Guide
The Complete GDPR Compliance Checklist
A practical, 12-item checklist covering everything website owners need to verify for full GDPR compliance. Updated for 2026 with the latest enforcement guidance, regulatory expectations, and practical implementation steps.
The General Data Protection Regulation has been in force since May 25, 2018, and enforcement is not slowing down — it is accelerating. European data protection authorities have now issued over €7.1 billion in cumulative fines, with record-breaking penalties handed down in 2024 and 2025. Regulators are no longer focused solely on tech giants. Small and medium-sized businesses, e-commerce shops, SaaS companies, and even personal blogs are receiving complaints, audits, and fines. The European Data Protection Board’s coordinated enforcement actions mean that supervisory authorities across all 27 EU member states are actively scanning websites for violations — often using automated tools not unlike the one FixGDPR provides.
This checklist distills the regulation’s requirements into 12 concrete, actionable items that every website owner should verify. It is designed to be comprehensive without being overwhelming. Whether you operate a single-page portfolio site or a multi-country e-commerce platform, these 12 items represent the core obligations you must meet. We cover the full spectrum: from foundational activities like data mapping and establishing a lawful basis for processing, through technical requirements like cookie consent and international data transfers, to organizational measures like breach notification procedures and employee training.
For each item, we explain what it means in plain language, why it matters from both a legal and practical standpoint, and how FixGDPR can help you address it. Some items require manual effort — there is no way around that. But many of the technical and website-facing requirements can be scanned, automated, and monitored with the right tools. That is exactly what FixGDPR was built to do.
The checklist
12 Essential GDPR Compliance Items
Work through each item in order. Items 1–5 are foundational and affect nearly every website. Items 6–12 address organizational and procedural requirements that depend on your scale and data processing activities.
-
1
Data mapping and inventory
Before you can comply with the GDPR, you need to know exactly what personal data you collect, where it is stored, how it flows through your systems, and who has access to it. This is the foundation of every other compliance activity. Under Article 30, organizations are required to maintain a Record of Processing Activities (ROPA) that documents each type of personal data processing you perform.
Start by auditing every form on your website: contact forms, newsletter signups, account registration, checkout flows, and comment systems. Then look beyond forms at passive data collection: analytics scripts, tracking pixels, session recordings, heatmaps, and server logs. For each data point, document the category of data (name, email, IP address, payment details), the purpose of collection, the retention period, and any third parties it is shared with. Do not forget data collected by third-party scripts that you embed on your site — these are your responsibility too.
Many website owners are surprised to discover they collect far more personal data than they realize. A single Google Analytics implementation collects IP addresses, device fingerprints, browsing behavior, approximate location, and referral sources. A Facebook pixel tracks users across your entire site and reports that data back to Meta. Each of these data flows must be documented and justified.
How FixGDPR helps
Our compliance scanner automatically detects third-party scripts, cookies, and tracking technologies on your website. The scan report lists every data collector we find, categorized by purpose (analytics, advertising, functional, etc.), giving you a head start on your data inventory. Run a free scan to see exactly what personal data your site is collecting right now.
-
2
Lawful basis for processing
Article 6 of the GDPR requires that every processing activity has a valid legal basis. There are six lawful bases: consent, performance of a contract, legal obligation, vital interests, public task, and legitimate interests. For most website owners, the relevant ones are consent (for cookies, newsletters, and marketing), contract (for fulfilling orders or providing a service the user signed up for), and legitimate interests (for basic security measures and fraud prevention).
You must identify and document the lawful basis for each processing activity before you begin that processing — not after. You cannot retroactively change your legal basis if one proves inconvenient. If you rely on consent, that consent must meet the GDPR’s strict requirements: it must be freely given, specific, informed, and unambiguous. If you rely on legitimate interests, you must conduct a Legitimate Interest Assessment (LIA) that balances your interests against the data subject’s rights and freedoms.
