# What Should a Website Design Contract Include?

> A UK checklist for charities, clinics and small businesses hiring a web designer. Check ownership, GDPR terms, accessibility, payments and exit before you sign.

Source: https://elitedigitalagency.io/guides/website-design-contract-checklist/
Format: Markdown mirror of the HTML page (text/markdown). Content is identical;
the canonical, citable version is the HTML source URL above.

---
Web · Buyer’s checklist

# What should a website design contract include?

A UK checklist for charities, clinics and small businesses hiring a web designer or agency. Use it to read a proposal before you sign, with the official guidance behind each clause.

  By Kaiser Khan · Updated 25 September 2026 · 12 min read

       Quick answer A website design contract should fix the scope, price and payment stages, how the site is tested and accepted, and who owns the domain, hosting, code, designs and content. It should name an accessibility standard such as WCAG 2.2 AA, include UK GDPR processor terms where needed, and cover maintenance, warranty, changes and exit.

   Who this guide is for

UK charities, private clinics and practices, and small businesses commissioning a new website or a redesign from a freelancer or agency, including trustees and practice managers reviewing a proposal.

 Who this is not for

Anyone who needs advice on a specific contract: speak to a solicitor. It is also not written for public sector procurement, which has its own rules, or for website builder subscriptions sold on standard terms.

  General information, not legal advice. We are a web agency, so we also write these contracts from the supplier side. This is the checklist we would want a client to use on us.

## Which clauses should a website design contract cover?

At minimum, the sixteen areas below. Use the table for a first pass when a proposal arrives, then read the detail for the clauses that matter most to you.

| Clause | What to look for | Red flag |
| --- | --- | --- |
| Scope and deliverables | Named pages or templates, features, integrations, who supplies content, design rounds, browsers and devices, training, and a list of exclusions. | “Website as discussed”, or a scope that exists only in emails and calls. |
| Domain name | Registered in your organisation’s name, with your contact details and your own registrar login. | The agency or freelancer is listed as the registrant. |
| Hosting and accounts | Hosting, DNS, CMS, analytics, Search Console and email-sending accounts in your name, or with full admin access for you. | Only the agency holds the logins. |
| Code and design files | A written, signed assignment of copyright in bespoke work, usually on full payment. Design source files listed as a deliverable. | The agency “retains all intellectual property” with no licence terms, or your right to use the site ends when you stop paying for hosting. |
| Third-party components and content | A list of themes, plugins, fonts and images, with whose name each licence is in. Your own content stays yours. | Stock images or premium plugins supplied with no licence evidence. |
| Payment milestones | Payments tied to things you can check, such as design sign-off and acceptance. Recurring fees and renewal dates shown separately. | Most of the fee due before you can test anything, or the final payment due before acceptance. |
| Acceptance testing | Written acceptance criteria, a testing window, a defect list and a retest. | The site is “deemed accepted” at launch or after a very short silence. |
| Accessibility | A named standard and version, such as WCAG 2.2 Level AA, how it will be tested and who fixes failures. | “Fully accessible” with no standard, or an automated score as the only evidence. |
| UK GDPR | Article 28 processor terms if the agency will process personal data for you, with sub-processors named. | No data protection terms, even though the agency will host forms or access records. |
| Security and maintenance | Who applies updates and how quickly, backup frequency and restore tests, monitoring, support hours and response times. | “Maintenance included” with no list of tasks. |
| Warranty and bug fixes | A fixed period after acceptance in which defects in the agency’s work are fixed at no charge, with a definition of a defect. | Every fix is billed as a change from launch day. |
| SEO migration | A URL map, permanent redirects, who tests them and for how long they stay, plus Search Console access. | Old URLs left to return errors, or a guarantee of rankings. |
| Analytics and cookie consent | A list of tags and tools to be installed, how consent or a PECR exception applies, and who maintains the cookie information. | Tracking and advertising pixels added by default without a consent mechanism. |
| Change requests | A written process: description, price, timeline impact and your approval before work starts. | Changes agreed verbally, then invoiced. |
| Termination and exit | Notice periods for both sides, payment for work done, a handover list and the return or deletion of personal data. | Handover “at the agency’s discretion”, or exit fees that are not stated. |
| Insurance and liability | The types and levels of cover the agency holds, and a liability cap that makes sense next to them. | Liability excluded altogether, or capped at a token amount. |

## What should the scope and deliverables say?

Enough detail that someone outside the project could check whether the job was done. If a feature is not written down, assume it is not included.

