GDPR compliance checklist for websites: 15 steps with checkbox tables for data mapping, lawful basis, cookie consent, DSARs, DPAs, transfers and breaches.
GDPR compliance means that you process the personal data of people in the EU and EEA in line with the General Data Protection Regulation. In practice, you need a lawful basis for every use of data, you tell people clearly what you do with it, you respect their rights, you keep the data secure, and you can prove all of this. For a website, that usually starts with valid cookie consent, a clear privacy notice, a way to handle data requests, and a contract with every vendor that receives visitor data.
This page is a practical GDPR compliance checklist for websites. For background on the law itself, including who it applies to, the seven principles and key definitions, read our GDPR compliance guide.
Work through the 15 areas below in order. Each one has a short explanation and a checkbox table with the relevant GDPR article. Only tick an item when you can show evidence, such as a record, a signed contract, a screenshot or a log. Article 5(2) makes you responsible for demonstrating compliance, not only for achieving it.
You cannot protect data you do not know you have. Start with an inventory of every place your website and business collect personal data: contact forms, accounts, orders, analytics, advertising pixels, chat widgets and newsletters.
| Done | Task | Reference |
|---|---|---|
| ☐ | List each data source, data category, purpose and recipient | Art. 30 |
| ☐ | Record where data is stored and how long it is kept | Art. 5(1)(e), Art. 30 |
| ☐ | Scan the website for cookies and third-party tags | ePrivacy Art. 5(3) |
| ☐ | Keep a written Record of Processing Activities (RoPA) up to date | Art. 30 |
Organisations with fewer than 250 employees are exempt from keeping a RoPA only when the processing is occasional, unlikely to result in a risk and does not include special category or criminal offence data. Most websites process visitor data on a regular basis, so keep a record anyway. A cookie checker shows which cookies and trackers your site sets today.
Article 6 lists six lawful bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. Choose one for each purpose before you start processing, and document why it applies.
| Done | Task | Reference |
|---|---|---|
| ☐ | Assign and document one lawful basis per purpose | Art. 6, Art. 5(2) |
| ☐ | Complete a legitimate interests assessment where you rely on it | Art. 6(1)(f) |
| ☐ | Identify special category data and the Article 9 condition you use | Art. 9 |
| ☐ | Use consent, not legitimate interests, for non-essential cookies | ePrivacy Art. 5(3) |
Under Article 5(3) of the ePrivacy Directive, storing or reading information on a visitor's device requires consent, unless it is strictly necessary for a service the user asked for. The GDPR defines valid consent: freely given, specific, informed and unambiguous (Art. 4(11)). It must be as easy to withdraw as to give (Art. 7(3)), and you must be able to prove it (Art. 7(1)). Silence and pre-ticked boxes are not consent (Recital 32), as the Court of Justice of the EU confirmed in the Planet49 case in 2019.
| Done | Task | Reference |
|---|---|---|
| ☐ | Block non-essential cookies and tags until the visitor consents (prior blocking) | ePrivacy Art. 5(3) |
| ☐ | Make "Reject all" as easy and visible as "Accept all" | Art. 4(11), Art. 7 |
| ☐ | Offer granular choices by purpose, with no pre-ticked boxes | Art. 7, Recital 32 |
| ☐ | Explain purposes and vendors before asking for consent | Art. 7(2), Art. 13 |
| ☐ | Let visitors change or withdraw consent at any time | Art. 7(3) |
| ☐ | Store consent records: choice, time, banner version and purposes | Art. 7(1) |
In its January 2023 cookie banner taskforce report, the European Data Protection Board noted that a vast majority of authorities considered a banner with an accept option but no reject option on any layer to be non-compliant. Some regulators, such as the French CNIL, expect the reject button on the first layer. See how to set up a compliant cookie banner and keep a consent audit trail.
Your privacy notice must give people the information listed in Articles 13 and 14 in concise, plain language, at the time you collect their data.
| Done | Task | Reference |
|---|---|---|
| ☐ | Name the controller and give contact details, including the DPO if any | Art. 13(1)(a)-(b) |
| ☐ | State each purpose and its lawful basis | Art. 13(1)(c) |
| ☐ | List recipients and any transfers outside the EEA | Art. 13(1)(e)-(f) |
| ☐ | Give retention periods and explain data subject rights | Art. 13(2) |
| ☐ | Mention the right to complain to a supervisory authority | Art. 13(2)(d) |
| ☐ | Explain the source of data you did not collect from the person | Art. 14 |
| ☐ | Link the notice from every page footer and every form | Art. 12(1) |
Our privacy policy generator helps you draft a notice that covers these points.
