Three decisions get made in the first week of a website project, usually in a hurry: the domain name, the hosting, and the content management system. They are also the three you live with for years. A design can be redone in a month. A page of copy is rewritten before lunch. A domain registered in somebody else's name, a hosting plan whose backups nobody has restored, or a CMS you cannot leave — those cost far more, and the bill arrives at the worst moment.
I came to the web without a development background, through the proprietary editors bundled with hosting plans at the time. Open-source publishing software unblocked it in 2012, for one reason more than any feature: I could take the site elsewhere.
This is the check I run on every project before anything gets designed. None of it takes an hour.
The domain name: the only question that matters is who is the registrant
A domain name is not bought. It is registered for a fixed term through a registrar, and the person or company recorded as the registrant holds the right to use it. The agency that built the site may be technical contact, billing contact, or account administrator. None of that gives the client any right over the name.
I have taken over several sites whose domain was registered in the previous provider's name, inside a shared account holding dozens of other people's domains. While the relationship is good, nobody notices. The day it ends, the owner discovers they do not own their own address.
Three checks are enough. Get direct access to the registrar account, in your company's name: access delegated by a supplier is not access. Confirm in writing that the registrant line carries the company's legal name, not an employee's. Then make sure the contact email address belongs to the business and is read, because that is where expiry notices and transfer approvals land.
Term, renewal and transfer
Registration usually runs for a year and renews. Turn on auto-renewal, but do not rely on it alone: an expired payment card is all it takes for the charge to fail quietly. I set a reminder in a calendar that has nothing to do with the host or the registrar, two months before the date. An expired domain is not lost immediately — there is a suspension period and then a redemption period — but recovery is chargeable and the site stays offline.
One French data point, quoted for what it is: Afnic, the registry for .fr, announced on 3 September 2026 that the extension had passed 4.5 million registered names. In any established extension, the short and obvious names went years ago. Pick a name you can say over the phone without spelling it, check it against registered trade marks, and take both extensions that matter for your market.
Hosting: where the data sits, and who can actually restore it
The moment your site collects anything through a form, your host is processing personal data on your behalf. Under the GDPR — and the UK GDPR, which keeps the same structure — that relationship has to be set out in a written contract. Article 28 lists what it must cover: documented instructions, confidentiality, security measures, rules for sub-processors, breach notification, and the point everyone forgets, what happens to the data at the end of the contract. Deletion, return, or transfer: pick one, in writing.
France's regulator publishes a worked example of that wording, the CNIL's model processor clauses. Serious hosts already carry equivalent terms: read them before you sign, not on the day you leave.
Server location is not a lawyer's whim either. There is no general obligation to host in a particular country, but transfers of personal data outside the UK or the EEA need a lawful mechanism: an adequacy decision, standard contractual clauses, or binding corporate rules, an area reshaped by Schrems II in July 2020. For a small company with no legal team, hosting inside a jurisdiction covered by adequacy avoids that analysis.
Backups: the answer is always yes
Ask a host whether there are backups and you will be told yes. The useful questions come after. How often? How many versions are kept? Are they held anywhere other than the production server? Who triggers a restore, and when was the last one tested?
A backup that has never been restored is a hypothesis, not a guarantee. I restore every site I maintain onto a test environment once a year. That habit is how I found out, on one project, that the database was captured nightly while the media library uploads were not. Better to learn that on a quiet Tuesday than after an incident, when a compromised site turns from a technical problem into a commercial one.
The certificate: a setting, not a purchase
Free certificates are now the norm for a brochure site or a standard shop. Let's Encrypt states in its FAQ that its default certificates are valid for 90 days, with a six-day option for highly automated setups. A short lifetime is only a problem if renewal is not automated. One question for your host, then: is renewal automatic and monitored, and what happens if it fails? An expired certificate throws a full-screen warning in every browser, and traffic drops within hours.