Getting this wrong is one of the most common and most costly GDPR violations. Meta was fined €390 million in January 2023 precisely because it tried to rely on “contractual necessity” as its legal basis for behavioral advertising, when the correct basis was consent. The lesson is clear: choose your legal basis carefully and document your reasoning thoroughly.
How FixGDPR helps
FixGDPR’s privacy policy generator walks you through identifying the lawful basis for each of your processing activities and documents it in your privacy policy. Our scanner also flags cases where your site appears to process data without a clear legal basis — for example, loading advertising cookies before obtaining consent.
-
3
Privacy policy
Articles 13 and 14 of the GDPR prescribe a detailed list of information you must provide to individuals when you collect their personal data. This is typically done through a privacy policy (sometimes called a privacy notice). Unlike pre-GDPR privacy policies, which could be vague, boilerplate documents, a GDPR-compliant privacy policy must be specific to your actual data practices and written in clear, plain language that your audience can understand.
Your privacy policy must include: the identity and contact details of the data controller; the purposes and legal basis for each processing activity; categories of personal data collected; any recipients or categories of recipients; details of international transfers; retention periods (or criteria for determining them); all data subject rights; the right to lodge a complaint with a supervisory authority; whether data provision is a statutory or contractual requirement; and information about any automated decision-making, including profiling. If you have a Data Protection Officer, their contact details must be included as well.
The privacy policy must be easily accessible from every page of your website — typically via a link in the footer. It must be kept up to date. When you add a new analytics tool, switch email providers, or start processing data for a new purpose, your privacy policy must be updated accordingly. Regulatory audits frequently check whether the privacy policy accurately reflects a website’s actual data processing activities, and discrepancies are treated as violations.
How FixGDPR helps
FixGDPR includes a privacy policy generator that produces a fully GDPR-compliant privacy policy based on your specific data practices. Answer a guided questionnaire, and we generate a policy that covers all Article 13 and 14 requirements. The policy is hosted on your domain, version-tracked, and we alert you when regulatory changes may require an update.
-
4
Consent management
Where consent is your lawful basis for processing, the GDPR sets a high bar. Consent must be freely given, meaning the user must have a genuine choice and must not suffer negative consequences for refusing. It must be specific, meaning you need separate consent for each distinct processing purpose — a single “I agree to everything” checkbox is not valid. It must be informed, meaning the user must know exactly what they are consenting to before they agree. And it must be unambiguous, requiring a clear affirmative action like ticking an unticked box or clicking a specific button.
Pre-ticked checkboxes, consent bundled with terms of service, cookie walls that block access to a site entirely, and “by continuing to browse you accept cookies” banners are all explicitly non-compliant. The European Data Protection Board has issued multiple guidelines clarifying these requirements, and enforcement actions have confirmed them. The French CNIL fined Google €150 million specifically for making cookie rejection more difficult than acceptance — proving that the mechanics of how you present choices matter enormously.
You must also be able to demonstrate that consent was obtained. This means keeping records of when consent was given, what information was presented at the time, and the specific action the user took. Consent must be as easy to withdraw as it was to give, and users must be informed of their right to withdraw before they consent. If you change the scope of your processing, you need to obtain fresh consent for the new purposes.
How FixGDPR helps
The FixGDPR consent banner is designed from the ground up to meet every GDPR consent requirement. It presents accept and reject options with equal prominence, provides granular category-level controls, records consent with timestamps, and makes withdrawal as simple as one click. Our scanner also audits existing consent mechanisms on your site for dark patterns and compliance issues.
-
5
Cookie compliance
Cookie compliance under the GDPR (and the ePrivacy Directive, which works alongside it) requires more than simply displaying a banner. You must categorize every cookie and similar technology your website uses — strictly necessary, functional, analytics, and advertising — and ensure that non-essential cookies are not set until the user has given explicit consent for each relevant category. This is known as “prior consent” or “prior blocking,” and it is one of the most commonly violated requirements.
