, not a lightning bolt. The ICO typically starts with guidance, reprimands and enforcement notices, with fines reserved for serious or persistent failures, though those can reach 17.5 million GBP or 4 percent of global turnover. The more common real-world costs are complaints, reputational damage, failed due-diligence when a bigger customer audits you, and private claims from affected individuals.

Do small businesses have to comply with these rules?

Yes. UK GDPR, PECR cookie rules and the Companies Act website disclosure requirements apply regardless of company size, and most organisations processing personal data owe the ICO data protection fee (tiered, starting around 40 GBP a year). Enforcement is proportionate to risk and scale, but "we are a small business" is not an exemption from any of it.

How often should website compliance be reviewed?

A deliberate review once a year, plus an immediate one whenever something material changes: a new form, a new tracking or marketing tool, a redesign, or a new way of using customer data. Between reviews, automated monitoring covers the drift, alerting you when trackers appear, legal pages change or the consent banner breaks, so the annual review confirms compliance rather than rediscovering it.
Mark Grice, founder of TLDTrack

Mark Grice, founder of TLDTrack. Runs FullyCoded, a Cornwall web agency, and built this to keep 500+ client sites in front of him every day.

What happens next

Put this on autopilot

Do it yourself

Start your free trial

TLDTrack runs every check in this guide automatically across all your client sites and alerts you the moment something changes. Your card is not charged for 7 days.

Start your free trial

Talk it through

Arrange a call with Mark

If you would rather talk through how this works across every site you look after, we can go through it together.

Book a call

See every check TLDTrack runs