Creating a website is no longer mainly a coding decision. The important question is which route gives your UK business, project or organisation enough control without creating an expensive or difficult service to run. For most new sites, the choice is between a hosted website builder, managed WordPress and a developer-built site.
In summary: a hosted builder is often right for a simple, supported website; managed WordPress is a flexible middle route for a content-led site; and a developer-built site is worthwhile where a bespoke journey, integration or performance need genuinely justifies it. Whichever option you take, keep the domain, recovery email, hosting, analytics, payment and email-marketing accounts under the business’s control—not an agency’s, freelancer’s or former employee’s.
This guide explains how to select a platform, budget the first year without relying on headline promotions, and launch with a proportionate baseline for legal information, privacy, cookies, accessibility, security, ecommerce and maintenance.
Important: This article is general information, not personal legal, tax, financial, security or professional advice. Requirements depend on your entity, customers, sector, data use and products or services. Seek suitably qualified advice where you have regulated activity, handle sensitive data, sell complex digital services, work for the public sector or trade internationally.
Start with the outcome, not the template
Write a one-page brief before comparing plans. State the website’s primary job: generating enquiries, taking bookings, publishing information, selling goods, accepting donations or supporting members. Identify the main action a visitor should complete, who will update the site and which systems it must connect to. A service website with a contact form needs a different solution from a shop with stock, customer accounts, delivery and returns.
Define success in practical terms. It might be a qualified enquiry, completed booking, newsletter sign-up or paid order—not simply visits. Keep the first release focused on the essential visitor journey. A modest, reliable site with a named owner is more valuable than an ambitious build with no budget for updates.
If somebody else will build it, obtain a written scope. It should cover deliverables and exclusions, content responsibility, accessibility, third-party subscriptions, ownership of design and code, testing, training, handover and post-launch support. This makes assumptions visible before they become cost or risk.
Compare the three main website routes
A hosted builder is a subscription service that supplies the editor, hosting and core infrastructure. Managed WordPress normally combines WordPress with a host that handles some technical work, while retaining access to its theme and plugin ecosystem. A developer-built site is tailored to your requirements, commonly using a content management system (CMS), chosen hosting and a dedicated support arrangement.
| Decision factor | Hosted builder | Managed WordPress | Developer-built site |
|---|---|---|---|
| Best suited to | Brochure site, portfolio, campaign or standard small shop | Content-rich business site, publication or growing shop | Bespoke workflow, integration, distinctive customer journey or specialist performance need |
| Initial cost | Usually low: setup time and a subscription | Moderate: configuration, theme, migration and possible specialist help | Usually highest: discovery, design, development, testing and project management |
| Ongoing cost | Subscription plus applications or commerce services | Hosting, maintenance, premium extensions and occasional development | Hosting, monitoring, licences, support and future development |
| Ownership and portability | Content export may be limited; moving can mean rebuilding | Files, database and content can usually move, but themes and plugins may complicate it | Potentially highly portable, but only if contract, architecture and documentation support it |
| Support | Provider support within plan limits | Responsibility may be split between host, plugin vendors and maintainer | Tailored support is possible, but only if purchased with clear service levels |
| Ecommerce | Fast route for a familiar catalogue and checkout | Flexible for content and commerce together | Appropriate for unusual checkout, account or integration needs; not automatically better |
There is no universally cheapest platform. Builders can become costly once important applications and higher plans are added. WordPress can become fragile when it relies on too many poorly governed plugins. Bespoke development can waste money if it recreates mature standard features without a business reason.
Choose the least complex route that meets the next 12 to 24 months of real requirements, then make sure you can leave it. A hosted builder fits where one or two trained people need to publish straightforward pages and are content with the platform’s design system. Managed WordPress can suit a business that will publish regular articles, guides and landing pages. A developer-built site is appropriate where configuration cannot meet the brief, such as a proprietary quote process or a core business-system integration.
Before signing, ask every supplier the same exit questions. Can you export content and media? Can the business obtain domain-transfer credentials? Can you download files and database? Who owns the code repository? How are backups retained after cancellation? Can another supplier take over? A clear answer is more valuable than a polished sales demonstration.
Treat the domain and accounts as business assets
Your domain is the web address; hosting is where the site runs. They can be bought separately. For .uk domains, Nominet defines the registrant account name as the company or individual on whose behalf the domain is registered. 1 Make the correct legal entity or owner the registrant. Do not allow an agency or developer to be the only registrant or recovery contact.
Use a role-based business email address for account recovery and an approved password manager for credentials. Enable multi-factor authentication where it is available. Keep a secure access register for the registrar, DNS, hosting, CMS, analytics, search tools, consent manager, payment provider, email platform and social accounts. Review it when staff or suppliers leave.
