The General Data Protection Regulation (GDPR) continues to be the gold standard for data privacy legislation. Even in 2026, many websites still fail basic compliance requirements—exposing them to fines up to €20 million or 4% of global annual revenue (whichever is higher).
This checklist covers the 12 key areas of GDPR compliance for websites. Use it to audit your website, identify gaps, and build a compliance roadmap.
A few numbers are worth holding on to before the list starts. The GDPR is Regulation (EU) 2016/679; it entered into force in 2016 and has applied across the EU since 25 May 2018, replacing the 1995 Data Protection Directive. Article 83(5) sets the upper fine band at €20 million or 4% of worldwide annual turnover for breaches of the basic principles, and Article 83(4) sets the lower band at €10 million or 2%. Article 33(1) allows 72 hours to notify a personal data breach, and Article 12(3) allows one month to answer an access request. Germany layers its own BDSG, recast in 2018, on top. Beside the GDPR sit the ePrivacy Directive 2002/58/EC for cookies, NIS2 — Directive (EU) 2022/2555, with transposition due by 17 October 2024 — for essential and important entities, and the EU AI Act, Regulation (EU) 2024/1689, which reaches €35 million or 7% of worldwide annual turnover under Article 99(3).
1. Data Inventory & Mapping (Data Processing Register)
You cannot protect data you don't know you have. GDPR requires a documented Records of Processing Activities (RoPA).
2. Privacy Policy & Transparency
Your privacy policy must be clear, specific, and in plain language. It must tell users exactly what you collect and why.
3. Consent Management
For non-essential processing, consent is required. It must be freely given, specific, informed, and unambiguous.
4. Data Subject Access Rights
Users have 8 core rights under GDPR. You must have processes to handle requests within 30 days.
5. Data Retention & Deletion
You cannot keep data forever. GDPR requires that personal data is "kept in a form which permits identification of data subjects for no longer than necessary."
6. Data Protection Impact Assessment (DPIA)
For high-risk processing, you must conduct a DPIA. This includes large-scale processing, monitoring, automated decision-making, or use of new technologies.
7. Third-Party Data Processors
If you use services that access personal data (hosting, analytics, CRM, payment processor), you need a Data Processing Agreement (DPA).
8. International Data Transfers
Transferring data outside the EU/EEA requires a legal mechanism. This is complex and changes frequently.
9. Data Breach Response & Notification
If you experience a data breach, you have specific obligations. Delays or failures here can result in massive fines.
10. Data Protection Officer & Governance
Depending on your organization, you may need a Data Protection Officer (DPO). You always need someone responsible for GDPR compliance.
11. Security & Encryption
GDPR requires "appropriate technical and organizational measures" to protect personal data. This means encryption, access controls, and regular security audits.
12. Regular Compliance Audits
GDPR compliance is not a one-time project. It requires ongoing monitoring and improvement.
Pro Tip: Use this checklist to generate a compliance roadmap. Prioritize high-risk items (data access requests, breach response, consent management). Allocate 1-3 months to implement basic compliance. Then continuously improve based on your audit results.
Where This Checklist Stops
A checklist is a prompt, not a legal opinion. These are its limitations, stated plainly, so you know what it does not cover.
- It is not legal advice. Article 39(1)(a) GDPR places the duty to advise on your data protection officer, not on a web page. Ask a qualified adviser before you rely on any item here.
- It is not a substitute for the text. Regulation (EU) 2016/679 runs to 99 articles and 173 recitals, and national laws add more on top — the German BDSG, for example. Twelve headings cannot stand in for that.
- A scanner finds exposure, not lawfulness. Automated scanning shows which personal data a page publishes. It cannot tell you whether Article 6(1) GDPR gave you a lawful basis to process that data in the first place.
- Regulated sectors need more. Essential and important entities also fall under NIS2, Directive (EU) 2022/2555. Providers and deployers of AI systems also fall under the EU AI Act, Regulation (EU) 2024/1689, which entered into force in 2024. Neither is covered above.
- Scan scope is bounded. One piisafe.eu scan covers at most 1,000 pages, and you may start 20 scans per hour from one IP address. A large estate needs several runs and a plan for stitching the results together.
Key Takeaways
- GDPR applies if you process data of EU residents, regardless of where you're located
- You need documented proof of compliance (privacy policy, DPA, DPIA, RoPA, breach logs)
- Consent must be explicit, informed, and easy to withdraw
- Users have strong rights: access, correction, deletion, portability, and objection
- Breaches must be reported to regulators within 72 hours
- Data cannot be kept longer than necessary
- Regular audits (including PII scanning) are essential to stay compliant
GDPR compliance requires effort, but it's not impossible. Start with this checklist, prioritize high-risk items, and build a compliance culture in your organization. Your users—and regulators—will appreciate it.