List the pages or templates and the features that carry risk, such as a donation or booking journey or a CRM integration. Say who writes and uploads content, how many existing pages move across, how many design rounds you get, which browsers and devices are tested, and what is excluded. Our website project brief template gives you a structure to attach as a schedule.

## Who should own the domain, hosting, code, designs and content?

Your organisation should control every account and own, or hold a clear licence to, everything built for you. The legal default does not favour you: the creator of a commissioned work owns the copyright unless you agree otherwise in writing.

### Domain name

Register it in your organisation’s name, with your own registrar login. ICANN says letting a web developer or hosting provider be the registrant “is generally not considered a good practice”. It warns this “might allow that third party to challenge the registration in terms of transferring the domains away”. Give the agency delegated access instead.

### Hosting and accounts

Hosting, DNS, the CMS, analytics, Search Console, Bing Webmaster Tools, form and email services, and any code repository should be in your name, or at least give you full admin access. If the agency hosts the site on its own account, the contract should give you a full export of files and database on request.

### Code and design files

GOV.UK says that when you commission a work, “the first legal owner of copyright is the person or organisation that created the work and not you the commissioner, unless you otherwise agree it in writing”. To transfer ownership, it says “there would need to be a written, signed contract stating a transfer has taken place”. Section 90(3) of the Copyright, Designs and Patents Act 1988 says an assignment “is not effective unless it is in writing signed by or on behalf of the assignor”.

Without that, GOV.UK says a court may find an implied licence, and the commissioner “may only get a limited non-exclusive licence”. An assignment moves ownership to you. A licence is permission to use something the agency still owns. A licence can be acceptable for an agency’s reusable framework, but it should be perpetual, cover everything you need to run and change the site, and not end if you move hosting. Include design source files in the deliverables. GOV.UK also notes that moral rights cannot be assigned, although they can be waived.

### Third-party components and your content

Themes, plugins, fonts and stock images belong to their makers and are licensed, not owned. The agency cannot give you more than its own licence allows, so ask for a list showing whose name each licence is in and what happens when it renews. Your own text, photos and data should stay yours.

## How should payments be staged?

Tie each payment to something you can check, such as signed-off designs or an accepted build, not to dates alone. Keep a meaningful final payment until after acceptance testing.

A simple structure is a deposit to start, a payment at design approval and a final payment on acceptance. It should also say what happens if your feedback is late. Show VAT treatment and list recurring costs separately, including hosting, licences and maintenance, with renewal dates and notice periods. For business transactions, GOV.UK says that if no payment date is agreed, payment is late 30 days after the customer gets the invoice or the service is provided.

## How will the site be tested and accepted?

The contract should say what “finished” means, who tests it, for how long, and what happens to faults. Without that, launch day can become acceptance by default.

Link the criteria to the scope and allow a set number of working days to test on a staging site with real content. Agree how defects are logged, ranked and retested. Test the journeys that matter end to end, such as an enquiry reaching the right inbox or a donation completing. Confirm acceptance in writing, and be wary of clauses that treat launch or a short silence as acceptance.

## Which accessibility standard should the contract name?

Name WCAG 2.2 Level AA. It is the standard UK public sector websites must meet, and it gives both sides a testable benchmark.

WCAG 2.2 is a W3C Recommendation, most recently dated 12 December 2024. Level AA means meeting every Level A and Level AA success criterion. W3C says content that conforms to WCAG 2.2 also conforms to 2.0 and 2.1. Version 2.2 added criteria that affect everyday design decisions, including Focus Not Obscured (Minimum), Dragging Movements, Target Size (Minimum) and Accessible Authentication (Minimum) at AA.