Set renewal reminders and maintain a continuity note with the registrar, domain expiry, DNS provider, hosting, renewal contacts and recovery route. Auto-renewal helps, but it is not a substitute for oversight. An authorised colleague should be able to restore access without relying on one person’s inbox or memory.
Budget the whole first year—not an introductory offer
Do not select a service solely by a temporary price, voucher code, discount or assumed renewal cost. Plans, features, taxes, transaction fees and contract periods can change. Obtain current written quotes and compare the full first-year operating cost.
| Cost area | What to check | Common omission |
|---|---|---|
| Domain and DNS | Registration term, renewal, transfer method, privacy options and registrant | Domain held by a supplier or a missed renewal |
| Platform or hosting | Renewal, storage, staging, backup policy, service limits and support scope | Choosing on promotion while missing renewal or limitations |
| Build and content | Discovery, copy, photography, migration, design, development, QA, training and handover | A low quote that excludes content and testing |
| Extensions and operations | Templates, plugins, forms, booking, email, consent, analytics and automation | Small critical subscriptions becoming untracked |
| Ecommerce | Payment processing, delivery tools, tax settings, returns, fraud controls and support | Pricing only the storefront plan |
| Maintenance | Updates, monitoring, restoration testing, security support and emergency changes | Treating launch as the end of the cost |
VERIFY BEFORE PUBLISHING: If this page later names providers, packages or products, add a dated check of the applicable price, renewal terms, transaction charges, features and exclusions. Never present live offers, rates, codes or supplier terms without checking the original source immediately before publication.
Publish the minimum trustworthy set of pages
A clear navigation should show visitors who you are, what you offer, how to contact you and what happens to their information. Do not hide essential information in an image, a hard-to-find footer or an inaccessible document.
| Page or element | Minimum purpose and content |
|---|---|
| Home | Explain the audience, offer, benefit and next action quickly. |
| About and contact | Give trading identity, a working contact route, location where relevant and realistic response expectations. |
| Service, product or pricing pages | Provide accurate descriptions, material limitations, current prices and the next step. |
| Privacy notice | Explain personal-data use in a way that matches the live site. |
| Cookie information and controls | Explain the technologies and purposes, offer preference controls and let users revisit their choice. |
| Terms, delivery, returns and cancellation information | Match the goods, services, fulfilment and consumer rights that actually apply. |
| Company or business disclosures | Show the details appropriate to the business structure in a readable, permanent location. |
| Accessibility information | Give users a route to ask for help or report a barrier; publish a statement where required. |
For a registered company, the current trading-disclosures regulations require its registered name on its website. They also require the relevant part of the UK in which it is registered, registered number and registered-office address, with extra particulars in specific cases. 2 A sole trader or partnership using a business name has different disclosure rules, so do not copy a limited-company footer without checking. 3
The Electronic Commerce Regulations require information-society service providers to make core identity and contact information easily, directly and permanently accessible, including their name, geographic address and effective direct contact details. Further information may be needed depending on registration, regulatory status and VAT activity. 4 Make sure that forms work and that customers can reach a person or team who can respond.
Design privacy, cookies and marketing into the build
Enquiries, bookings, purchases, newsletter sign-ups, customer accounts, analytics identifiers and chat tools may involve personal data. UK data-protection law requires data to be used fairly, lawfully and transparently, for specified purposes, limited to what is necessary, kept no longer than needed and handled with appropriate security. 5 Map every data flow before launch: forms, plugins, embedded services, tracking scripts, inboxes, spreadsheets and suppliers. Remove tools that do not have a clear purpose.
Your privacy notice should be easy to find where information is collected and describe what actually happens. The ICO says it normally needs to cover the organisation’s name and contact details, purposes, lawful basis, retention, relevant recipients, overseas transfers where applicable, individual rights and the right to complain to the ICO. 6 A generic notice is not enough if it does not reflect the tools and retention practices in use.
Cookie compliance is a configuration task, not merely a banner-design task. Audit the site before and after a visitor makes a choice, including analytics, embedded video, maps, chat, advertising and affiliate tracking. The ICO says users must be told about cookies, what they do and why, and must give active, clear consent. The main exception is technology strictly necessary to provide a service requested by the user. 7 Do not set non-essential technologies until the relevant consent is recorded. Let users change their preferences, and retest after any integration changes.