People can ask to access, correct, delete, restrict or port their data, and can object to processing. You must respond without undue delay and within one month of receiving a request. You can extend this by two further months for complex or numerous requests, as long as you tell the person within the first month.
| Done | Task | Reference |
|---|---|---|
| ☐ | Provide a simple request channel, such as a form or privacy portal | Art. 12(2) |
| ☐ | Verify identity in a proportionate way | Art. 12(6) |
| ☐ | Log each request and its one-month deadline | Art. 12(3) |
| ☐ | Respond free of charge in normal cases | Art. 12(5) |
| ☐ | Pass corrections and deletions on to recipients | Art. 19 |
| ☐ | Stop direct marketing as soon as someone objects | Art. 21(3) |
Learn more about handling a Data Subject Access Request (DSAR) and about the UniConsent privacy portal.
A DPO is mandatory for public authorities and for organisations whose core activities involve large-scale regular and systematic monitoring of individuals, or large-scale processing of special category or criminal offence data.
| Done | Task | Reference |
|---|---|---|
| ☐ | Assess and document whether you need a DPO | Art. 37(1) |
| ☐ | Publish the DPO's contact details and notify the supervisory authority | Art. 37(7) |
| ☐ | Appoint an EU representative if you are based outside the EU | Art. 27 |
Read more: what a Data Protection Officer does.
A DPIA is required before processing that is likely to result in a high risk to people, such as extensive profiling with significant effects, large-scale processing of special category data, or large-scale systematic monitoring of public areas.
| Done | Task | Reference |
|---|---|---|
| ☐ | Screen new projects, tools and tracking for high risk | Art. 35(1) |
| ☐ | Check your national authority's list of processing that needs a DPIA | Art. 35(4) |
| ☐ | Document the DPIA and the measures that reduce risk | Art. 35(7) |
| ☐ | Consult the authority if high risk remains | Art. 36 |
See our guide to the Data Protection Impact Assessment (DPIA).
Every vendor that processes personal data on your behalf, such as hosting, email, analytics, CRM or support tools, needs a written contract with the terms set out in Article 28(3).
| Done | Task | Reference |
|---|---|---|
| ☐ | List every processor and what data it receives | Art. 28, Art. 30 |
| ☐ | Sign a Data Processing Agreement with each one | Art. 28(3) |
| ☐ | Check sub-processor approval and notification terms | Art. 28(2) |
| ☐ | Confirm data is deleted or returned when the contract ends | Art. 28(3)(g) |
Learn more about Data Processing Agreements (DPA).
Personal data can leave the EEA only with an adequacy decision, appropriate safeguards such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules, or a specific derogation. For the United States, the European Commission adopted the EU-US Data Privacy Framework adequacy decision on 10 July 2023. It covers transfers to US companies certified under the framework, and the EU General Court dismissed a challenge to it on 3 September 2025.
| Done | Task | Reference |
|---|---|---|
| ☐ | Map which vendors store or access data outside the EEA | Art. 44 |
| ☐ | Check that US vendors are certified under the Data Privacy Framework | Art. 45 |
| ☐ | Sign SCCs and assess the transfer where there is no adequacy | Art. 46 |
| ☐ | Disclose transfers in your privacy notice | Art. 13(1)(f) |
Article 32 requires appropriate technical and organisational measures, taking into account the risk. It names pseudonymisation and encryption, ongoing confidentiality and resilience of systems, the ability to restore data, and regular testing.
| Done | Task | Reference |
|---|---|---|
| ☐ | Use HTTPS across the whole website | Art. 32(1) |
| ☐ | Limit access and use multi-factor authentication for admin accounts | Art. 32(1)(b) |
| ☐ | Encrypt personal data at rest and in transit | Art. 32(1)(a) |
| ☐ | Back up data and test that you can restore it | Art. 32(1)(c) |
| ☐ | Test security regularly and train staff | Art. 32(1)(d) |
Notify your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people. Tell affected individuals without undue delay when the risk is high.
| Done | Task | Reference |
|---|---|---|
| ☐ | Write a breach response plan with named owners | Art. 33 |
| ☐ | Make processors notify you without undue delay | Art. 33(2) |
| ☐ | Notify the authority within 72 hours when required | Art. 33(1) |
| ☐ | Inform individuals when the risk is high | Art. 34 |
| ☐ | Record every breach, including those you did not report | Art. 33(5) |
When you offer online services directly to children and rely on consent, parental consent is needed for children under 16. EU countries can lower this age, but not below 13. Children also merit specific protection when their data is used for marketing or profiling (Recital 38).
| Done | Task | Reference |
|---|---|---|
| ☐ | Decide whether your website or app is aimed at children | Art. 8 |
| ☐ | Check the age of consent in each country you target | Art. 8(1) |
| ☐ | Obtain and verify parental consent where required | Art. 8(2) |
| ☐ | Write notices that children can understand | Art. 12(1) |
Electronic marketing to individuals generally needs prior consent under Article 13 of the ePrivacy Directive and national rules. The exception, often called "soft opt-in", lets you email existing customers about your own similar products if you offered an opt-out when you collected their details and in every message.
