If your website has visitors from the UK or EU, GDPR applies to you, whether you’re a two-person startup or a large organisation. In the UK it’s the UK GDPR and the Data Protection Act 2018, alongside PECR (the rules on cookies and electronic marketing). The EU has its own version, and if you serve visitors in both places, you need to satisfy both.
Compliance isn’t a badge you install. It’s a set of practices, and most of them can be checked in an afternoon. Here’s how to tell where you stand.
Do you know what personal data your site collects?
This is the foundation. Personal data is anything that can identify a person, directly or indirectly, and it goes well beyond names and emails. Your site probably collects more than you think:
- Contact forms, newsletter signups, and account registrations
- Analytics data, including IP addresses and device identifiers
- Cookies and tracking pixels (Meta, LinkedIn, Google Ads)
- Embedded content like YouTube videos, maps, and chat widgets
- Payment and checkout details
- Server logs
The test: can you list every place data enters your site and where it goes afterwards? If not, start there. A simple data map, even a spreadsheet, is the most useful compliance document you can create.
Do you have a lawful basis for each use of data?
GDPR requires a lawful reason for processing personal data. The most common are consent, contract, legitimate interests, and legal obligation. Each purpose needs its own basis. Replying to an enquiry might rely on legitimate interests, while marketing emails usually need consent.
The test: for each data collection point, can you name the lawful basis and explain why it applies?
Is your cookie consent actually compliant?
This is where many sites fall down. A compliant cookie banner should:
- Block non-essential cookies until the visitor opts in. If analytics and marketing cookies fire on page load, your banner is decoration.
- Offer “Reject all” as easily as “Accept all”. Burying rejection behind extra clicks isn’t valid consent.
- Avoid pre-ticked boxes. Consent must be an active choice.
- Explain each category clearly in plain language.
- Let people change their mind at any time, via a persistent link or icon.
- Keep a record of consent.
The test: open your site in a private browser window, decline all cookies, then check your browser’s developer tools. If tracking cookies are still being set, you have a problem. Also note that PECR rules on analytics cookies have been evolving in the UK, so check the ICO’s current guidance rather than assuming last year’s advice still holds.
Is your privacy policy accurate and easy to understand?
Your privacy policy must tell people who you are, what data you collect, why, on what lawful basis, who you share it with, how long you keep it, and how to exercise their rights. It should be written in plain language, not legalese.
The most common failure is a policy that was copied from a template and no longer matches what the site does. If you’ve added a new tool or form since it was written, it’s probably out of date.
The test: read your privacy policy alongside your data map. Do they match?
Can people exercise their rights?
Individuals have the right to access their data, correct it, delete it, restrict or object to its use, and take it elsewhere. You generally have one month to respond to a request.
The test: if someone emailed asking you to delete everything you hold about them, would you know where to look and who would do it? Publish a clear contact point, and make sure someone owns the process.
Are your third-party tools and suppliers covered?
Every plugin, analytics platform, email service, and hosting provider that touches personal data is a processor working on your behalf. You need:
- A data processing agreement with each one
- An understanding of where data is transferred, especially outside the UK/EEA, and what safeguards apply
- A habit of reviewing what’s installed. Unused plugins and abandoned tracking scripts are a common source of risk.
The test: can you list your processors and show a signed agreement or terms for each?
Is the site secure?
GDPR requires “appropriate technical and organisational measures” to protect data. In practice, that means:
- HTTPS across the whole site
- Up-to-date software, frameworks, and plugins
- Strong access controls and multi-factor authentication for admin accounts
- Regular backups and a tested recovery process
- Data minimisation: don’t collect what you don’t need, and delete what you no longer need
The test: when was the last time you patched your CMS or framework, and who has admin access today?
Do you have a plan for when things go wrong?
A personal data breach that poses a risk to individuals must be reported to the ICO (or your relevant EU authority) within 72 hours of you becoming aware of it. That’s not much time to work out who to call.
The test: do you have a written breach response process, and does your team know it exists?
A quick self-audit checklist
- I’ve mapped all personal data collected through my site
- Each use has a documented lawful basis
- Non-essential cookies are blocked until consent, and rejecting is as easy as accepting
- My privacy policy is current, accurate, and readable
- I have a process for handling data subject requests
- I have agreements in place with every processor
- My site is secure and kept up to date
- I have a breach response plan
If you can tick everything, you’re in good shape. If you can’t, you’ve just built your to-do list.
Why it’s worth getting right
Fines grab the headlines, but the day-to-day case for compliance is simpler: it builds trust. Visitors are increasingly aware of how their data is used, and a site that’s transparent and respectful of their choices stands out.
This post is general information, not legal advice. For a definitive view on your situation, speak to a data protection professional or solicitor.


