Privacy notice and cookies for a professional’s website: what you need and what to say
· 8 min read
The moment your page has a contact form, a booking tool, a map or a visitor counter, you are handling other people’s personal data, and in most places the law expects you to tell them how. For a sole practitioner this is simpler than it sounds: collect little, say plainly what you do with it, and avoid tools that need a cookie banner. This guide explains what to include, when cookie consent is needed, how the main regimes differ, and gives a short template. It is general information, not legal advice.
The short answer
- If you collect any personal data through your page (a form, a booking tool, an email list), you should tell visitors who you are, what you collect, why, how long you keep it and how to contact you.
- Collect only what you need. A form that asks for a name, an email and a message needs a much shorter notice than one that asks for a case history.
- In the UK, consent is needed before non-essential cookies, and analytics cookies are not treated as essential. Pre-ticked boxes and “by continuing you agree” do not count.
- The simplest way to avoid cookie banners is to use no tracking cookies at all, and say so.
- Rules differ by country and by profession. Doctors, lawyers, therapists and advisers hold special categories of information and often owe duties of confidentiality on top of data law.
Do you need a privacy notice?
If you collect, store or use information that identifies a person, you are handling personal data. Typical sources on a professional page:
- A contact or enquiry form: name, email, phone, message.
- A booking tool or calendar: name, contact details, appointment time.
- An email list or newsletter sign-up.
- Analytics and advertising tools, which can set cookies or collect device information.
- Embedded content such as maps, videos and social feeds, which can load third-party code.
- Live chat or messaging links.
If none of these apply, you may collect almost nothing. Even so, a short statement that you do not use cookies or collect data through the page is useful and builds trust.
What a privacy notice should say
In the UK and EU, data protection law lists what people must be told when you collect their data. In plain terms:
- Who you are, and how to contact you (name or firm, address or email).
- What you collect: for example, name, email and the message they send.
- Why you collect it, and your legal basis (for example, to reply to the enquiry, or to carry out a contract, or consent).
- Who else receives it: your email provider, booking tool or accountant, if they handle it for you.
- Whether it leaves the country, and what protects it if it does.
- How long you keep it, or how you decide.
- Their rights: to see their data, correct it, ask for it to be erased, object, and complain to the regulator.
- Whether providing it is optional, and what happens if they do not.
Write it in short, plain sentences. A notice nobody can understand does not meet the purpose of the rule.
A short template
Privacy notice
Who I am: Anna Weiss, physiotherapist, 12 Example Road, Bristol. Contact: anna@example.com.
What I collect: if you use the contact form, I collect your name, email address and the message you write. I do not use cookies to track you on this page.
Why: to reply to your enquiry. I will use your details for nothing else without asking you.
Who sees it: only me, and my email provider, which stores messages on my behalf.
How long: I keep enquiries for up to 12 months, or longer if you become a client, in which case my client records policy applies.
Your rights: you can ask to see, correct or delete what I hold about you, or object to how I use it, by emailing me. You can also complain to the Information Commissioner’s Office.
Last updated: 3 October 2026.Replace the details with yours, name the regulator that applies where you work, and have a lawyer check it if your work involves sensitive information.
Cookies: when you need consent
- United Kingdom: the Privacy and Electronic Communications Regulations need consent before you place non-essential cookies or similar technologies on a visitor’s device, to the standard set by data protection law: a clear, positive action. Implied consent by continuing to use the site and pre-ticked boxes do not meet it. Strictly necessary cookies are exempt, but the exemption is read narrowly, and analytics cookies are not treated as essential.
- EU: the ePrivacy rules, as national laws apply them, similarly require consent for non-essential cookies and similar technologies, and information about what they do.
- United States: no single federal cookie consent law applies to a small professional site, but state privacy laws can give people rights over how their data is sold, shared or used for targeted advertising where the law applies to you.
- India: see the section below.
A banner is only needed if you use non-essential cookies. If you use no analytics or advertising cookies, no embedded trackers and no third-party widgets that set them, you may need no banner at all. That is the simplest route for a small practice.
Avoiding the banner
- Use analytics that do not set cookies or identify individuals, or none at all.
- Do not install advertising pixels unless you need them and will ask for consent.
- Use privacy-friendly embeds: for example, a video embed that does not set cookies until the visitor plays it, or a map link instead of a live embedded map.
- Check with your browser’s developer tools or a cookie scanner what your page actually sets. Tools you added years ago may still be running.
- Say what you do on the page in one line: “This page does not use tracking cookies.”
