Back
CheckLegal AI

GDPR Compliance Checklist

49 practical checks across 12 areas, each mapped to the GDPR article or ruling behind it — built for website and SaaS teams that need to know what to fix before launch.

Check your live site against it
Scan any URL for missing policies, pre-consent trackers and cookie issues.
Run a free scan

1. Lawful basis for every processing activity

Every use of personal data needs one of the six lawful bases before processing starts — you cannot swap basis later to fix a problem.

  • Each processing activity is mapped to one lawful basis (consent, contract, legal obligation, vital interests, public task, legitimate interests). (Art. 6(1))
  • Legitimate interests assessments (LIA) are documented for any activity relying on Art. 6(1)(f). (Art. 6(1)(f))
  • Special category data (health, biometrics, beliefs) has an additional Art. 9 condition documented. (Art. 9)
  • Children's data uses age assurance and, where applicable, parental consent. (Art. 8)

2. Privacy notice that meets Art. 13/14

The privacy notice must be reachable from every page and written in clear language, not legal boilerplate.

  • Controller identity and contact details (and DPO, where appointed) are published. (Art. 13(1)(a)-(b))
  • Purposes and lawful basis are listed per processing activity, not as one generic paragraph. (Art. 13(1)(c))
  • Recipients and categories of recipients (analytics, hosting, payment, support vendors) are named. (Art. 13(1)(e))
  • Retention periods — or the criteria used to set them — are stated. (Art. 13(2)(a))
  • All data subject rights and the right to complain to a supervisory authority are described. (Art. 13(2)(b)-(d))
  • Data obtained from third parties has an Art. 14 notice sent within one month. (Art. 14(3))

3. Cookie and tracker consent

Analytics and advertising tags must not fire before consent. The CJEU ruled in Planet49 (C-673/17) that pre-ticked boxes are never valid consent.

  • Non-essential scripts are blocked until the visitor makes an affirmative choice. (ePrivacy Art. 5(3))
  • Reject is as easy and as prominent as Accept — no dark patterns. (EDPB 05/2020)
  • Consent is granular per category (analytics, functionality, advertising). (Art. 4(11))
  • Cookie duration and third-party access are disclosed before consent is given. (C-673/17 para. 81)
  • Consent can be withdrawn as easily as it was given, and proof of consent is logged. (Art. 7(3))
  • The cookie table matches an actual scan of the live site, refreshed at least quarterly. (Accountability)

4. Data subject rights operations

Rights requests carry a one-month deadline, extendable by two months for complex cases.

  • A monitored intake channel exists for access, rectification, erasure, restriction, portability and objection requests. (Art. 15-21)
  • Identity verification is proportionate and does not collect excess data. (Art. 12(6))
  • Responses are issued within one month, free of charge in ordinary cases. (Art. 12(3))
  • Erasure propagates to backups, processors and analytics tools. (Art. 17(2))
  • Portable data is exported in a structured, machine-readable format. (Art. 20)

5. Records of processing (ROPA)

The ROPA is the first document a supervisory authority asks for. The under-250-employee exemption rarely applies in practice.

  • A ROPA exists covering purposes, data categories, recipients, transfers and retention. (Art. 30(1))
  • Processor-side records are maintained where you process on behalf of others. (Art. 30(2))
  • The ROPA is reviewed whenever a new tool, vendor or feature is launched. (Art. 30)

6. Processors and vendor contracts

Every vendor touching personal data needs a written data processing agreement.

  • A DPA with Art. 28(3) clauses is signed with every processor, including analytics and AI vendors. (Art. 28(3))
  • Sub-processor changes require notice and an objection window. (Art. 28(2))
  • Vendor security is assessed before onboarding and re-reviewed periodically. (Art. 28(1))

7. International transfers

Post-Schrems II, a transfer tool alone is not enough — you need a transfer impact assessment.

  • Transfers outside the EEA are mapped, including US-hosted SaaS and CDNs. (Ch. V)
  • An adequacy decision, the 2021 SCCs, or BCRs cover each transfer. (Art. 45-47)
  • A transfer impact assessment documents supplementary measures where needed. (C-311/18)

8. Security and breach response

72 hours is the notification clock, and it starts at awareness, not at diagnosis.

  • Encryption in transit and at rest, access control and logging are implemented. (Art. 32)
  • A breach response plan names the decision-makers and the 72-hour notification path. (Art. 33(1))
  • An internal breach register records every incident, including non-notifiable ones. (Art. 33(5))
  • High-risk breaches trigger notification to affected individuals without undue delay. (Art. 34)

9. DPIAs and privacy by design

High-risk processing needs an assessment before launch, not after.

  • A DPIA is completed for large-scale monitoring, profiling, special category data or new AI features. (Art. 35)
  • Data protection by design and by default is applied to new features. (Art. 25)
  • Defaults collect the minimum data necessary for the stated purpose. (Art. 5(1)(c))

10. Retention and deletion

Storage limitation is one of the most commonly failed principles in audits.

  • A retention schedule sets a period for each data category. (Art. 5(1)(e))
  • Automated deletion or anonymisation runs on schedule, including in logs and backups. (Art. 5(1)(e))
  • Marketing lists are pruned of inactive contacts and suppression lists are respected. (Art. 5(1)(e))

11. Governance and accountability

Accountability means being able to demonstrate compliance, not just claim it.

  • A DPO is appointed where Art. 37 triggers apply, and contact details are published. (Art. 37)
  • An EU or UK representative is appointed for non-established controllers. (Art. 27)
  • Staff handling personal data receive documented training. (Art. 39(1)(b))
  • Policies are version-controlled with review dates. (Art. 5(2))

12. Website and product surface checks

These are the checks an automated scan of your live site can verify in minutes.

  • Privacy policy and terms are linked in the footer of every page. (Art. 12(1))
  • Forms use unbundled, unticked opt-ins and explain what happens to the data. (Art. 7(2))
  • No tracker fires before consent on first load. (ePrivacy Art. 5(3))
  • TLS is enforced site-wide and mixed content is eliminated. (Art. 32(1)(a))
  • Embedded third parties (maps, chat, video, fonts) are consent-gated or self-hosted. (Art. 5(3))

GDPR checklist FAQs

Who does the GDPR apply to?

The GDPR applies to any organisation established in the EU that processes personal data, and to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour — including through website analytics and advertising trackers (Art. 3).

Do I need a cookie banner to be GDPR compliant?

You need consent before storing or reading non-essential cookies and similar identifiers under Art. 5(3) of the ePrivacy Directive. A banner is the usual mechanism, but it only counts if non-essential scripts are actually blocked until the visitor opts in, rejecting is as easy as accepting, and consent is logged.

How long do I have to answer a data subject access request?

One month from receipt, extendable by a further two months for complex or numerous requests, provided you inform the requester of the extension within the first month (Art. 12(3)).

What are the GDPR fines for non-compliance?

Up to EUR 10 million or 2% of global annual turnover for administrative breaches, and up to EUR 20 million or 4% of global annual turnover for breaches of core principles, lawful basis or data subject rights (Art. 83(4)-(5)).

Can this checklist replace legal advice?

No. It is a structured starting point grounded in the GDPR text and EDPB guidance. Obligations vary by sector, jurisdiction and processing activity, so confirm your final position with a qualified adviser.

Sources

See which of these you already pass

CheckLegal AI scans your live site and returns a prioritised report in under a minute.

Scan my website

This checklist is general information, not legal advice.