The CMS: the real question is how you get out
Content management systems are rarely worth arguing about on features, which converge over time. They are worth arguing about on reversibility. It also helps to know where the skills sit; the figures below come from the W3Techs daily survey of its panel, taken on 11 September 2026.
| CMS | Share among sites using a CMS | Share of the whole panel |
|---|---|---|
| WordPress | 58.8% | 40.3% |
| Shopify | 7.8% | 5.4% |
| Wix | 6.2% | 4.2% |
| Squarespace | 3.5% | 2.4% |
| Joomla | 1.6% | 1.1% |
| Drupal | 0.9% | 0.6% |
In the same survey, 31.5% of sites in the panel use none of the systems W3Techs tracks: custom builds, applications, static pages. These shares do not say which tool suits your business. They say where the skills are, which is what counts when you replace a supplier.
Three families, three levels of reversibility. A self-hosted open-source CMS moves: you take the database and the files, and change host without changing site. An online site builder is comfortable at the outset, but the export usually stops at raw content — structure, templates and settings stay with the publisher. A proprietary CMS built by an agency is the riskiest, because the same company supplies the tool and is the only one able to work on it.
The European framework is moving in a helpful direction: the Data Act has been applicable since 12 September 2025 and sets out how customers can switch data processing service providers effectively. Do not expect it to rescue a brochure site trapped in a bespoke in-house tool: a reversibility clause in the contract, naming the export format and the deadline, remains your best protection.
The checklist before you sign
- Domain: registrant is the client company, direct access to the registrar account, an internal contact address, auto-renewal plus an independent calendar reminder.
- Hosting: a server location you can name, a processor contract that meets Article 28, and the fate of the data at the end of the contract in writing.
- Backups: frequency, retention, off-server storage, restore procedure, date of the last real test.
- Certificate: automatic renewal, monitoring of failures, HTTP to HTTPS redirection in place.
- CMS: who holds the licence, what export format exists, how long a migration would take, and at what cost.
These are the situations I still meet when a redesign starts: a domain to recover from an unreachable third party, a database with no usable backup, a site to rebuild because nothing can be extracted. Treat the three choices as management decisions, not technical details. If your site is already live, run the check this quarter — a good moment to see what is left on the table in page speed and organic search, and to note what you would want from a future redesign.
Common questions
Who should be listed as the registrant of a company domain name?
The company itself, under its legal name — not the provider who built the site, and not an employee in a personal capacity. The provider can remain technical contact or account administrator, which lets them work without holding the right to the name. If you are unsure, ask to see the registration record.
What happens if a domain name is not renewed in time?
The domain stops resolving at expiry, so the site and any email addresses on it go down with it. Depending on the extension there is then a suspension period and a chargeable redemption period before the name returns to circulation. Auto-renewal reduces the risk but fails if the stored card has expired.
Does a business site have to be hosted in a particular country?
For an ordinary business site there is no general obligation, although regimes such as health data have their own rules. What does apply is that transfers of personal data outside the UK or the EEA need a lawful mechanism, such as an adequacy decision or standard contractual clauses. Hosting inside a jurisdiction covered by adequacy avoids that analysis.
How often should a site be backed up, and how often should a restore be tested?
A daily backup of files and database, kept on storage separate from the production server, suits most brochure sites; a busy shop needs more frequent captures. How many versions are retained, and how long a restore takes, matter just as much. A real restore onto a test environment once a year is the only way to confirm the backup is usable.
Can you leave an online site builder and take your site with you?
Text, images and product records can usually be exported, but structure, templates and settings stay with the publisher, so in practice the site is rebuilt elsewhere. The only real protection is to check, before committing, which export formats exist and what they contain. The domain itself transfers, provided you are the registrant.
Is a paid SSL certificate necessary for a professional site?
For a brochure site or a standard shop, a free domain-validated certificate provides the same encryption as a paid one. Paid certificates mainly add verification of the organisation's identity and a contractual support path, which some regulated contexts call for. The real issue is whether renewal is automated and failures monitored, since an expired certificate blocks visitors.
