GDPR Compliance Checklist for Websites

GDPR compliance checklist for websites: 15 steps with checkbox tables for data mapping, lawful basis, cookie consent, DSARs, DPAs, transfers and breaches.

What Is GDPR Compliance?

GDPR compliance means that you process the personal data of people in the EU and EEA in line with the General Data Protection Regulation. In practice, you need a lawful basis for every use of data, you tell people clearly what you do with it, you respect their rights, you keep the data secure, and you can prove all of this. For a website, that usually starts with valid cookie consent, a clear privacy notice, a way to handle data requests, and a contract with every vendor that receives visitor data.

This page is a practical GDPR compliance checklist for websites. For background on the law itself, including who it applies to, the seven principles and key definitions, read our GDPR compliance guide.

How to Use This GDPR Checklist

Work through the 15 areas below in order. Each one has a short explanation and a checkbox table with the relevant GDPR article. Only tick an item when you can show evidence, such as a record, a signed contract, a screenshot or a log. Article 5(2) makes you responsible for demonstrating compliance, not only for achieving it.

1. Data Mapping and Records of Processing (Art. 30)

You cannot protect data you do not know you have. Start with an inventory of every place your website and business collect personal data: contact forms, accounts, orders, analytics, advertising pixels, chat widgets and newsletters.

DoneTaskReference
☐List each data source, data category, purpose and recipientArt. 30
☐Record where data is stored and how long it is keptArt. 5(1)(e), Art. 30
☐Scan the website for cookies and third-party tagsePrivacy Art. 5(3)
☐Keep a written Record of Processing Activities (RoPA) up to dateArt. 30

Organisations with fewer than 250 employees are exempt from keeping a RoPA only when the processing is occasional, unlikely to result in a risk and does not include special category or criminal offence data. Most websites process visitor data on a regular basis, so keep a record anyway. A cookie checker shows which cookies and trackers your site sets today.

2. Lawful Basis for Every Purpose (Art. 6)

Article 6 lists six lawful bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. Choose one for each purpose before you start processing, and document why it applies.

DoneTaskReference
☐Assign and document one lawful basis per purposeArt. 6, Art. 5(2)
☐Complete a legitimate interests assessment where you rely on itArt. 6(1)(f)
☐Identify special category data and the Article 9 condition you useArt. 9
☐Use consent, not legitimate interests, for non-essential cookiesePrivacy Art. 5(3)

3. Consent and Cookies (ePrivacy Directive and Art. 7)

Under Article 5(3) of the ePrivacy Directive, storing or reading information on a visitor's device requires consent, unless it is strictly necessary for a service the user asked for. The GDPR defines valid consent: freely given, specific, informed and unambiguous (Art. 4(11)). It must be as easy to withdraw as to give (Art. 7(3)), and you must be able to prove it (Art. 7(1)). Silence and pre-ticked boxes are not consent (Recital 32), as the Court of Justice of the EU confirmed in the Planet49 case in 2019.

DoneTaskReference
☐Block non-essential cookies and tags until the visitor consents (prior blocking)ePrivacy Art. 5(3)
☐Make "Reject all" as easy and visible as "Accept all"Art. 4(11), Art. 7
☐Offer granular choices by purpose, with no pre-ticked boxesArt. 7, Recital 32
☐Explain purposes and vendors before asking for consentArt. 7(2), Art. 13
☐Let visitors change or withdraw consent at any timeArt. 7(3)
☐Store consent records: choice, time, banner version and purposesArt. 7(1)

In its January 2023 cookie banner taskforce report, the European Data Protection Board noted that a vast majority of authorities considered a banner with an accept option but no reject option on any layer to be non-compliant. Some regulators, such as the French CNIL, expect the reject button on the first layer. See how to set up a compliant cookie banner and keep a consent audit trail.

4. Privacy Notice (Art. 13 and 14)

Your privacy notice must give people the information listed in Articles 13 and 14 in concise, plain language, at the time you collect their data.

DoneTaskReference
☐Name the controller and give contact details, including the DPO if anyArt. 13(1)(a)-(b)
☐State each purpose and its lawful basisArt. 13(1)(c)
☐List recipients and any transfers outside the EEAArt. 13(1)(e)-(f)
☐Give retention periods and explain data subject rightsArt. 13(2)
☐Mention the right to complain to a supervisory authorityArt. 13(2)(d)
☐Explain the source of data you did not collect from the personArt. 14
☐Link the notice from every page footer and every formArt. 12(1)

Our privacy policy generator helps you draft a notice that covers these points.

5. Data Subject Rights and DSARs (Art. 12 to 22)

People can ask to access, correct, delete, restrict or port their data, and can object to processing. You must respond without undue delay and within one month of receiving a request. You can extend this by two further months for complex or numerous requests, as long as you tell the person within the first month.

DoneTaskReference
☐Provide a simple request channel, such as a form or privacy portalArt. 12(2)
☐Verify identity in a proportionate wayArt. 12(6)
☐Log each request and its one-month deadlineArt. 12(3)
☐Respond free of charge in normal casesArt. 12(5)
☐Pass corrections and deletions on to recipientsArt. 19
☐Stop direct marketing as soon as someone objectsArt. 21(3)

Learn more about handling a Data Subject Access Request (DSAR) and about the UniConsent privacy portal.