| Done | Task | Reference |
|---|---|---|
| ☐ | Use an unticked opt-in box for newsletters | Art. 7, Recital 32 |
| ☐ | Record when and how each subscriber opted in | Art. 7(1) |
| ☐ | Include an unsubscribe link in every email | ePrivacy Art. 13(2) |
| ☐ | Suppress unsubscribed and objecting contacts | Art. 21(3) |
Google's EU User Consent Policy applies to users in the EEA, the UK and Switzerland. Since March 2024, Google has required consent signals for EEA traffic to use personalisation features such as remarketing and audiences, sent through Consent Mode v2 (the ad_user_data and ad_personalization parameters) or the IAB TCF. Without these signals, advertising and measurement features are limited.
| Done | Task | Reference |
|---|---|---|
| ☐ | Use a Google-certified CMP | Google EU User Consent Policy |
| ☐ | Set consent defaults to denied before the visitor chooses | Consent Mode v2 |
| ☐ | Send ad_user_data and ad_personalization with the visitor's choice | Consent Mode v2 |
| ☐ | Test the setup with a consent mode checker | Best practice |
Read more about Google Consent Mode v2 with a certified CMP, or test your site with the Consent Mode checker.
The GDPR does not set fixed review dates, but Article 24(1) requires your measures to be reviewed and updated where necessary. A simple schedule keeps the checklist current:
| Done | What to review | Recommended frequency |
|---|---|---|
| ☐ | Website cookie and tag scan | Monthly and after each release |
| ☐ | Cookie banner and vendor list | Every time you add a tag or vendor |
| ☐ | Privacy notice | When processing changes, at least yearly |
| ☐ | RoPA, DPAs and transfer safeguards | At least yearly |
| ☐ | DPIAs | When the processing or risk changes |
| ☐ | DSAR and breach procedures, staff training | Yearly |
Article 83 sets two tiers of fines, based on the higher of a fixed amount or a percentage of total worldwide annual turnover:
| Tier | Maximum fine | Examples of infringements |
|---|---|---|
| Higher | EUR 20 million or 4% of turnover | Principles, lawful basis, consent, data subject rights, international transfers |
| Lower | EUR 10 million or 2% of turnover | Records, security, breach notification, DPO, DPIA, processors, children's consent |
Authorities can also order you to stop processing or delete data, and individuals can claim compensation (Art. 82). See recent cases in our GDPR fines and enforcement report.
The UK kept the GDPR in its own law as the UK GDPR, so the same checklist applies in the UK, with a few differences:
| EU GDPR | UK GDPR | |
|---|---|---|
| Regulator | National supervisory authorities, coordinated by the EDPB | Information Commissioner's Office (ICO) |
| Maximum fine | EUR 20 million or 4% of turnover | GBP 17.5 million or 4% of turnover |
| Cookie and email marketing rules | ePrivacy Directive, as implemented in each country | PECR, with fines raised to UK GDPR levels by the Data (Use and Access) Act 2025 from 5 February 2026 |
| Complaints | Right to complain to a supervisory authority | Since June 2026, organisations must also offer a complaints process and acknowledge complaints within 30 days |
Read the full UK GDPR guide.
UniConsent is a Google-certified, IAB TCF-registered consent management platform that covers the website items on this checklist:
Start your free trial and tick off the cookie consent part of your GDPR checklist today.
GDPR compliance means processing the personal data of people in the EU and EEA in line with the General Data Protection Regulation: a lawful basis for each purpose, clear privacy notices, respect for data subject rights, appropriate security, contracts with processors, and records that prove it.
Map the personal data and cookies your site collects, block non-essential cookies until visitors consent through a banner with equal Accept and Reject options, publish a privacy notice, offer a way to submit data requests, sign data processing agreements with vendors, secure the site and keep consent records.
Yes. The GDPR applies to organisations of any size that process the personal data of people in the EU. Organisations with fewer than 250 employees get a limited exemption from keeping records of processing, but only when the processing is occasional, low risk and does not involve sensitive data.
No. A cookie banner covers consent for cookies and tracking, but GDPR compliance also requires a privacy notice, a lawful basis for each purpose, a process for data subject requests, processor contracts, security measures and a breach response plan.
The GDPR does not set a fixed schedule, but it requires measures to be reviewed and updated where necessary. A good practice is to scan your website for cookies monthly and after each release, and to review your records, privacy notice and vendor contracts at least once a year.
Supervisory authorities can issue fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher, order you to stop processing and require data to be deleted. Individuals can also claim compensation for damage under Article 82.
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up