Updated August 2026
Yes, I know – what an amazingly dull read for a blog. Who wants to read about cookies and privacy law? Voiceovers are a creative bunch and understandably this topic probably isn’t going to inspire you. Unfortunately, as boring as this is, it’s a legal requirement, and getting it wrong can mean fines – so as a voice actor with a website, you need to know what’s required and how to comply.
It’s dull. It’s not at all sexy or fun. It’s also quite technical, so I’ll do my best to summarise the key bits for you and give you how-to guides to get your website compliant – whether your clients are in the UK, Europe, the USA or Canada. I’ll cover the main website platforms too – WordPress, Wix and Squarespace.
(I’m not a lawyer, and nothing here is legal advice – just a practical, plain-English guide from someone who builds voiceover websites for a living. If in doubt, speak to a legal professional.)
Do I need a Privacy Policy and cookie banner on my voice-over website?
The quick answer is yes. You need both.
Every single website collects data in some shape or form. If you’re based in the UK, the European Economic Area (EEA) or Switzerland – or you actively market to clients there – you need to comply with UK GDPR or EU GDPR. And as you’ll see below, if you work with US or Canadian clients too, you need to think about their rules as well.
I’m in no way a legal professional, so this is where you can read the full UK GDPR guidance from the ICO or the general GDPR overview here.
I’m based outside the EU or UK – do I still need a cookie banner and privacy policy?
That depends on who you work with, not just where you live.
If you collect data from visitors based in the EEA, UK or Switzerland – or you actively market your voice-over services to people or businesses there – then yes, you need a GDPR-compliant cookie banner and privacy policy too. This is the bit voice actors most often miss: it’s about your audience and clients, not your home address.
The same principle applies in reverse if you’re a UK voice actor with US or Canadian clients – more on that below.
What’s changed with UK GDPR? (2025/2026 update)
If you read an older version of this post, or an older guide anywhere else, here’s the update: in 2025 the UK introduced the Data (Use and Access) Act (DUAA). It doesn’t replace UK GDPR – it amends it, and most of the changes are aimed at bigger, more complex organisations. But two bits are worth knowing:
- Cookie consent has loosened slightly, but only for low-risk cookies. Cookies used purely for basic analytics, or for remembering things like language or accessibility settings, can now run without asking first – as long as you tell visitors clearly that they’re there. Anything used for advertising, personalisation or A/B testing still needs proper opt-in consent, exactly as before.
- Penalties have gone up. Cookie and marketing-related breaches (PECR) can now be fined at the same level as GDPR breaches – up to £17.5 million or 4% of global turnover, whichever is higher. That’s obviously aimed at large companies, not solo voice actors, but it’s a sign regulators are taking this more seriously, not less.
The safest, simplest approach for a voice actor’s website hasn’t changed: use a proper cookie consent banner that asks before non-essential cookies run, and have a clear privacy policy. It covers you regardless of which cookies you end up using.
What about my clients in the USA
Here’s a question I get asked a lot now, as more of us work internationally: “I’m not in America, but I’ve got US clients – do I need to worry about their privacy laws too?”
There’s no single federal privacy law in the USA – instead, states are creating their own. As of 2026, 20 US states have their own comprehensive privacy laws, with more due to take effect this year. California’s law (the CCPA, updated by the CPRA) is the one you’ll hear about most, since it was first and is the most well-known.
US state laws work differently to GDPR. Rather than asking for opt-in consent before tracking (like the UK/EU), they generally use an opt-out model – tracking can happen by default, but you must be transparent about it in your privacy policy and honour requests from visitors who want their data deleted or want to opt out of their data being “sold or shared” (broadly meaning shared with ad networks and similar). Most also only apply once a business processes data from a large number of residents (often 100,000+), so a typical voice-over site is unlikely to be legally caught by the letter of the law.
That said, “unlikely to be legally required” isn’t the same as “fine to ignore” – especially if you actively market to or work with US clients. My advice: make sure your privacy policy clearly explains what data you collect (including via cookies), why, and how someone can ask you to delete it. That one step covers the spirit of US state laws even if the strict legal thresholds don’t apply to you.
