CheckoryCheckory
Frozen privacy notice beside live collectors with a High mismatch flagged before send

Privacy Policy Review Checklist for Small Business Websites

Match the live site to your privacy notice: inventory forms, cookies, and vendors, then fix High mismatches before the next campaign.

9 min readArticle
💡

Key takeaway in 30 seconds

A privacy policy review checklist for a small business website starts with the live page: inventory every form, cookie, pixel, and AI snippet, then mark each row match or mismatch. Name who you complain to, not only the ICO.

You published a generator page two years ago. The live shop now has a contact form, a newsletter, analytics, a campaign pixel, and a chatbot. Use this privacy policy review checklist for small business website work: walk the live site in a private window, log every collector, and treat a mismatch as a High flag — an item scored high severity — until you rewrite the notice or kill the script. A copied footer is not finished.

In August 2026 Elise — UK florist, four people, a few US buyers — is 40 minutes from an autumn send. The agency added a pixel and a product-quiz chatbot last Tuesday. The privacy page still lists Mailchimp from 2024 and says “essential cookies only.” Typical mistake: treating the generator as done. The risk is a live pixel against a stale notice. The ICO says a shorter notice can work better — and from 19 June 2026 UK controllers must also describe a complaint-to-you path, not only “complain to the ICO.”

Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.

How do you match the notice to live forms, cookies, and vendors?

Open a private window and click every path a customer uses. Write down each collector: form, checkout, newsletter, widget, chat or AI, pixel, analytics, embed, payment, CRM. Then open the published notice and mark yes, no, or vague. That is the privacy policy versus what the site actually collects.

Freeze the live URL, the “last updated” date, and a PDF print. In practice the Network tab names the vendor faster than the footer. For example, a Meta pixel still fires when the notice says “we do not share data.” ICO PECR rules cover cookies, pixels, and SDKs — not only “desktop cookies.”

  • Do: walk the live site first, then the notice.
  • Do not: review a draft while the agency already shipped a pixel.
Privacy notice beside a cookie and vendor list with one mismatch circled
Match the notice to the live collectors.

What should categories, purpose, and lawful basis actually say?

Write one row per purpose, not one blanket “we process lawfully.” Name the data types, why you use them, and the lawful basis you already decided. If the shop is UK-facing, “consent by using this site” is not a basis. A shorter notice can still carry every required row.

The ICO SME how-to wants contact details, data types, source if not from the person, purposes, lawful basis, who you share with, and how long you keep it — decided before you start. UK GDPR Article 13 adds recipients, transfers, rights, and how to withdraw consent. ICO timing: at collection, or within one month if the data did not come from the person.

  • Do: one row per form, cookie, or list.
  • Do not: paste “we process lawfully” across a UK shop.
One row per purpose: data types, lawful basis, recipients, retention, and contact
One row per purpose: data types, lawful basis, recipients, retention, and contact

Do you have to name every plugin, AI tool, and retention period?

Name the services a person would recognise — email, analytics, ads, payments, AI chat — not “trusted partners.” If you cannot name a script, remove it before the campaign. Cookie duration belongs in the same row as the vendor. A 2019 Mailchimp line is not an inventory.

PECR wants a positive action, not continued browsing, and wants third parties named — including first-party-looking tags. Refuse as easily as accept. If a vendor processes personal data for you, you likely need a DPA — a data processing agreement. That is a separate checklist.

  • Do: name the email tool, GA4, Meta, the quiz bot, and cookie life.
  • Do not: leave “trusted partners” while an AI snippet runs.

Where should people send a rights request or complaint?

Publish a mailbox a human answers, then send a dummy access, delete, and complaint before you relaunch. Listing rights with a dead privacy@ inbox is a mismatch. From 19 June 2026 UK controllers must also describe complaining to you, not only to the ICO.

ICO complaints guidance, updated 8 May 2026, says every controller must have a complaints process. Give a way to complain to you, acknowledge within 30 days, and tell people the outcome.

  • Do: test-send and put the 30-day acknowledgement in a UK notice.
  • Do not: rely on “email us” with no human on the other end.
Rights path: working mailbox, dummy access, 30-day acknowledgement, UK 19 June 2026
Rights path: working mailbox, dummy access, 30-day acknowledgement, UK 19 June 2026

When to update — quarterly light or annual full?

Run a light review every quarter — new plugin, new form, new vendor — and a full review at least annually. The ICO says update privacy information before starting any new processing, not after the campaign. California-covered businesses also update the online policy at least once every 12 months.