GOV.UK says public sector bodies must meet WCAG 2.2 AA unless exempt. The exemptions include “non-government organisations like charities - unless they are mostly financed by public funding, provide services that are essential to the public or aimed at disabled people”. Separately, GOV.UK says “all UK service providers have a legal obligation to make reasonable adjustments under the Equality Act 2010”, or the Disability Discrimination Act 1995 in Northern Ireland. The contract should say how conformance will be tested, including manual checks, which templates are covered, who fixes failures, and how you keep new content accessible after launch.

## What does UK GDPR require if the agency handles personal data?

If the agency processes personal data on your behalf, it is likely to be your processor. The ICO says there must then be a written contract containing specific Article 28 terms. You remain the controller.

The ICO describes controllers as “the main decision-makers”, while processors “act on behalf of, and only on the instructions of, the relevant controller”. On a website project, that could include hosting form submissions, managing a CMS that holds donor or patient details, or supporting a newsletter sign-up. The ICO says: “Every time a controller uses a processor to process personal data, there must be a written contract”. It also says a controller “must only use a processor that can provide ‘sufficient guarantees’”.

The contract must set out the subject matter and duration of the processing, its nature and purpose, the type of personal data and categories of data subject, and your obligations and rights. It must also include these terms:

| Article 28 term | What it looks like on a website project |
| --- | --- |
| Documented instructions | The agency uses form submissions, user accounts and records only to run the site for you, as you instruct. |
| Duty of confidence | Staff and freelancers with access to your data are bound by confidentiality. |
| Security measures | Hosting, access control, backups and updates are described, not just promised. |
| Sub-processors | Hosting, email delivery, form and analytics providers are named, with your authorisation before any change. |
| Data subjects’ rights | The agency helps you find, export or delete a person’s data when they ask. |
| Assisting the controller | Help with security, notifying breaches to the ICO and individuals, and DPIAs when required. |
| End of the contract | At your choice, the agency deletes or returns all the personal data it processed for you. |
| Audits and inspections | The agency gives you the information needed to show it has met Article 28. |

The ICO also says processors must notify the controller of a personal data breach “without undue delay”. Transfers outside the UK must be authorised by the controller. If a processor decides the purpose and means of processing outside your instructions, the ICO says it “will be a controller”. Clinics should note that “data concerning health” is special category data, which needs extra protection. When we checked, parts of the ICO’s processor guidance were marked as under review following the Data (Use and Access) Act, so check the current version.

## Who is responsible for security and maintenance after launch?

The contract should name who applies updates, how quickly, how backups work and who you contact when something breaks. “Maintenance included” means little without a list.

The NCSC advises: “Apply updates as soon as possible, and ideally automatically”. Its best-practice timescale for internet-facing services and software is five days. Ask how CMS, plugin and theme updates are tested and applied, how often backups run, where they are stored, and when a restore was last tested. Check who renews the SSL certificate, whether uptime is monitored, and the support hours and response times. The ICO says a processor must take appropriate technical and organisational measures to keep personal data secure.

## What warranty or bug-fix period should you expect?

A fixed period after acceptance in which the agency fixes defects in its own work at no extra charge. The contract should define a defect so it is not confused with a change.

A workable definition is that the site does not do what the agreed scope and acceptance criteria say. Expect exclusions for changes you make yourself and for changes by third-party services, and check the exact wording. Agree response targets by severity: a broken donation form is not the same as a misaligned icon. After the period ends, fixes move to a maintenance plan or a stated rate.

## Who handles SEO and redirects when replacing an old site?

Decide in writing who builds the URL map, sets up permanent redirects, tests them and watches search data after launch. If no one owns this, old links can break.

Google’s site move guidance says to “prepare a URL mapping from the current URLs to their corresponding new format” and to use server-side permanent redirects, such as 301 or 308. It says to “keep the redirects for as long as possible, generally at least 1 year”. It also warns that visibility “may fluctuate temporarily during the move”. The contract should make the redirect map a deliverable you own. It should also give you Search Console access and keep the old domain renewed. A contract that guarantees rankings is a red flag: no one can promise them. If you are still deciding whether to rebuild, read is a website redesign worth it?