Many websites display a cookie banner but load Google Analytics, Facebook pixels, advertising tags, and other tracking technologies immediately on page load, before the user has interacted with the banner at all. This is a clear violation. The technical requirement is unambiguous: non-essential cookies and scripts must be blocked by default and only activated after the user affirmatively opts in to the relevant category. If a user rejects analytics cookies or simply ignores the banner, no analytics cookies should be set.
You also need to maintain a cookie declaration or cookie policy that lists each cookie by name, its provider, its purpose, its type (session or persistent), and its expiry period. This declaration must be accessible from your cookie banner and should be linked from your privacy policy. Regulators routinely check whether the cookies actually set by a website match what is described in the cookie declaration, and mismatches are flagged as violations.
How FixGDPR helps
FixGDPR’s consent banner automatically blocks non-essential cookies and scripts before consent is given. We detect and categorize cookies on your site, provide granular category controls in the banner, and generate a cookie declaration. Our scanner specifically tests whether cookies are being set before consent — the single most common technical violation we find across the 2,500+ sites we have scanned.
-
6
Data Protection Officer
Article 37 of the GDPR requires that certain organizations appoint a Data Protection Officer (DPO). A DPO is mandatory if you are a public authority or body, if your core activities require large-scale systematic monitoring of individuals (such as behavioral tracking across websites), or if your core activities involve large-scale processing of special categories of data (health data, biometric data, data about racial or ethnic origin, etc.).
Even if you are not legally required to appoint a DPO, you must still document the assessment you made and the reasoning behind your decision. Many mid-sized companies voluntarily appoint a DPO or designate someone to fulfill a similar role because having a dedicated point of contact for data protection matters simplifies compliance. If you do appoint a DPO, they must be given sufficient resources and independence to carry out their duties, and their contact details must be published in your privacy policy and communicated to your supervisory authority.
For small website owners and businesses, the practical takeaway is this: evaluate whether the DPO requirement applies to you, document your conclusion, and if it does not, designate someone internally who is responsible for data protection compliance. That person should be the one working through this checklist and maintaining your ongoing compliance posture.
How FixGDPR helps
FixGDPR’s privacy policy generator includes questions about your DPO status and incorporates the appropriate disclosures into your published policy. Our compliance reports can also serve as documentation for your DPO or data protection lead, providing an auditable record of your website’s compliance status over time.
-
7
Data Protection Impact Assessment
A Data Protection Impact Assessment (DPIA) is a structured process for identifying and minimizing data protection risks. Under Article 35, a DPIA is required whenever a type of processing is likely to result in a high risk to individuals’ rights and freedoms. The GDPR specifically mentions three scenarios that trigger this requirement: systematic and extensive profiling with significant effects, large-scale processing of special category data, and systematic monitoring of publicly accessible areas on a large scale.
In practice, a DPIA may be required if your website uses extensive behavioral profiling or tracking, processes sensitive data such as health information, implements automated decision-making that affects users, or deploys new technologies like AI-driven personalization. Your national supervisory authority may also publish a list of processing activities that require a DPIA. It is worth consulting these lists for your specific jurisdiction.
A DPIA should describe the processing, assess its necessity and proportionality, identify risks to data subjects, and outline measures to mitigate those risks. Even when a DPIA is not strictly required, conducting one is considered best practice for any significant new data processing initiative. Documenting that you considered the privacy impact of your processing activities demonstrates accountability — a core GDPR principle under Article 5(2).
How FixGDPR helps
While a full DPIA is a manual process, FixGDPR’s scanner gives you a clear picture of the tracking technologies and data processing on your website — which is the essential input for assessing whether a DPIA is needed. Our AI audit reports (Pro plan) also flag high-risk processing activities that may trigger the DPIA requirement.
-
8
Breach notification procedures
Articles 33 and 34 of the GDPR impose strict breach notification obligations. If you experience a personal data breach, you must notify your supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. If the breach is likely to result in a high risk to affected individuals, you must also notify those individuals without undue delay. The 72-hour clock is tight, and failing to meet it has itself resulted in fines.