Name the statute. Cal. Civ. Code § 1798.130(a)(5) is the 12-month update for covered California businesses — not a global rule. In the US, FTC Section 5 treats a material mismatch as deceptive. Workflow: freeze → private-window walk → match table → rewrite → test the inbox → dated publish or stop.

  • Do: calendar quarterly-light and annual-full, plus a freeze before a send.
  • Do not: wait a year while the agency adds a pixel.

Severity × live fact × action

SeverityLive fact vs noticeAction
High“No sharing” / “essential cookies only” while ads, analytics, or a pixel runRewrite or kill the script before send
HighAI chat or product quiz live; notice silentName the tool and purpose, or remove it
HighDead privacy@ inbox, or rights with no routePublish a mailbox a human answers; UK: complaint-to-you + 30-day ack
HighNew processing already started; notice staleStop the campaign; update before new processing
Medium“Trusted partners” instead of named vendorsName the services people would recognise
MediumOne blanket lawful basis for every formOne basis per purpose on a UK shop

Typical mistake

Waiting for an annual refresh while a campaign pixel or AI chat already ships. The ICO trigger is before new processing, not after the send.

Privacy notice vs live-site checklist

1

Freeze the live notice

Save the URL, the “last updated” date, and a PDF print. Review that text.

2

Inventory collectors

Private window: forms, widgets, chat or AI, pixels, analytics, embeds, payment. Note vendor URLs.

3

Build the match table

Collector → purpose → lawful basis → recipient → retention → in the notice? Flag High if the notice denies sharing.

4

Rewrite one row per purpose

Plain English. Name the legal entity and a working contact. If consent, say how to withdraw.

5

Name vendors and retention

Email, analytics, ads, payments, AI chat. If a script cannot be named, remove it before the campaign.

6

Test the rights path

Dummy access, delete, and complaint. UK after 19 June 2026: complain-to-you and acknowledge within 30 days.

7

Align cookies with the inventory

Non-exempt tags stay off until accept. Reject as easy as accept.

8

Decide: publish, freeze, or escalate

Publish a dated update only if High mismatches are closed. Else block the campaign. Escalate health data, kids, or sale/share to counsel — a qualified lawyer.

Eight-step walk from freeze the live notice to publish, freeze, or escalate
Eight-step walk from freeze the live notice to publish, freeze, or escalate

What to fix before the next campaign?

Stop the send if the notice still says “name and email only” or “essential cookies only” while a pixel, AI chat, or new plugin is live. Close every High mismatch or escalate. A copied US template on a UK shop is a draft, not a finish line.

Success bar before send: a one-page log (collector → vendor → purpose → lawful basis → retention → rights contact), each row match / mismatch / fix-before-launch, and either a dated update live or the campaign frozen. A first-pass — the first machine pass that extracts clauses — can highlight the PDF. A named human still opens the live forms.

  • Do: treat a copied template as a draft and freeze the pixel.
  • Do not: launch the plugin and “update the policy later.”

Name the jurisdiction

UK: ICO SME + PECR + complaint-to-you from 19 June 2026. California: 12-month update only if covered. US: FTC Section 5 for a deceptive mismatch.

Every processor on the live site needs a written contract: DPA checklist before you sign.

Frequently asked questions

How often should you update a privacy policy?
Light review every quarter when a plugin, form, or vendor changes. Full review at least annually. Update before any new processing.
Do I need to list every plugin in the privacy policy?
Name the services a person would recognise. If you cannot name a script, turn it off before the campaign. “Trusted partners” is not a list.
Is a copied privacy policy template enough?
No. A US template on a UK shop usually misses lawful basis, named recipients, and a real complaint path. Treat it as a draft and walk the live site.
What is the difference between a privacy notice and a privacy policy?
In UK ICO language the public page is a privacy notice. “Privacy policy” is the usual website label. Review the page people actually see.
When must a UK website update its privacy notice?
Before any new processing — a pixel, AI chat, or new form counts. From 19 June 2026 also describe how to complain to you and acknowledge within 30 days.
What should a website privacy policy checklist 2026 include for a small shop?
Live collectors, one lawful basis per purpose, named vendors including AI tools, retention, a working complaint contact, and a dated publish-or-stop decision.

Run a first-pass on the notice PDF

Upload the published page, then compare every High row to the live site.

Start document analysis

What to do next

Sources

Read also

Related guides

Updated: August 27, 2026