6. Data Protection Officer (Art. 37)

A DPO is mandatory for public authorities and for organisations whose core activities involve large-scale regular and systematic monitoring of individuals, or large-scale processing of special category or criminal offence data.

DoneTaskReference
☐Assess and document whether you need a DPOArt. 37(1)
☐Publish the DPO's contact details and notify the supervisory authorityArt. 37(7)
☐Appoint an EU representative if you are based outside the EUArt. 27

Read more: what a Data Protection Officer does.

7. Data Protection Impact Assessment (Art. 35)

A DPIA is required before processing that is likely to result in a high risk to people, such as extensive profiling with significant effects, large-scale processing of special category data, or large-scale systematic monitoring of public areas.

DoneTaskReference
☐Screen new projects, tools and tracking for high riskArt. 35(1)
☐Check your national authority's list of processing that needs a DPIAArt. 35(4)
☐Document the DPIA and the measures that reduce riskArt. 35(7)
☐Consult the authority if high risk remainsArt. 36

See our guide to the Data Protection Impact Assessment (DPIA).

8. Processors and Data Processing Agreements (Art. 28)

Every vendor that processes personal data on your behalf, such as hosting, email, analytics, CRM or support tools, needs a written contract with the terms set out in Article 28(3).

DoneTaskReference
☐List every processor and what data it receivesArt. 28, Art. 30
☐Sign a Data Processing Agreement with each oneArt. 28(3)
☐Check sub-processor approval and notification termsArt. 28(2)
☐Confirm data is deleted or returned when the contract endsArt. 28(3)(g)

Learn more about Data Processing Agreements (DPA).

9. International Data Transfers (Art. 44 to 49)

Personal data can leave the EEA only with an adequacy decision, appropriate safeguards such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules, or a specific derogation. For the United States, the European Commission adopted the EU-US Data Privacy Framework adequacy decision on 10 July 2023. It covers transfers to US companies certified under the framework, and the EU General Court dismissed a challenge to it on 3 September 2025.

DoneTaskReference
☐Map which vendors store or access data outside the EEAArt. 44
☐Check that US vendors are certified under the Data Privacy FrameworkArt. 45
☐Sign SCCs and assess the transfer where there is no adequacyArt. 46
☐Disclose transfers in your privacy noticeArt. 13(1)(f)

10. Security of Processing (Art. 32)

Article 32 requires appropriate technical and organisational measures, taking into account the risk. It names pseudonymisation and encryption, ongoing confidentiality and resilience of systems, the ability to restore data, and regular testing.

DoneTaskReference
☐Use HTTPS across the whole websiteArt. 32(1)
☐Limit access and use multi-factor authentication for admin accountsArt. 32(1)(b)
☐Encrypt personal data at rest and in transitArt. 32(1)(a)
☐Back up data and test that you can restore itArt. 32(1)(c)
☐Test security regularly and train staffArt. 32(1)(d)

11. Data Breach Notification (Art. 33 and 34)

Notify your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people. Tell affected individuals without undue delay when the risk is high.

DoneTaskReference
☐Write a breach response plan with named ownersArt. 33
☐Make processors notify you without undue delayArt. 33(2)
☐Notify the authority within 72 hours when requiredArt. 33(1)
☐Inform individuals when the risk is highArt. 34
☐Record every breach, including those you did not reportArt. 33(5)

12. Children's Data (Art. 8)

When you offer online services directly to children and rely on consent, parental consent is needed for children under 16. EU countries can lower this age, but not below 13. Children also merit specific protection when their data is used for marketing or profiling (Recital 38).

DoneTaskReference
☐Decide whether your website or app is aimed at childrenArt. 8
☐Check the age of consent in each country you targetArt. 8(1)
☐Obtain and verify parental consent where requiredArt. 8(2)
☐Write notices that children can understandArt. 12(1)

13. Marketing Emails (ePrivacy Art. 13)

Electronic marketing to individuals generally needs prior consent under Article 13 of the ePrivacy Directive and national rules. The exception, often called "soft opt-in", lets you email existing customers about your own similar products if you offered an opt-out when you collected their details and in every message.

DoneTaskReference
☐Use an unticked opt-in box for newslettersArt. 7, Recital 32
☐Record when and how each subscriber opted inArt. 7(1)
☐Include an unsubscribe link in every emailePrivacy Art. 13(2)
☐Suppress unsubscribed and objecting contactsArt. 21(3)

14. Google Consent Mode v2 for EEA and UK Ads

Google's EU User Consent Policy applies to users in the EEA, the UK and Switzerland. Since March 2024, Google has required consent signals for EEA traffic to use personalisation features such as remarketing and audiences, sent through Consent Mode v2 (the ad_user_data and ad_personalization parameters) or the IAB TCF. Without these signals, advertising and measurement features are limited.

