BLOG · GDPR CHECKLIST

GDPR Website Compliance Checklist:
18 Checks Every Site Should Pass

Cookie banners are the visible tip. These 18 checks cover everything a compliant website actually needs — consent, processors, forms, retention and data subject rights.

Updated August 2026 · Reading time: 7 minutes

Consent is where most website GDPR failures concentrate, and where regulators fine first. The ePrivacy Directive requires consent for non-essential cookies BEFORE they are set — meaning no tracking scripts fire until the visitor clicks accept. Pre-ticked boxes are invalid (Planet49 ruling), rejecting must be as easy as accepting, and the banner may not nudge users toward yes.

✅ 1. Consent before scripts

No analytics/marketing tag fires pre-consent. Verify in DevTools: block the banner and confirm no _ga/_fbp/gtag requests appear.

✅ 2. Equal reject button

"Reject all" is equally prominent and clickable as "Accept all". No hidden reject links in grey footers.

✅ 3. Granular choices

Separate categories (necessary / preferences / statistics / marketing), not one all-or-nothing toggle.

⚠️ 4. Consent log

Store timestamp, categories chosen, banner version. You must be able to prove consent, not just obtain it.

⚠️ 5. Legit interest assessed

Where you rely on legitimate interest instead of consent, a documented balancing test exists.

✅ 6. Cookie list & lifetimes

Cookie policy lists every cookie, purpose and expiry — regenerate it when tags change.

Transparency and Content

Users must be able to find out what happens to their data without effort. That means a privacy notice written in plain language, reachable from every page, that names each role correctly: you are the controller for your own site data, and often a processor for client data if you run client sites.

✅ 7. Privacy policy current

Names legal basis per processing activity, retention periods, third countries transfers, and your DPO/contact.

✅ 8. Policy reachable everywhere

Linked from footer AND from the cookie banner and every form that collects data.

✅ 9. Forms declare purpose

Each form says what the data will be used for and links to the policy. No "we may use it for marketing" surprises.

⚠️ 10. No unnecessary collection

Fields collecting data you never use are a liability, not an asset. Delete them.

Processors and Transfers

Every third-party tool that touches personal data — analytics, email marketing, hosting, fonts, chat widgets — needs a Data Processing Agreement and a transfer mechanism if data leaves the EU. US-based tools need an EU-US Data Privacy Framework certification or SCCs. Google Analytics type tools remain legally sensitive in several member states after the Schrems II line of cases.

✅ 11. Processor inventory

List every tool touching personal data with its role and DPA status.

✅ 12. DPAs signed

Standard contractual clauses or provider DPAs on file for each processor.

⚠️ 13. Transfer mechanism

Non-EU processors: DPF certified or SCCs + transfer impact assessment documented.

✅ 14. Sub-processors known

You know who your vendors sub-contract, and object rights are respected.

Rights and Response

Data subject rights are operational, not theoretical: when someone emails "delete my data" you have one month to respond (Art. 12(3)). Sites fail audits because nobody knows where the data lives or who answers such requests.

✅ 15. Request channel

A named contact (privacy@…) that is monitored. Response within one month, documented.

⚠️ 16. Access/deletion procedure

Written steps: identify the person across systems, export, delete, confirm. Test it once a year.

✅ 17. Breach plan

72-hour supervisory-authority notification path documented, with templates ready before an incident.

✅ 18. Retention enforced

Old form submissions, exports and CRM entries auto-delete on schedule. Indefinite storage is indefensible.

Going Deeper

Our GDPR e-book includes DPA templates, a records-of-processing sheet and an 8-clause contract pack for agencies.

Check Your Cookies Free →    GDPR E-Book →

Frequently Asked Questions

Is a cookie banner enough for GDPR compliance?

No. The banner handles consent (checks 1–6 above), but processors, transparency, rights-handling and retention are independent requirements — and they are where fines actually originate.

Do I need consent for anonymous analytics?

In most member states, yes, if cookies are involved. Some tools without cookies and with IP anonymisation can rely on legitimate interest, but that requires the documented balancing test in check 5. When in doubt, ask consent — it is always defensible.

What is the biggest fine risk for a normal website?

Practically: ignoring data subject requests and having no processor agreements. Both are trivially provable violations that regulators encounter constantly, unlike exotic cross-border questions.

We run client websites — what is OUR exposure?

You are usually a processor for client data: you need DPAs with clients (see our DPA guide), and your own site practices signal whether you take GDPR seriously. Enterprise clients check.

Check Your Cookies Free →    GDPR E-Book →