Free GDPR Compliance Checklist.

Review website controls for collection, consent, deletion and vendor oversight.

Mark requirements complete, incomplete or not applicable to reveal gaps.

Use the checklist to prepare privacy questions and professional review.

Review your GDPR controls

Checklist progress

1 / 3

Lawful collection

Educational guidance only. This checklist is not legal advice.

Why it matters

Turn a broad regulation into concrete checks.

GDPR obligations span product design, marketing, analytics, security, support and vendor management, so responsibilities can disappear between teams. Translating those obligations into controls creates an inventory of what must exist, who owns it and what evidence demonstrates that it works.

The checklist encourages teams to examine lawful collection, transparency, consent, retention, access controls and individual rights as connected parts of one operating system. That structure makes vague concerns easier to discuss, prioritize and assign instead of leaving privacy work dependent on memory or occasional reviews.

A structured review can surface missing consent flows, undocumented processors, unclear retention periods and unresolved data-rights procedures before they contribute to a complaint or incident.

Lawful collection

Confirm every data purpose and legal basis is clearly documented.

User rights

Review data-rights procedures, owners, timelines and identity checks.

Security controls

Match access, encryption and incident safeguards to data sensitivity.

Accountability

Find documentation gaps, assign owners and retain supporting evidence.

How to use

Review, mark and resolve.

Complete the checklist with the people responsible for your website, data and customer operations.

  1. Review each requirement

    Review each control with the responsible owner and compare your answer against current policies, contracts and technical evidence.

  2. Choose a status

    Choose complete, incomplete or not applicable, then record evidence and explain every exclusion or uncertain answer.

  3. Work through the gaps

    Prioritize incomplete controls, assign an owner and follow-up date, then verify every implemented correction with reliable evidence.

FAQs

GDPR Compliance Checklist FAQ

Important context before using the checklist for your website.

Get more from your analytics.

Start tracking your traffic with cookieless, privacy-first analytics and ask your data questions through the AI tools you already use.