DoneTaskReference
☐Use a Google-certified CMPGoogle EU User Consent Policy
☐Set consent defaults to denied before the visitor choosesConsent Mode v2
☐Send ad_user_data and ad_personalization with the visitor's choiceConsent Mode v2
☐Test the setup with a consent mode checkerBest practice

Read more about Google Consent Mode v2 with a certified CMP, or test your site with the Consent Mode checker.

15. Review Cadence

The GDPR does not set fixed review dates, but Article 24(1) requires your measures to be reviewed and updated where necessary. A simple schedule keeps the checklist current:

DoneWhat to reviewRecommended frequency
☐Website cookie and tag scanMonthly and after each release
☐Cookie banner and vendor listEvery time you add a tag or vendor
☐Privacy noticeWhen processing changes, at least yearly
☐RoPA, DPAs and transfer safeguardsAt least yearly
☐DPIAsWhen the processing or risk changes
☐DSAR and breach procedures, staff trainingYearly

GDPR Fines for Non-Compliance

Article 83 sets two tiers of fines, based on the higher of a fixed amount or a percentage of total worldwide annual turnover:

TierMaximum fineExamples of infringements
HigherEUR 20 million or 4% of turnoverPrinciples, lawful basis, consent, data subject rights, international transfers
LowerEUR 10 million or 2% of turnoverRecords, security, breach notification, DPO, DPIA, processors, children's consent

Authorities can also order you to stop processing or delete data, and individuals can claim compensation (Art. 82). See recent cases in our GDPR fines and enforcement report.

GDPR vs UK GDPR

The UK kept the GDPR in its own law as the UK GDPR, so the same checklist applies in the UK, with a few differences:

EU GDPRUK GDPR
RegulatorNational supervisory authorities, coordinated by the EDPBInformation Commissioner's Office (ICO)
Maximum fineEUR 20 million or 4% of turnoverGBP 17.5 million or 4% of turnover
Cookie and email marketing rulesePrivacy Directive, as implemented in each countryPECR, with fines raised to UK GDPR levels by the Data (Use and Access) Act 2025 from 5 February 2026
ComplaintsRight to complain to a supervisory authoritySince June 2026, organisations must also offer a complaints process and acknowledge complaints within 30 days

Read the full UK GDPR guide.

How UniConsent Helps You Complete the Checklist

UniConsent is a Google-certified, IAB TCF-registered consent management platform that covers the website items on this checklist:

  • A customisable cookie banner with Accept and Reject options of equal prominence
  • Prior blocking of non-essential cookies, JavaScript tags and pixels until consent
  • An automatic cookie scanner to keep your cookie list and disclosures up to date
  • Consent logs that record each visitor's choice as proof of consent
  • Google Consent Mode v2 and IAB TCF support for EEA and UK advertising
  • A privacy portal for data requests and consent changes

Start your free trial and tick off the cookie consent part of your GDPR checklist today.

Frequently Asked Questions

What is GDPR compliance?

GDPR compliance means processing the personal data of people in the EU and EEA in line with the General Data Protection Regulation: a lawful basis for each purpose, clear privacy notices, respect for data subject rights, appropriate security, contracts with processors, and records that prove it.

How do I make my website GDPR compliant?

Map the personal data and cookies your site collects, block non-essential cookies until visitors consent through a banner with equal Accept and Reject options, publish a privacy notice, offer a way to submit data requests, sign data processing agreements with vendors, secure the site and keep consent records.

Does the GDPR apply to small businesses?

Yes. The GDPR applies to organisations of any size that process the personal data of people in the EU. Organisations with fewer than 250 employees get a limited exemption from keeping records of processing, but only when the processing is occasional, low risk and does not involve sensitive data.

Is a cookie banner enough for GDPR compliance?

No. A cookie banner covers consent for cookies and tracking, but GDPR compliance also requires a privacy notice, a lawful basis for each purpose, a process for data subject requests, processor contracts, security measures and a breach response plan.

How often should GDPR compliance be reviewed?

The GDPR does not set a fixed schedule, but it requires measures to be reviewed and updated where necessary. A good practice is to scan your website for cookies monthly and after each release, and to review your records, privacy notice and vendor contracts at least once a year.

What happens if you are not GDPR compliant?

Supervisory authorities can issue fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher, order you to stop processing and require data to be deleted. Individuals can also claim compensation for damage under Article 82.

UniConsent Consent Manager for GDPR Compliance

  • Cookies scan and disclosing
  • JavaScript tags blocking and cookies blocking
  • Google Consent Mode v2 support
  • Certified IAB CMP
  • One-tag Implementation
  • Multiple languages support
  • Easy self-serve solution
  • Learn more from GDPR Compliance Guide

Microsoft certified CMP - UniConsent CMPIAB certified CMP - UniConsent CMPIAB TCF V2 certified CMP - UniConsent CMPIAB TCF Canada certified consent manager - UniConsent CMPGoogle-certified CMP Gold tire - UniConsent CMPGoogle-certified CMP partner

Comply With Global Privacy Regulations

Trusted by 5000+ of global publishers and marketers
  • sej
  • football365
  • sharethrough
  • districtm
  • pf1
  • tower cast

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up