What about my clients in Canada?
Canada has two things to be aware of:
- PIPEDA – the federal law covering commercial activity across Canada. It requires “meaningful consent,” a clear privacy policy, and lets people ask what data you hold on them.
- Quebec’s Law 25 – this one’s stricter, and it’s the one to pay real attention to if you work with Quebec-based clients or agencies. Unlike PIPEDA, Law 25 requires explicit opt-in consent before any tracking cookie fires – much closer to the UK/EU approach than the US one. It applies based on whose data you’re processing, not where your business is based, so a UK voice actor with a Quebec client can still be caught by it.
The good news – one compliant setup covers (almost) everywhere
Given the above, here’s the reassuring part: an opt-in cookie banner built to UK/EU GDPR standard is the strictest version of consent out there. If you set your website up that way, you’re automatically covering Quebec’s Law 25 too, and you’re going well beyond what US state laws require. You don’t need six different banners for six different regions – you need one good one, set to ask before it tracks, plus a clear, honest privacy policy that explains what you collect and why.
That’s exactly what the WordPress, Wix and Squarespace options below do.
I hired someone to build my site and I’m worried it doesn’t comply
Professional web designers and developers should know the laws for the regions they offer services in. If you’ve hired someone to build your website, they should have already added these features if they’re needed.
A good way to check if you have a cookie banner is to look at your website in “incognito mode” in your browser. Does a cookie banner pop up or not?
If you’re not sure, or think it’s missing, get in touch with me or send your developer/designer a friendly worded email asking them to check and get your website legally compliant. It’s usually a 10-minute job, and most businesses will be happy to help you – it is a legal requirement, after all.
What are cookies? Does my website even use them?
Every single website uses cookies, but there are a few different types – some essential for your website to run, some only active while your browser is open, and others that collect data for analytics or function. These are known as Duration, Provenance or Purpose cookies.
Some cookies are temporary and expire as soon as the browser is closed. Others stay on your hard drive until erased. Some are used by the site you’re visiting, some by third-party apps (like an embedded YouTube player or a demo player widget).
Some cookies are essential – your website simply wouldn’t work without them. Some allow certain features to work, some collect analytics data, others track online activity to help advertisers send “relevant” marketing directly to visitors.
Not every website has every type of cookie, but there are always some active. And don’t forget – if you’re asking visitors to contact you, you’re also collecting their personal data in the form of email addresses. You need to state how you store that information too.
If you want to know more, this is a link to the GDPR website.
What is a privacy policy and how do I write one?
I mentioned earlier – I’m not a legal professional, so please do seek legal advice if you wish. However, I use a website privacy policy template from Net Lawman. It’s a free-to-use template covering a standard UK privacy policy. You can download it, follow their guide to make it relevant to your website, and then upload it to your site. There’s an option to pay for a legal review if you want one, but the template itself is free to download and use.
This is a link to the Net Lawman website where you can get the download.
If you have US or Canadian clients, make sure your policy also covers: what personal data you collect (including via cookies and contact forms), why you collect it, how long you keep it, and how someone can ask you to delete it or opt out. Adding a short paragraph covering this is usually enough for a small voice-over business.
Once you have your privacy policy, you can add your cookie banner.
How to add a cookie consent banner for…
… WordPress sites
I use Complianz – if you’ve read an older version of this post, you’ll have seen me recommend CookieYES. I’ve since switched, and Complianz is now what I set up on client sites.
Why the switch? Complianz covers GDPR, UK GDPR, US state laws (CCPA/CPRA and others) and Canada (PIPEDA) in one plugin, and it lets you set a specific “region” so your banner automatically adapts its wording and consent style depending on where a visitor is – handy if, like a lot of us, you work with clients in more than one country. And it has a free-to-use version too.
