Legal pages every business website needs

The pages a business website must or should publish, what each contains, and how to keep the set small, accurate and current.

4 minread 810words last updated

The short answer

A business website needs fewer legal pages than a template suggests, and they need to be more accurate than a template makes them. For an ordinary services website, four cover it: company details identifying who you are and how to reach you, a privacy statement describing what you do with personal data, cookie information if you place non-essential cookies, and terms for whatever the site offers. A site that sells adds the consumer requirements: general terms and conditions, information about the right of withdrawal, returns, delivery, prices and payment. An accessibility statement is mandatory for public sector bodies and is good practice, and sometimes required, for businesses within the scope of accessibility legislation. Beyond the required set, extra pages tend to add risk rather than protection, because every page is a statement that must be true. The real work is keeping them accurate as the business changes, which is where inherited sites fail almost universally.

The set for a typical business

PageRequired?Core content
Company detailsYes for online servicesLegal name, address, email, chamber of commerce and VAT numbers, legal form
Privacy statementYes where personal data is processedWhat, why, basis, recipients, retention, transfers, rights, complaints
Cookie informationYes if non-essential cookies are usedCookies by purpose, setters, lifetimes, how to change consent
Terms of use or service termsIn substance, yes for services offered onlineWhat you provide, on what conditions, liability, governing law
General terms and conditionsYes for salesOrdering, prices, payment, delivery, withdrawal, warranty, complaints
Returns and withdrawal informationYes for consumer salesThe statutory period, how to exercise it, costs, exceptions
Accessibility statementYes for public sector; good practice and sometimes required for businessConformance status, known issues, feedback route
DisclaimerNoRarely adds protection; keep any claims modest and true
Copyright noticeNoA line in the footer suffices

Keeping them true

  1. Write each page from your own facts, not from a generator: your entity, your tools, your terms.
  2. Link them from the footer on every page, plus the relevant point of use: forms, checkout, sign-up.
  3. Date each page and keep previous versions.
  4. Add a review trigger to your process: any new tool, service, address, entity or payment arrangement prompts a check.
  5. Review annually regardless.
  6. Check them on a phone, because legal pages are where responsive layout is usually forgotten.
  7. Keep them in the repository with the rest of the site so changes are versioned and reviewable.

What not to add

Long disclaimers denying responsibility for everything. Copyright warnings threatening legal action. Cookie pages listing cookies the site does not set. Terms copied from a different jurisdiction or a different kind of business. None of these protects you, all of them can mislead, and consumer protection rules disregard terms that are unfair regardless of what the page says. A short, accurate set is stronger than a long, generic one.

What this means for you

Publish the small set that applies to you: company details, privacy, cookies where relevant, terms, and the consumer pages if you sell. Write them from your own facts, link them from the footer and the points of use, date them, review annually and whenever the business changes, and keep them in the repository. Accuracy matters more than volume, and extra generic pages add risk rather than protection. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Which pages are actually mandatory?

Identity and contact information is required of anyone offering services online, and in the Netherlands company registration and VAT details must be findable. A privacy statement is required wherever personal data is processed. Cookie information is required if you place non-essential cookies. Terms are required in substance for online sales, including withdrawal rights, pricing and delivery information. Other pages are good practice rather than obligations, and vary by sector.

Can we put everything on one page?

You can combine, and it is usually clearer not to. Visitors look for specific things, and regulators expect information to be easily accessible. A practical structure is a short company details block in the footer and on a contact page, a privacy statement, a cookie page if needed, and terms. What matters is that each required item is findable without hunting, not how many files it lives in.

How often should they be reviewed?

Annually as a routine, and whenever something changes: a new tool, a new service, a move, a change of legal entity, a new payment or delivery arrangement. Date each page and keep previous versions. A defect we find on inherited sites is legal pages describing a business that has since moved, renamed, changed suppliers or started selling something new.

Sources

  1. EUR-Lex: Directive 2000/31/EC on electronic commerce (accessed 2026-09-12)
  2. ACM: Checklist online verkoop (accessed 2026-09-14)