This week I was up in Edinburgh with my family. On our last evening we wanted some wine for dinner, so I wandered into a small independent wine merchant near where we were staying — the kind of shop where the owner knows every bottle on the shelf. He pointed me to a lovely 2024 Côtes du Rhône, and while he wrapped it we got chatting about the business. He clearly loves it, and like a lot of good small operators he has built a proper marketing engine on the side: a mailing list of around 800 people who get an email most weeks about a tasting or a case worth grabbing. When privacy came up — because of what I do, it always does — he gave me the answer I hear almost every time. He knows the rules exist. It just lives permanently near the bottom of the list, under stock, staff, and everything else that keeps the lights on.
I wasn't there to audit his shop, and I did not. But the story he told me is one I hear constantly, and the pattern behind it sits on almost every small-business site I look at. If it is yours too, you are normal — and also, quietly, a little exposed. Not because you have been reckless, but because the setup nearly every small business starts with has three small gaps in it. The good news, and the reason I wanted to write this: closing them is not a mega-project. It is four cheap fixes, most done in an afternoon.
What a two-minute look usually finds
You do not need an audit to spot the pattern. Look at almost any small-business website — a café, a florist, a physio, a wine shop — and you tend to find the same three things:
- A privacy notice that is still the template. The privacy policy page on your site (its proper name is a "privacy notice") is the unedited boilerplate your website builder or a WordPress plugin dropped in on day one. It does not mention your mailing list or your analytics, and it may still name a company that is not even yours.
- Analytics running with no cookie banner. Google Analytics is firing the moment someone lands, before they have been asked anything.
- A newsletter signup with no consent step. People hand over an email for 10% off or "news and offers," and get added to the list, with nothing recording what they agreed to.
None of this makes you a villain. It makes you a busy owner who set the site up once and moved on. But two of those three gaps sit in the exact areas the UK regulator, the ICO, pays the most attention to: email marketing and cookies.
The mailing list is the real risk
Here is the part most small businesses get wrong without realising, because the rule is genuinely a bit fiddly.
UK marketing emails are governed by PECR (the Privacy and Electronic Communications Regulations). Under PECR you generally need consent to send someone marketing email — unless you can rely on the "soft opt-in", which is the exemption most shops are quietly depending on without knowing its name.
The soft opt-in lets you email marketing to someone only if all four of these are true:
- You got their details in the course of a sale, or negotiating a sale (they bought something, or nearly did);
- You are marketing your own, similar products or services (a wine shop emailing about wine — fine; emailing about a mate's yoga studio — not);
- You gave them a simple way to opt out when you collected the address; and
- You give them a way to opt out in every message you send.
That covers a lot of a normal customer list. What it does not cover is the stuff small businesses most often lump in with it: people who signed up on your website but never bought anything, prospects, free event sign-ups, or a list you bought or were handed. Those people need actual consent — a clear, unbundled opt-in — before you email them. If the merchant's 800-person list is a mix of real customers and website signups who never purchased, part of that list is on shakier ground than he thinks.
This is not about scaring you off your own customers. A genuine list of existing customers, emailed about similar products with an easy unsubscribe, is often perfectly fine. The fix is knowing which people are which — and adding a consent step for the ones the soft opt-in does not reach.
The bit that changed in 2026
For years, the reason a lot of small businesses shrugged at PECR was the ceiling: fines were capped at £500,000 and realistically aimed at spam operations sending millions of texts — not a wine shop emailing 800 regulars.
That ceiling moved. The Data (Use and Access) Act 2025 came into force on 5 February 2026, and one of the things it did was lift PECR penalties up to UK GDPR levels — a maximum of £17.5 million, or 4% of global annual turnover.
Read that honestly, though. That £17.5 million is a ceiling, not a price list for corner shops. A good-faith small business that has slipped is far more likely to get a nudge or a "put this right" than a headline fine. The realistic risk for you is time, hassle, and the sting of a complaint — not bankruptcy. But a ceiling that just rose this sharply is a fair reason to move privacy up your list, especially when the fixes are this cheap.
The good news: four cheap fixes
Here is the whole to-do list. None of it needs a lawyer or a big budget.
- Replace the template privacy notice with a real one that actually describes what you do — your mailing list, your analytics, who you share data with — and gives people a clear way to contact you and exercise their rights. Under UK GDPR (Articles 13–14) it has to be accurate and complete; a boilerplate that omits your list does not clear that bar.
- Fix the mailing list. Add a proper consent step at signup for anyone the soft opt-in does not cover, keep a simple record of what people agreed to, and make sure every email has a working unsubscribe.
- Sort the cookies. Non-essential analytics need consent before they load. The 2026 rules carved out a narrow exemption for basic, first-party, statistics-only analytics — but it comes with a required opt-out and generally does not cover Google Analytics, because GA shares data with Google. So either add a cookie banner that holds analytics until someone agrees, or switch to a cookieless, privacy-friendly analytics tool.
- Check your ICO registration and fee. If you handle personal data — and a marketing list counts — you most likely need to register with the ICO and pay the annual data protection fee: £52 a year for the smallest firms (£47 by direct debit). It is the small, mechanical piece, but worth doing — not paying is the one enforcement action that is genuinely likely (a £400 fixed penalty for a micro-organisation). Run the ICO's two-minute self-assessment if you are not sure, then set it to renew and forget it.
That is it. Four things, most of an afternoon — and you move from "hoping it's fine" to actually being in good shape, which is exactly the difference the ICO cares about between an owner acting in good faith and one doing nothing.
I will be upfront: this is the problem we built Dxtra to solve, so I am hardly neutral. But it is why I wanted to write this — because for years the honest answer to "how do I fix all this?" was "hire someone and wait months," and for a shop like his that may as well have meant "don't bother." That is what we set out to change. Dxtra builds your whole privacy program — notices, consent, cookies, processor management, and a public Transparency Center — in hours, not months, from $10 per month (about £7.40). Sign in and an AI assistant hands you a short checklist and walks you through it step by step: publish your privacy notice, set up consent, connect your processors, sort your tags and cookies, and review your data-subject-rights form. It generates what is missing, and you review everything before it goes live.
See your own version of this in minutes
The fastest way to find out which gaps you actually have is to look at your own site the way a regulator would. Run a free Dxtra scan of your site → — in under a minute you get a plain-English read on your privacy notice, cookies and trackers, consent setup, and rights routes, each gap paired with the fix. No sign-up, no card; it reads only your public pages.
The wine merchant did not need me to lecture him about UK GDPR. He needed to know it was four small jobs, not a wall — and that he could see exactly where he stood before dinner. So can you.
This article is for general information and is not legal advice. Privacy rules change and specifics depend on your business — confirm anything that matters with the ICO (ico.org.uk) or a qualified adviser before you rely on it.