This is how to add it:
- Log in to your WordPress Dashboard
- Go to Plugins > Add New Plugin and search for “Complianz“
- Click Install Now, then Activate
- Once activated, you’ll be taken into the setup wizard – work through it step by step
- Select your regions (for most voice actors, that’s UK/EU as your primary region, plus USA and Canada if you have clients there)
- Let Complianz run its cookie scan – this checks your site for the cookies it’s actually using and builds your cookie policy from the results
- Customise your banner text and appearance to match your branding
The scan step is essential – skip it and your banner won’t correctly list the cookies on your site, which means it isn’t properly compliant. There’s a free version that covers the basics for most small business websites, with paid tiers if you need more advanced features like A/B testing or Google Consent Mode integration.
Here’s the full Complianz setup guide if you want more detail.
… Squarespace sites
Squarespace has a built-in cookie banner. Here’s how to activate it:
- In your Home Menu, click Settings, then Cookies & Visitor Data
- Select Enable Cookie Banner
- Use the default message, or write your own
- Style your banner – there are options for how it displays, where it’s positioned, and its appearance. Click Save when you’re done (you’ll get a preview first)
- You can also link to your privacy policy and restrict or disable Squarespace’s analytics cookies here too
For a more detailed guide, visit Squarespace Support.
… Wix sites
Wix has a built-in option to add a cookie banner. All you have to do is enable it.
Step 1 – enable the Wix cookie banner
- Go to Privacy & Cookies in your site’s settings
- Click Edit Cookie Banner
- Click the Display Cookie Banner on Site toggle
- Click Save & Publish to display the default banner on your site
Step 2 – customise how your banner looks
Under “Text & Display Settings,” customise your banner colours, buttons and fonts.
Step 3 – link the banner to your privacy policy
If you’re using the free privacy policy template mentioned above, add it to a page on your site, then link to it from the drop-down menu.
Step 4 – review the requirements
Tick the checkbox confirming you’ve read and understood Wix’s Ts&Cs.
Step 5 – advanced settings
There’s default text in the cookie banner, but you can customise it here.
Step 6 – save and publish
Once you click “Save and Publish,” your cookie banner goes live.
For more detail, see Wix’s help page on cookie banners.
If you’re not using any of these platforms and don’t have a friendly web person to help, search specifically for “GDPR compliant” when you look for how-to guides for your platform. Or ask me and I’ll lend a hand.
Quick checklist: is your voice-over website compliant?
- Cookie consent banner installed and asking before non-essential cookies run
- Cookie scan completed (so your banner lists what’s actually on your site)
- Privacy policy published and linked from your cookie banner and your footer
- Privacy policy explains what data you collect, why, how long you keep it, and how to request deletion
- If you have US or Canadian clients, your privacy policy reflects this (see sections above)
- Contact form data storage explained in your privacy policy
Pair this with my 36 quick and easy ways to update your voice-over website for a full website health-check, or my 6 pages you need for a successful voiceover website if you’re planning your site structure from scratch. And if you’re building your very first site, my one-page voice actor website guide covers where your privacy policy link belongs, even on a single page.
FAQs
Do voice actors need a privacy policy?
Yes. If your website collects any data – contact form submissions, email addresses, analytics cookies – you need a privacy policy, regardless of where in the world you’re based.
Do I need a cookie banner if I only have a one-page website?
Yes. Cookie and privacy requirements apply to the content and function of your site, not the number of pages.
Is CookieYES still okay to use, or do I need to switch to Complianz?
CookieYES still works and remains GDPR compliant. I’ve personally switched to Complianz because it also covers US and Canadian regions in the same plugin, which suits voice actors with international clients – but you don’t have to switch if your current setup is working and compliant.
I’m US or Canada based – do I need a GDPR-style cookie banner?
Only if you have EEA, UK or Swiss visitors or clients. If you have Quebec-based clients, you’ll want opt-in consent too, under Law 25. If in doubt, setting your banner to the strictest (opt-in) standard covers you everywhere.
If you need help getting your website legally compliant – or sorting anything else on your voice-over website – come and join us in Be Seen, Be Heard, our monthly membership for voice actors. Websites, branding, SEO and the business side of voiceover – it’s exactly what the membership is for.
Cover photo by Lianhao Qu on Unsplash