## What should the contract say about analytics and cookie consent?

It should say who chooses and configures analytics, tags and any consent tool, and who keeps the cookie information up to date. Under PECR, storing or accessing information on a visitor’s device needs clear information and consent, unless an exception applies.

The ICO says you must tell people what the technologies are, explain what they do and get consent, and that this applies to technologies “you incorporate from other organisations”. Consent must meet the UK GDPR standard. The ICO’s storage and access technologies guidance, published in final form on 29 April 2026, explains the exceptions, including one for statistical purposes. To rely on it, you must give “clear and comprehensive information about the purpose, and a ‘simple and free’ means to object”. The data must only be used to improve your service, and any analytics provider must act as your processor. Aggregated datasets must not allow people to be identified. The ICO is clear that “if your service uses storage or access technologies for the purposes of online advertising, you must get consent”.

In the contract, list every tag and tool to be installed. Require your approval before any new tracking is added, and say who updates the cookie information when tools change. The agency can set this up, but your organisation should decide what runs on its site.

## How should change requests work?

Through a short written process: describe the change, get the price and timeline impact, approve it in writing, then work starts.

Include a rate card, name who can approve changes on your side, and note whether a change affects the warranty or accessibility testing. Scope creep then becomes a decision rather than a surprise invoice.

## What happens if either side ends the contract?

The contract should let either side end it with notice, say what you pay for work already done, and list what is handed over. Exit terms are easiest to agree before anything goes wrong.

 A useful handover list includes:

- the domain transfer code and DNS records
- the hosting account, or a full export of files and database
- CMS admin accounts, the code repository and design source files
- ownership of analytics, tag manager and Search Console properties
- licence keys for paid themes, plugins and fonts, and the redirect map
- notes on how integrations are set up
- the return or deletion of personal data at your choice, as the ICO says the contract must require
 Set a handover timescale and a rate for reasonable help with the move.

## What insurance should the agency have?

Ask what cover the agency holds, such as professional indemnity and cyber insurance, and at what level. Then check the contract’s liability cap makes sense alongside it.

Ask to see a current certificate and check whether subcontractors are covered. Compare the cap with the project fee and with the harm a failure could cause you, such as a data breach involving patient or donor records. Do not accept a clause excluding liability altogether without advice.

## What should you ask before signing?

Ask questions whose answers you can check. A vague answer to any of these is a reason to slow down.

- Whose name will the domain, hosting and each account be in?
- What exactly will we own at the end, and when does ownership transfer?
- Which third-party themes, plugins, fonts or images will you use, and under whose licence?
- Will you process personal data for us? If so, where is it stored, and which sub-processors do you use?
- How will you test against WCAG 2.2 AA, and who fixes failures?
- How long do we have for acceptance testing, and how are defects handled?
- What is included in maintenance, and how quickly are security updates applied?
- If we are replacing a site, who builds and tests the redirects?
- What tracking will you install, and how will consent work?
- How are changes priced and approved?
- If we part ways, what do we receive, how quickly, and at what cost?
- What insurance do you hold, and what is your liability cap?

Before you ask, write your own brief using our website project brief, so every supplier quotes against the same scope.

## Sources and further reading: what did we check?

The legal and technical statements above come from these official pages, each checked on 25 September 2026. This guide is general information, not legal advice. For a specific contract, especially one involving health data or a large budget, take advice from a qualified solicitor.

