
Google Reviews for Small Businesses: The New 2026 Rules and Why AI Reads Them First
AI now summarises your ratings and review gating is banned. Read our 2026 guide to Google reviews for small businesses, including how to ask properly.
In 2026 the ground under small business marketing has shifted twice at once. Studies of search behaviour suggest that around 68 per cent of Google searches in the first months of this year ended without a single click, and traffic to brand and publisher websites is reported to be down by close to half compared with three years ago. Fewer people reach your site even when your rankings hold steady.
At the same time, the tracking that made advertising cheap has quietly degraded. Chrome never did remove third-party cookies outright, but it now asks people to choose and plenty say no. Between that, tighter phone privacy settings and stricter UK rules, the audience data you rent from a platform covers a smaller and less reliable slice of real customers than it used to.
This is why first-party data has become the most valuable asset a small business can build. It is the information customers give you directly, held on ground you control, and no platform can switch it off in a product update. In this article we explain what first-party data really is, how to collect it legally, and what to actually do with it once you have it.
First-party data is anything a customer shares with you through your own channels. Email addresses and marketing consent, order history, enquiry form answers, booking details, loyalty activity, survey responses, and how people behave on your own website. You collected it, you hold it, and you can use it again tomorrow without paying anybody for permission.
Third-party data is the opposite. It is behavioural information gathered across other people’s websites by advertising networks, packaged into audiences and rented to you for as long as the platform allows. It was always a blunt instrument, and in 2026 it reflects a shrinking share of real people, which is why campaigns built mainly on it have become so much less predictable.
There is a middle ground worth knowing about. Zero-party data is what somebody tells you deliberately, such as answering “what are you shopping for today?” on a signup form. It is the most accurate information you will ever hold about a customer, because they chose to give it, and it costs nothing beyond asking one good question at the right moment.
Most businesses we work with collect far more than they realise and use almost none of it. Order records in the shop platform, enquiries sitting in an inbox, quotes in a spreadsheet, bookings in a calendar, reviews on Google, and years of purchase history on the till system. None of it does any marketing work while it sits in five separate places.
The first job is simply to find it all and write down where it lives. Make a short list of every system holding a customer name, an email address or a purchase, then note whether those records carry marketing consent. Owners are regularly surprised to discover they already hold a few thousand contacts they are perfectly entitled to email.
The second job is to stop losing it. A website that takes an enquiry and fires it into one inbox throws away data every day, whereas one that stores the enquiry properly and tags where it came from builds an asset instead. When our web design team rebuilds a site, capturing this information cleanly is part of the brief rather than an afterthought.
The UK rules are clear and the penalties have grown. Under UK GDPR and PECR you need genuine consent before setting non-essential cookies or sending marketing email, and the ICO finalised updated guidance on storage and access technologies in April 2026. The maximum penalty for getting this wrong now sits at £17.5 million rather than the old £500,000 ceiling.
In practice, compliance and good marketing point in the same direction. A cookie banner with a real reject option, a signup form that says exactly what you will send and how often, and a consent record you could produce if asked. People who opt in knowingly go on to open your emails and buy things. People who were nudged onto a list simply do not.
Two technical details matter more than most. Consent Mode v2 needs to be wired correctly if you advertise to anybody in the UK or EU, otherwise your conversion reporting quietly degrades. And keep a timestamped record of every consent, including where it was given, because that record is what turns a pile of contacts into a list you can safely use.
An email address is only worth having if the person behind it is pleased to hear from you, and that starts with the offer you make at signup. Ten per cent off is fine for retail, but a genuinely useful guide, an early access window, a service reminder or a size and fit check often performs better, because it attracts buyers rather than discount hunters.
Then ask for a little more over time. Progressive profiling means every interaction adds one small piece, such as which product range somebody cares about or roughly when they plan to buy. Two or three fields gathered gradually will teach you far more than a long form that visitors abandon halfway down the first screen.
Once the basics are running the payoff compounds, because a list you own is not exposed to an algorithm change or a rise in click costs. Our email marketing team usually begins with a welcome sequence, a browse or enquiry follow-up and a win-back message, which between them do most of the heavy lifting in the first year.
Advertising is where good data pays for itself fastest. Uploading a consented customer list to Google or Meta lets you exclude existing buyers from prospecting campaigns, bid harder for people who already know you, and build lookalike audiences from your best customers rather than from a rented segment that never fitted your business properly.
It also improves measurement, which quietly matters more. Enhanced conversions and offline conversion imports send your own securely hashed customer data back to the ad platform, so the system learns which clicks turned into real revenue instead of guessing. Our Google Ads team now treats this as a setup step rather than an optimisation to get round to later.
On your own website the same data drives sensible personalisation. Returning customers can see different messaging from first-time visitors, an abandoned basket can be recovered by email, and a loyal repeat buyer never needs the introductory offer written for somebody who has never heard of you. None of that requires expensive software, only joined-up systems.
You do not need a data project or a new platform to make progress. Start by listing every place customer information currently sits, then check which of those records carry marketing consent. That single audit almost always reveals two things at once: a usable list nobody has been emailing, and a leak where enquiries have been quietly disappearing.
Next, fix the collection. One clear signup offer on the website, a compliant cookie banner, and form submissions stored somewhere sensible and tagged by source. Then send something genuinely useful to the list you already have. A first email to a neglected list often produces more revenue in a week than a month of new advertising spend.
At Primedia we help businesses across Wales join these pieces together, from the website and its forms through to email and paid advertising built on data they own outright. If your marketing feels increasingly expensive for the results it brings back, get in touch and we will look at what you already have before recommending you spend anything more.
First-party data is customer information you collect directly through your own channels, such as email signups, orders, enquiry forms, bookings, loyalty schemes and behaviour on your own website. You own it outright, so you can keep using it without paying a platform for access, and no algorithm change can take it away from you.
First-party data comes straight from your own customers on your own channels. Third-party data is collected across other websites by advertising networks and rented to you as an audience segment. First-party data is more accurate, cheaper over time, and far more durable now that browsers and privacy rules limit cross-site tracking.
Yes, provided you do it properly. UK GDPR and PECR require genuine consent before setting non-essential cookies or sending marketing emails, and you must keep a record of that consent. Be clear about what you will send and how often, offer a real reject option on cookies, and make unsubscribing easy.
Most businesses already hold more than they think, so an audit of existing records often produces something usable within days. Building meaningfully from there takes months rather than weeks. A steady signup offer on the website plus consistent collection at the point of sale will usually show a clear return within one or two quarters.
Not at the small business stage. A decent email platform, your website forms feeding into it, and your shop or booking system connected will cover most needs. Customer data platforms become worthwhile only at larger volumes. The priority is joining up what you already run, not buying another subscription.

AI now summarises your ratings and review gating is banned. Read our 2026 guide to Google reviews for small businesses, including how to ask properly.

Third-party tracking is fading and search sends fewer clicks. Here is how small businesses build first-party data they own, legally, and use it well.

Is social commerce worth it in 2026? We look at TikTok Shop, Instagram and Facebook, what the fees cost, and which small businesses should sell there.