A data breach is not limited to hacking or cyberattacks. It includes any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. This means accidental exposure of a database, sending an email to the wrong recipient, losing a laptop with unencrypted customer data, or a misconfigured server that makes user data publicly accessible are all reportable breaches. Over 400 breach notifications are filed daily across the EU.
You need a documented breach response plan before a breach occurs. This plan should designate who is responsible for assessing and reporting breaches, describe the internal escalation process, include templates for supervisory authority notifications and individual notifications, and define criteria for assessing risk severity. Regularly test this plan. When a breach happens, you will not have time to create a process from scratch — you need one ready to execute immediately.
How FixGDPR helps
FixGDPR’s continuous monitoring helps prevent breaches by detecting security misconfigurations and vulnerability indicators on your website. Our scanner checks for exposed data, missing security headers, insecure form submissions, and other technical issues that could lead to breaches. Prevention is always better than notification.
-
9
Third-party contracts and Data Processing Agreements
Article 28 of the GDPR requires that whenever you share personal data with a third party that processes it on your behalf (a “data processor”), you must have a written Data Processing Agreement (DPA) in place. This applies to a wide range of services that virtually every website uses: your hosting provider, email marketing service, analytics platform, payment processor, customer support tools, CRM, cloud storage, and any other SaaS product that handles your users’ data.
A DPA must specify the subject matter and duration of processing, the nature and purpose of processing, the types of personal data and categories of data subjects, and the obligations and rights of both the controller and processor. It must also include specific provisions requiring the processor to only act on your documented instructions, ensure confidentiality, implement appropriate security measures, assist you with data subject requests, delete data when the contract ends, and submit to audits.
Most reputable SaaS vendors now offer a standard DPA that you can sign or accept online. However, simply having a DPA is not enough — you must verify that its terms are adequate and that the vendor actually complies with them. Review your DPAs periodically, especially when vendors update their terms of service. Keep an inventory of all your processors and sub-processors, and make sure your privacy policy accurately reflects who you share data with.
How FixGDPR helps
FixGDPR’s scanner identifies every third-party service loading on your website, giving you a comprehensive list of processors you need DPAs with. Many website owners are surprised to discover third-party scripts they did not knowingly install — often added by themes, plugins, or tag managers. Our report helps you identify every data relationship you need to formalize.
-
10
Data subject rights
The GDPR grants individuals eight fundamental rights regarding their personal data: the right to be informed (Articles 13–14), the right of access (Article 15), the right to rectification (Article 16), the right to erasure or “right to be forgotten” (Article 17), the right to restrict processing (Article 18), the right to data portability (Article 20), the right to object (Article 21), and the right not to be subject to automated decision-making including profiling (Article 22). You must have processes in place to handle requests for all eight rights.
When a data subject submits a request, you generally have 30 days to respond. You must verify the requester’s identity, locate all relevant personal data across your systems, and provide a complete response. For access requests, this means providing a copy of all personal data you hold about the individual, along with supplementary information about how and why it is processed. For erasure requests, you must delete the data from all systems, including backups (within a reasonable timeframe), and inform any third parties with whom you shared the data.
Provide a clear, easy-to-find contact method for data subject requests on your website — typically an email address or form linked from your privacy policy. Train your customer service team to recognize and properly route these requests. Keep a log of all requests received and actions taken, including your response times, as this demonstrates compliance to regulators. The right to object to direct marketing must be honored immediately and without question.
How FixGDPR helps
FixGDPR’s scanner checks whether your website provides accessible contact information for data subject requests and whether your privacy policy adequately describes users’ rights. Our privacy policy generator ensures all eight GDPR rights are clearly explained with your specific contact details included. We help make sure users can actually exercise their rights.