- [When is a contract needed and why is it important?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/when-is-a-contract-needed-and-why-is-it-important/) (ICO). Checked 25 September 2026.
- [What needs to be included in the contract?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/what-needs-to-be-included-in-the-contract/) (ICO). Checked 25 September 2026.
- [What responsibilities and liabilities do controllers have when using a processor?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/responsibilities-and-liabilities-for-controllers-using-a-processor/) (ICO). Checked 25 September 2026.
- [What responsibilities and liabilities do processors have in their own right?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/responsibilities-and-liabilities-for-processors-in-their-own-right/) (ICO). Checked 25 September 2026.
- [A guide to controllers and processors](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/controllers-and-processors/controllers-and-processors-a-guide/) (ICO). Checked 25 September 2026.
- [What does it mean if you are a processor?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/controllers-and-processors/controllers-and-processors/what-does-it-mean-if-you-are-a-processor/) (ICO). Checked 25 September 2026.
- [What is special category data?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-is-special-category-data/) (ICO). Checked 25 September 2026.
- [What are the PECR rules? (storage and access technologies)](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-the-pecr-rules/) (ICO). Checked 25 September 2026.
- [What are the exceptions? (storage and access technologies)](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-the-exceptions/) (ICO). Checked 25 September 2026.
- [Final storage and access technologies guidance published (29 April 2026)](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/final-storage-and-access-technologies-guidance-published/) (ICO). Checked 25 September 2026.
- [Web Content Accessibility Guidelines (WCAG) 2.2](https://www.w3.org/TR/WCAG22/) (W3C). Checked 25 September 2026.
- [Understanding accessibility requirements for public sector bodies](https://www.gov.uk/guidance/accessibility-requirements-for-public-sector-websites-and-apps) (GOV.UK). Checked 25 September 2026.
- [Ownership of copyright works](https://www.gov.uk/guidance/ownership-of-copyright-works) (GOV.UK). Checked 25 September 2026.
- [License, sell or market your copyright material](https://www.gov.uk/guidance/license-sell-or-market-your-copyright-material) (GOV.UK). Checked 25 September 2026.
- [Copyright, Designs and Patents Act 1988, section 90](https://www.legislation.gov.uk/ukpga/1988/48/section/90) (legislation.gov.uk). Checked 25 September 2026.
- [Good practices for the registration and administration of domain name portfolios (Part II)](https://www.icann.org/en/blogs/details/good-practices-for-the-registration-and-administration-of-domain-name-portfolios-part-ii-23-6-2017-en) (ICANN). Checked 25 September 2026.
- [Site moves with URL changes](https://developers.google.com/search/docs/crawling-indexing/site-move-with-url-changes) (Google Search Central). Checked 25 September 2026.
- [Vulnerability management: put in place a policy to update by default](https://www.ncsc.gov.uk/collection/vulnerability-management/guidance/policy-update-by-default) (NCSC). Checked 25 September 2026.
- [Late commercial payments: charging interest and debt recovery](https://www.gov.uk/late-commercial-payments-interest-debt-recovery) (GOV.UK). Checked 25 September 2026.

   In this guide

   Scoping a new site?

 Use the project brief →

## Common questions

**Who owns the copyright in a website I paid for?**

   Not automatically you. GOV.UK says that when you commission a work, the person or organisation that created it is the first legal owner of copyright unless you agree otherwise in writing. To transfer ownership, GOV.UK says you need a written, signed contract, known as an assignment.

**Does our web designer need a data processing contract?**

   Only if they will process personal data on your behalf, for example by hosting form submissions or accessing a CMS that holds donor or patient records. In that case the ICO says there must be a written contract that includes the Article 28 terms.

**Should the domain name be registered in our organisation’s name?**

   Yes. ICANN says letting a third party such as a web developer be the registrant is generally not considered good practice, because that party could move the domain away and you may need legal steps to get it back.

**What accessibility standard should a UK website contract specify?**

   WCAG 2.2 Level AA is a sensible, testable benchmark. GOV.UK says public sector websites must meet it, and that all UK service providers have a legal obligation to make reasonable adjustments under the Equality Act 2010, or the Disability Discrimination Act 1995 in Northern Ireland.

**Do analytics cookies need consent in the UK?**

   Not always. The ICO’s guidance describes a statistical purposes exception with conditions, including clear information, a simple and free way to object, and only aggregate data used to improve the service. Storage or access for online advertising still needs consent.

## Want to put these questions to us?

 Ask us anything on this checklist before you commit, or compare our published prices first.

  Get in touch See pricing
