Case study

Website rules check: is your website following the UK rules?

In short: A plain-English check of a website against the UK rules on privacy, cookies, accessibility, consumer law and company details, with my own site as the example.

Illustration of a laptop with a magnifying glass, a ticked checklist, a padlock, a cookie and an accessibility badge

The problem

Most small business owners know there are rules about websites. Fewer know exactly what they are, and almost nobody has time to keep up as they change. In 2026 alone, the cookie rules changed, a new duty on handling data protection complaints came in, and the regulators kept a close eye on hidden charges and fake reviews.

The trouble is that the rules don't sit in one place. Privacy is one set of rules, cookies another, accessibility another, consumer law another, and company law has its own requirements about what a limited company must show online. A website can look lovely and still fall short on several of them, and the owner is usually the last to know.

I've spent 20 years in e-commerce, much of it around big retailers, where getting this right isn't optional. I wanted to bring the same care to small businesses, explained in plain words and without the scare stories.

What I built

The website rules check works through a site area by area, then gives the owner two things: a short, plain-English summary of where they stand, and a fix list in priority order. Once fixes are made, I check again against that list. Behind it, I keep a dated summary of the current UK rules and refresh it at least every 30 days, so the check reflects the rules as they are now, not as they were when someone last wrote a blog post.

Here's what it looks at, using serva.digital as the example.

Privacy (UK GDPR). Does the privacy policy say who is responsible for your data, what is collected, why, and for how long? Does it explain how to complain? Since June 2026, businesses have had to give people a way to complain to them directly about how their data is handled, and to acknowledge a complaint within 30 days. On serva.digital, the privacy policy names the company responsible, gives its registration with the Information Commissioner's Office (ICO), explains how to complain, promises an acknowledgement within 30 days and points to the ICO. The enquiry form says up front how long details are kept.

Cookies. Does the site set cookies before asking, and is any cookie banner honest? The simplest answer is often to need fewer cookies. serva.digital uses no tracking cookies at all, so there's no cookie banner to click through. Visits are counted without cookies, fonts are hosted on the site itself, and there are no embedded maps, videos or social media feeds quietly setting cookies of their own. The one cookie that can appear is a strictly necessary security cookie, and the cookie policy lists it.

Accessibility. Can everyone use the site, including people who use a keyboard instead of a mouse, a screen reader, or a very large text size? The benchmark is WCAG 2.2 AA, the recognised standard for accessible websites. serva.digital has an accessibility statement covering keyboard access, a "skip to content" link, colour contrast, labelled form fields, pages that still work when zoomed right in, and respect for people who prefer less motion. It's also honest about what isn't perfect yet: some looping illustrations don't have a pause button, and the checks so far are my own rather than an independent audit. Saying so plainly is part of doing it properly.

Consumer and business law. Are prices and terms clear, with no surprise extras added at the end? Are reviews genuine and presented fairly? serva.digital has plain-English terms and separate offer terms that set out what's included and what isn't.

Company information. A limited company's website must show certain details, such as its registered name and company number, where it's registered and its registered office address. serva.digital is a trading name, so the footer on every page says which company is behind it, where it's registered, its company number and its ICO registration, and the legal pages carry the full company details.

How it's going

My own website is the first site I hold to this standard, and I keep it there: the cookie policy, privacy policy and accessibility statement are all dated and kept up to date. I now offer the same check to other businesses, often alongside a website review, and I use it on every site I build before it goes live. The pub, restaurant and cleaning business websites on this page were all built to pass it.

See it live

My own cookie policy, the worked example, on a laptop and a phone.

The serva.digital cookie policy on a laptop: "Short answer: no tracking cookies, so no cookie banner."
The serva.digital cookie policy on a phone

Want something like this?

If you're not sure whether your website follows the UK rules, I'll check it and tell you in plain English what's fine, what needs fixing and what can wait. I'm not a solicitor, and if something needs proper legal advice I'll say so. Book a website review, or get in touch for a no-obligation chat.

Get in touch

More of my work

See all my work