-
11
International data transfers
Chapter V of the GDPR restricts the transfer of personal data outside the European Economic Area (EEA) unless the receiving country ensures an adequate level of data protection. Following the Schrems II ruling in July 2020, which invalidated the EU-US Privacy Shield, the legal landscape for international transfers has become significantly more complex. The EU-US Data Privacy Framework (DPF), adopted in July 2023, has restored a transfer mechanism for US companies that self-certify under the framework, but it is already facing legal challenges and its long-term stability remains uncertain.
For any transfer of personal data outside the EEA, you must have a valid transfer mechanism in place. The three primary options are: an adequacy decision by the European Commission (the receiving country has been deemed to provide adequate protection), Standard Contractual Clauses (SCCs) approved by the Commission (contractual safeguards between you and the data importer), or Binding Corporate Rules (BCRs) for intra-group transfers in multinational organizations. Since the Schrems II decision, you must also conduct a Transfer Impact Assessment (TIA) when relying on SCCs, evaluating whether the laws of the recipient country undermine the protections provided by the clauses.
Practically speaking, nearly every website that uses US-based services like Google Analytics, Cloudflare, AWS, Mailchimp, Stripe, or Intercom is transferring personal data internationally. Audit your third-party services and verify that each one operating outside the EEA has an appropriate transfer mechanism. For US services, check whether they are certified under the EU-US Data Privacy Framework. For services in other countries, check whether an adequacy decision exists or whether you have SCCs in place. Document all of this in your records of processing activities and disclose the transfers in your privacy policy.
How FixGDPR helps
FixGDPR’s scanner identifies third-party services and their geographic origins, flagging services that transfer data outside the EEA. Our report highlights which services are US-based, which are EU-based, and which load resources from other jurisdictions, so you know exactly where your international transfer obligations lie. This is especially valuable because many websites unknowingly transfer data through CDNs, font services, and embedded content.
-
12
Employee training and awareness
GDPR compliance is not purely a technical or legal exercise — it is an organizational one. Article 39(1)(b) requires that, where a DPO is appointed, they monitor compliance including “awareness-raising and training of staff involved in processing operations.” More broadly, the accountability principle under Article 5(2) means you must be able to demonstrate that appropriate measures are in place, and training is a key component regulators look for during audits and investigations.
Every employee who handles personal data — customer service agents, marketing staff, developers, HR, sales — should understand the basics of the GDPR: what personal data is, the principles of data protection, how to recognize a data subject request, what constitutes a data breach, and how to report one internally. Training should be role-specific. A developer needs to understand privacy by design and secure coding practices. A marketing team member needs to understand consent requirements and the lawful basis for direct marketing. Customer service staff need to recognize data subject access requests and know the escalation procedure.
Conduct training when employees join the organization and at regular intervals thereafter — annually at minimum, and whenever significant changes occur to your data processing practices or the regulatory landscape. Keep records of who was trained, when, and what material was covered. Some supervisory authorities have specifically cited the absence of staff training as an aggravating factor when determining fine amounts. Investing in training is one of the most cost-effective compliance measures available, because human error remains the single largest cause of data breaches.
How FixGDPR helps
FixGDPR’s detailed scan reports and AI-powered audit reports are valuable training resources in themselves. They provide concrete, specific examples of GDPR requirements in the context of your own website, making abstract regulations tangible. Share your FixGDPR compliance report with your team to illustrate what compliance looks like in practice and where your organization needs to improve.
Take action
Check your compliance automatically
Working through this checklist manually takes time. FixGDPR scans your website in 30 seconds and checks many of these items automatically — cookies, consent banners, privacy policies, third-party trackers, security headers, and more. Get your compliance score and a prioritized list of issues to fix.
Keep reading
Related Resources
What Is GDPR?
A plain-language explanation of the General Data Protection Regulation, its scope, and its key principles.
Read the guide →GDPR Cookie Consent
Everything you need to know about cookie consent requirements, banner implementation, and prior blocking.
Read the guide →Data Subject Rights
A detailed breakdown of all eight GDPR data subject rights and how to handle requests properly.
Read the guide →GDPR for Small Business
Practical guidance tailored for small businesses and startups with limited resources and budgets.
Read the guide →