
Privacy Policy Review Checklist for Small Business Websites
Match the live site to your privacy notice: inventory forms, cookies, and vendors, then fix High mismatches before the next campaign.
Key takeaway in 30 seconds
A privacy policy review checklist for a small business website starts with the live page: inventory every form, cookie, pixel, and AI snippet, then mark each row match or mismatch. Name who you complain to, not only the ICO.
You published a generator page two years ago. The live shop now has a contact form, a newsletter, analytics, a campaign pixel, and a chatbot. Use this privacy policy review checklist for small business website work: walk the live site in a private window, log every collector, and treat a mismatch as a High flag — an item scored high severity — until you rewrite the notice or kill the script. A copied footer is not finished.
In August 2026 Elise — UK florist, four people, a few US buyers — is 40 minutes from an autumn send. The agency added a pixel and a product-quiz chatbot last Tuesday. The privacy page still lists Mailchimp from 2024 and says “essential cookies only.” Typical mistake: treating the generator as done. The risk is a live pixel against a stale notice. The ICO says a shorter notice can work better — and from 19 June 2026 UK controllers must also describe a complaint-to-you path, not only “complain to the ICO.”
Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.
How do you match the notice to live forms, cookies, and vendors?
Open a private window and click every path a customer uses. Write down each collector: form, checkout, newsletter, widget, chat or AI, pixel, analytics, embed, payment, CRM. Then open the published notice and mark yes, no, or vague. That is the privacy policy versus what the site actually collects.
Freeze the live URL, the “last updated” date, and a PDF print. In practice the Network tab names the vendor faster than the footer. For example, a Meta pixel still fires when the notice says “we do not share data.” ICO PECR rules cover cookies, pixels, and SDKs — not only “desktop cookies.”
- Do: walk the live site first, then the notice.
- Do not: review a draft while the agency already shipped a pixel.

What should categories, purpose, and lawful basis actually say?
Write one row per purpose, not one blanket “we process lawfully.” Name the data types, why you use them, and the lawful basis you already decided. If the shop is UK-facing, “consent by using this site” is not a basis. A shorter notice can still carry every required row.
The ICO SME how-to wants contact details, data types, source if not from the person, purposes, lawful basis, who you share with, and how long you keep it — decided before you start. UK GDPR Article 13 adds recipients, transfers, rights, and how to withdraw consent. ICO timing: at collection, or within one month if the data did not come from the person.
- Do: one row per form, cookie, or list.
- Do not: paste “we process lawfully” across a UK shop.

Do you have to name every plugin, AI tool, and retention period?
Name the services a person would recognise — email, analytics, ads, payments, AI chat — not “trusted partners.” If you cannot name a script, remove it before the campaign. Cookie duration belongs in the same row as the vendor. A 2019 Mailchimp line is not an inventory.
PECR wants a positive action, not continued browsing, and wants third parties named — including first-party-looking tags. Refuse as easily as accept. If a vendor processes personal data for you, you likely need a DPA — a data processing agreement. That is a separate checklist.
- Do: name the email tool, GA4, Meta, the quiz bot, and cookie life.
- Do not: leave “trusted partners” while an AI snippet runs.
Where should people send a rights request or complaint?
Publish a mailbox a human answers, then send a dummy access, delete, and complaint before you relaunch. Listing rights with a dead privacy@ inbox is a mismatch. From 19 June 2026 UK controllers must also describe complaining to you, not only to the ICO.
ICO complaints guidance, updated 8 May 2026, says every controller must have a complaints process. Give a way to complain to you, acknowledge within 30 days, and tell people the outcome.
- Do: test-send and put the 30-day acknowledgement in a UK notice.
- Do not: rely on “email us” with no human on the other end.