The main regimes at a glance
| Where | Law | What it means for you |
|---|---|---|
| United Kingdom | UK GDPR, Data Protection Act 2018, PECR | Tell people what you do with their data. Consent for non-essential cookies. Some organisations must pay a data protection fee to the ICO; check whether you do. |
| European Union | GDPR and the ePrivacy rules | Similar to the UK. Notice, lawful basis, rights and consent for non-essential cookies. |
| California, USA | CCPA as amended by CPRA | Applies to businesses that meet a threshold: annual gross revenue above $25 million (adjusted to $25.625 million from 1 January 2025), or buying, selling or sharing the data of 100,000 or more consumers or households, or earning 50% or more of revenue from selling or sharing personal information. Most sole practitioners are below these lines, but check. |
| Other US states | State privacy laws | Many have their own thresholds. Professional and health-specific laws can also apply. |
| India | Digital Personal Data Protection Act 2023 and Rules 2025 | Notified on 13 November 2025 and phased in, with the main duties on consent, notice and breach reporting applying from May 2027. |
These rules change and have exceptions. Check with the regulator for your country, such as the ICO in the UK, or the data protection authority in your EU country, or a lawyer where the stakes are higher.
Professions with extra duties
- Health: information about health is a special category in UK and EU law, and doctors, therapists and clinics also owe duties of confidentiality. Avoid collecting clinical detail through a general contact form. Tell people not to include it.
- Law: lawyers owe confidentiality from the first contact. A form should warn that a message does not create a client relationship and should not contain confidential details.
- Accounting and finance: you may hold financial records, identity documents and tax details, and may have anti-money-laundering duties.
- Children and education: extra care applies when you collect data about children. Many places have stricter rules.
Good practice for a one-person practice
- Ask for the minimum. Every field you add is data you must protect.
- Say on the form what you will do: “I will use this to reply to you.”
- Reply to enquiries from an address you control, and delete those you no longer need.
- Keep your devices and email protected with strong passwords and two-step sign-in.
- Use providers you trust, and know where they store data.
- Keep a note of what tools collect data on your page. You will need it if someone asks.
- If you have a data breach that puts people at risk, tell your regulator and affected people within the time your law requires. In the EU and UK this is generally 72 hours for the regulator.
- Review your notice whenever you add a tool.
Common mistakes
- Copying another firm’s policy, with its name and tools in it.
- Saying “we do not collect any data” while a form and an analytics script do.
- A cookie banner with a pre-ticked “accept” or no real way to refuse.
- Asking for health or case details in a general form.
- A notice nobody can find. Link it from the footer and near the form.
- Never updating it after adding a tool.
Where BeVisible fits
On BeVisible, visitor statistics are collected without cookies and without recording IP addresses, names or anything that identifies a visitor. If a visitor sends a message through the optional enquiry form, their name, email and message are stored and passed to you, and they receive one short confirmation email. The service itself does not use advertising or tracking cookies. What you publish and how you handle enquiries once they reach you remains your responsibility, and you should add a short notice of your own if you collect personal data. You can build and preview free, and publish free for 7 days with no card needed; after that one yearly plan keeps a website online, and one plan covers one website. Start from a photo or type your details. Read BeVisible’s own privacy policy at bevisible.site/privacy.
Frequently asked questions
Does my professional website need a privacy policy?
If you collect personal data, through a contact form, a booking tool, an email list or analytics, you should tell visitors who you are, what you collect, why, how long you keep it, who sees it and what rights they have. A short plain-language notice is enough for a simple page.
Do I need a cookie banner?
Only if you use non-essential cookies or similar technologies. In the UK, consent is needed before these, and analytics cookies are not treated as essential. If your page sets no tracking cookies, you may not need a banner.
Is “by continuing to use this site you agree” valid consent?
Not under UK data protection and cookie rules. Consent needs a clear, positive action, and pre-ticked boxes do not count.
Does the CCPA apply to a sole practitioner?
Only if you meet one of its thresholds: annual gross revenue above $25 million (adjusted to $25.625 million from 1 January 2025), or buying, selling or sharing the data of 100,000 or more consumers or households, or earning 50% or more of revenue from selling or sharing personal information. Most sole practitioners do not, but check, and note that other state laws have different thresholds.
When does India’s data protection law apply?
The Digital Personal Data Protection Rules 2025 were notified on 13 November 2025 and are being phased in. The main duties on notice, consent and breach reporting apply from May 2027. Check the latest position with an Indian lawyer.
Can I use a template?
A template is a good starting point, but it must describe what you really do. Replace names, tools and retention periods with yours, and have a lawyer check it if you handle sensitive information.
Sources and further reading
- Lewis Silkin: ICO updated guidance on the use of cookies and similar technologiesSummary of the UK regulator’s cookie guidance and the consent standard.
- ICO: Guidance on the use of cookies and similar technologiesThe UK regulator’s own guidance.
- CookieYes: Who does the CCPA apply to?The business thresholds under the CCPA as amended.
- AZB & Partners: India’s Digital Personal Data Protection Act, phased rolloutDates for the commencement of the DPDP Rules 2025.