Website compliance has a reputation as a launch-day chore: write the privacy policy, add the cookie banner, tick the box, move on. The reality is less convenient. Compliance is a state your website is in, and websites drift out of it constantly, quietly, and without anyone deciding to. A new marketing tag sneaks past the cookie banner. A redesign loses the terms page. A form starts collecting emails with no privacy notice in sight.
This guide covers what website compliance actually involves for a UK business, in plain English, why sites fall out of compliance after launch, and which checks can be automated so it stays handled. One honest caveat before we start: this is practical guidance, not legal advice; for anything high-stakes, talk to a solicitor.
What "website compliance" actually covers
Privacy and data protection (UK GDPR)
If your website collects any personal data, and analytics, contact forms and newsletter signups all count, you need a privacy policy that says what you collect, why, on what lawful basis, how long you keep it, and how people can exercise their rights. It needs to be findable, current, and accurate about what the site really does. Most organisations processing personal data also need to be registered with the ICO and pay the data protection fee; it is a small annual cost and an easy thing to let lapse.
Cookies and consent (PECR)
UK rules are stricter than most cookie banners suggest: non-essential cookies and trackers must not fire until the visitor consents. That means analytics and advertising scripts load after the Accept click, not before; rejecting must be as easy as accepting; and pre-ticked boxes do not count as consent. The ICO has been increasingly vocal about non-compliant banners, and this is the compliance area where drift is almost guaranteed, because every new tag added to the site is a fresh chance to bypass the consent gate.
Company information (Companies Act 2006)
A UK limited company's website must state the registered company name, company number, registered office address and place of registration, and VAT-registered businesses should show the VAT number. Somewhere findable, the footer is the convention. It is the easiest requirement on this list and one of the most commonly missed, especially after redesigns.
Selling online (consumer law)
E-commerce adds a layer: clear total pricing including VAT and delivery, honest delivery times, and the information the Consumer Contracts Regulations require, including the 14-day cancellation right for most distance sales and how to exercise it. Get the cancellation information wrong and the window extends dramatically in the customer's favour.
Accessibility
The Equality Act 2010 expects reasonable adjustments so disabled users are not locked out, and WCAG 2.2 AA is the de facto benchmark for what "accessible" means. Public sector sites have explicit legal duties, and if you sell into the EU, the European Accessibility Act has applied to many consumer-facing digital services since June 2025. Beyond risk, the practical case is simple: accessible sites work better for everyone and tend to rank better too.
Security as a legal duty
UK GDPR requires "appropriate technical and organisational measures" to protect personal data. In website terms that starts with working HTTPS, patched software and no known malware. An expired certificate or a compromised CMS is not just an operational failure; on a site that handles personal data it is a compliance failure as well.
Why compliant websites stop being compliant
- New trackers bypass the consent banner. Someone adds a pixel for a campaign, pastes it into the template, and it fires before consent. The banner still looks fine; the site is no longer compliant.
- The banner itself breaks. A JavaScript error stops the consent gate working, and every script loads unconditionally. Nobody notices, because the page looks normal.
- Redesigns lose pages. Privacy policy and terms URLs change or vanish, and every link to them 404s.
- Policies go stale. The site starts using a new CRM, chat widget or analytics tool, and the privacy policy still describes the stack from two years ago.
- Forms appear without notices. A landing-page builder makes it easy to ship a new lead form, and no one adds the privacy information.
- Details rot. The company moves office, the footer does not. The ICO registration quietly expires.
The pattern is the same one we keep meeting across content monitoring and DNS: the change is silent, and the symptom, if one ever appears, shows up somewhere else, months later, as a complaint, a regulator letter or a lost deal with a due-diligence checklist.
What an automated checking tool can (and cannot) do
No tool can read a privacy policy and certify it lawful; that judgement stays human. What automation does brilliantly is watch for the drift, the gap between the compliant site you launched and the site that exists today:
- Key pages exist and say what they must. Content rules that check the privacy policy and terms pages are reachable and that required text, the company number, the VAT number, the cancellation notice, is still present. This is exactly what content monitoring rules are for.
- Tracker inventory. A continuously updated list of which scripts and trackers each page loads, with an alert when a new one appears. That alert is your cue to check consent gating and update the privacy policy while the change is one day old, not one audit cycle old.
- Client-side error monitoring. JavaScript errors on pages with a consent banner are exactly how you find out the banner broke before the regulator-relevant weeks pass.
- Security basics on watch. Certificate expiry warnings weeks ahead, malware and blacklist checks, and scheduled security scans covering the "appropriate measures" baseline.
- Change alerts on legal pages. Any edit to the privacy policy or terms triggers a notification, so accidental deletions and unauthorised changes surface immediately.
TLDTrack runs all of the above across every site you add, which for an agency is the difference between "we checked compliance at launch" and "we can show you what changed, and when, on every client site". That evidence trail matters: demonstrating you monitor and respond is itself part of what regulators look for.
A practical starting checklist
- Privacy policy: present, linked site-wide, and accurate about today's tools and forms.
- Cookie banner: nothing non-essential fires before consent, reject is one click, and consent actually gates the scripts (test it, do not trust it).
- Footer: registered name, company number, registered office, VAT number.
- ICO registration: current, renewal date diarised.
- Selling online: pricing, delivery and cancellation information matching the regulations.
- Accessibility: run an automated WCAG scan for the obvious issues, then fix the biggest human-verified ones (alt text, contrast, keyboard navigation).
- HTTPS everywhere, certificate expiry monitored.
- Put the drift on watch: content rules on legal pages, tracker-change alerts, error monitoring, so points 1 to 7 stay true without a quarterly panic.
Compliance done once is a snapshot. Compliance monitored is a state. If you look after client sites, fold these checks into the same monitoring stack as everything else, it is the same discipline we describe in our complete guide to monitoring client websites, pointed at the pages your clients' lawyers care about.