When to update — quarterly light or annual full?
Run a light review every quarter — new plugin, new form, new vendor — and a full review at least annually. The ICO says update privacy information before starting any new processing, not after the campaign. California-covered businesses also update the online policy at least once every 12 months.
Name the statute. Cal. Civ. Code § 1798.130(a)(5) is the 12-month update for covered California businesses — not a global rule. In the US, FTC Section 5 treats a material mismatch as deceptive. Workflow: freeze → private-window walk → match table → rewrite → test the inbox → dated publish or stop.
- Do: calendar quarterly-light and annual-full, plus a freeze before a send.
- Do not: wait a year while the agency adds a pixel.
Severity × live fact × action
| Severity | Live fact vs notice | Action |
|---|---|---|
| High | “No sharing” / “essential cookies only” while ads, analytics, or a pixel run | Rewrite or kill the script before send |
| High | AI chat or product quiz live; notice silent | Name the tool and purpose, or remove it |
| High | Dead privacy@ inbox, or rights with no route | Publish a mailbox a human answers; UK: complaint-to-you + 30-day ack |
| High | New processing already started; notice stale | Stop the campaign; update before new processing |
| Medium | “Trusted partners” instead of named vendors | Name the services people would recognise |
| Medium | One blanket lawful basis for every form | One basis per purpose on a UK shop |
Typical mistake
Waiting for an annual refresh while a campaign pixel or AI chat already ships. The ICO trigger is before new processing, not after the send.
Privacy notice vs live-site checklist
Freeze the live notice
Save the URL, the “last updated” date, and a PDF print. Review that text.
Inventory collectors
Private window: forms, widgets, chat or AI, pixels, analytics, embeds, payment. Note vendor URLs.
Build the match table
Collector → purpose → lawful basis → recipient → retention → in the notice? Flag High if the notice denies sharing.
Rewrite one row per purpose
Plain English. Name the legal entity and a working contact. If consent, say how to withdraw.
Name vendors and retention
Email, analytics, ads, payments, AI chat. If a script cannot be named, remove it before the campaign.
Test the rights path
Dummy access, delete, and complaint. UK after 19 June 2026: complain-to-you and acknowledge within 30 days.
Align cookies with the inventory
Non-exempt tags stay off until accept. Reject as easy as accept.
Decide: publish, freeze, or escalate
Publish a dated update only if High mismatches are closed. Else block the campaign. Escalate health data, kids, or sale/share to counsel — a qualified lawyer.

What to fix before the next campaign?
Stop the send if the notice still says “name and email only” or “essential cookies only” while a pixel, AI chat, or new plugin is live. Close every High mismatch or escalate. A copied US template on a UK shop is a draft, not a finish line.
Success bar before send: a one-page log (collector → vendor → purpose → lawful basis → retention → rights contact), each row match / mismatch / fix-before-launch, and either a dated update live or the campaign frozen. A first-pass — the first machine pass that extracts clauses — can highlight the PDF. A named human still opens the live forms.
- Do: treat a copied template as a draft and freeze the pixel.
- Do not: launch the plugin and “update the policy later.”
Name the jurisdiction
UK: ICO SME + PECR + complaint-to-you from 19 June 2026. California: 12-month update only if covered. US: FTC Section 5 for a deceptive mismatch.
Every processor on the live site needs a written contract: DPA checklist before you sign.
Frequently asked questions
How often should you update a privacy policy?▼
Do I need to list every plugin in the privacy policy?▼
Is a copied privacy policy template enough?▼
What is the difference between a privacy notice and a privacy policy?▼
When must a UK website update its privacy notice?▼
What should a website privacy policy checklist 2026 include for a small shop?▼
Run a first-pass on the notice PDF
Upload the published page, then compare every High row to the live site.
Start document analysisWhat to do next
Review the frozen notice
Upload the published PDF or DOCX and mark High rows against the live site.
ProductCheckory pricing
See plan limits before you run notices through first-pass.
RelatedDPA checklist
Processors on the live site need a written contract.
RelatedKeep confidential files out of chatbots
A product-quiz bot is still a processor.
Sources
Read also
Related guides