Treat newsletter consent separately from an enquiry or purchase where necessary. The ICO says marketing emails or texts to individuals normally require specific consent, subject to a limited soft opt-in for certain existing customers. Each marketing message needs a valid opt-out route and must not conceal the sender’s identity. 8
VERIFY BEFORE PUBLISHING: The ICO notes that some guidance is under review following the Data (Use and Access) Act. Check the ICO’s latest privacy, cookie and direct-marketing guidance, your own data map and the behaviour of the chosen consent tool immediately before launch. 6 8
Make accessibility a quality requirement
Accessibility supports people using keyboards, screen readers, magnification, voice input, mobile devices or slow connections. WCAG 2.2 groups web accessibility around four principles: perceivable, operable, understandable and robust. 9 Build and test towards WCAG 2.2 AA where appropriate, and seek specialist support where formal compliance duties apply.
Public-sector bodies have specific website and app accessibility rules, including an accessibility-statement requirement; government guidance points to WCAG 2.2 AA. 10 Other organisations should not assume accessibility can be ignored because they are not public bodies. Seek advice on your own position and make reasonable, user-centred improvements from the beginning.
Test major journeys with a keyboard only. Navigation, forms, checkout, pop-ups and cookie controls should work with a visible focus state. Use logical headings, descriptive links, adequate colour contrast, text alternatives for meaningful images, labelled form fields and clear error messages. Automated testing helps, but it cannot replace human testing.
Launch safely and maintain deliberately
The ICO’s security principle requires appropriate measures to protect personal data. 11 The National Cyber Security Centre’s guidance for small organisations emphasises backups, protecting devices and accounts, and recognising scams. 13 Use HTTPS, restrict administrator access, remove unused accounts, use strong unique passwords and multi-factor authentication, and keep the CMS, themes, plugins and server components supported and updated. Test material changes in a staging environment where feasible.
Back up content, media, database, configuration and custom code. Keep a copy separate from production and practise restoring it to a safe location. A backup that has never been restored is not a proven recovery plan. Record who receives security alerts, who can make emergency changes and how access is recovered.
| Pre-launch check | What good looks like |
|---|---|
| Content and claims | Names, legal details, prices, availability, images, links and calls to action are accurate and approved. |
| Forms and email | Forms reach the right place; confirmations, errors, spam controls and consent wording work. |
| Mobile and accessibility | Key journeys work on current phones and desktop browsers, with keyboard and basic assistive-technology checks. |
| Privacy and cookies | Notice matches the site; non-essential technologies wait for consent and choices can be changed. |
| Ecommerce test order | Price, stock, delivery, tax, confirmation, cancellation, refund and customer-service hand-off work as intended. |
| Search and handover | Staging is not indexed; redirects and important metadata are checked; accounts, renewals and recovery steps are documented. |
For online sales, give customers clear pre-contract information. GOV.UK lists the business name, contact details and address, goods or service description, price including taxes, payment, delivery arrangements and costs, and cancellation information among what must be given before an order. 14 Customers generally need information they can save. Rules and exceptions vary, especially for digital content and services, so make wording match the actual offer and obtain advice when uncertain.
After launch, assign an owner and schedule. Review failed forms, orders, support requests and suspicious activity weekly. Apply approved updates, review account access and check backups monthly. Each quarter, retest a key visitor journey, cookie configuration, accessibility basics and recovery process. Review legal pages, suppliers, renewals, analytics need, content accuracy and performance at least annually.
Frequently asked questions
Do I have to buy my domain from my website builder?
No. Keeping it in a business-controlled registrar account can make a future move easier. The key is that the correct company or person is the registrant, recovery details remain current and the business can manage DNS. 1
Is WordPress automatically better for search engines than a website builder?
No. Search performance depends on useful content and sound technical implementation, as well as many other factors. Choose the system your team can keep accurate, accessible and well maintained.
Can I add a privacy policy after launch?
Not if the website starts collecting or using personal data immediately. Privacy information should describe the processing from launch, and consent-dependent technologies should not run until the relevant consent has been obtained. 6
Does every UK business website need an accessibility statement?
Public-sector bodies have specific statement requirements. 10 Other businesses should prioritise accessible design and obtain advice on their own legal position. Providing a clear accessibility contact route is good practice.
What should I ask a developer before paying a deposit?
Ask for the scope, milestones, acceptance criteria, total-cost assumptions, change process, accessibility and security responsibilities, support period, IP ownership, repository access, export method, documentation and handover plan. Your organisation should be able to operate or transfer the site if the relationship ends.
The sensible standard for a first website
A successful website helps visitors complete a clear task, gives the organisation control of its assets, explains its practices honestly and remains recoverable after launch. Choose the simplest suitable platform, budget the full first year, document ownership and treat maintenance as part of the service—not an optional extra.





