Most small business websites are closer to GDPR-compliant than their owners fear — a handful of practical things are usually all that's missing. This website GDPR checklist walks through them in plain language, so you can see what you already have and what still needs doing.

GDPR (the EU's General Data Protection Regulation) is really about one simple idea: when your website collects information about people — a name in a contact form, an email for your newsletter, or a hidden tracking cookie — you handle that information carefully, tell people what you're doing, and only do what they've agreed to. That's it. The rest is detail.

A quick note before we start: this is a practical guide, not legal advice. Every business is different, and if you handle sensitive data or you're unsure, it's worth a short conversation with a lawyer. This checklist is here to help you get the obvious things right.

The website GDPR checklist at a glance

Here's the whole list. Each item is explained underneath.

  • A cookie banner that actually blocks trackers before people say yes
  • A clear, honest privacy policy people can find
  • Only collecting the form data you genuinely need — and saying why
  • A secure (https) website, so the little padlock shows in the browser
  • Data processor agreements with the services that handle your data
  • A simple way for people to ask what you hold, or to be deleted
  • Keeping data only as long as you actually need it

1. A cookie banner that really blocks trackers first

This is the item most sites get wrong. A cookie banner isn't just a pop-up that says "we use cookies" with an OK button. Under GDPR, any cookie or tracker that isn't strictly necessary — analytics, advertising pixels, embedded videos, chat widgets — must stay switched off until the visitor actively agrees. A banner that loads Google Analytics or a Facebook pixel the moment the page opens, before anyone clicks anything, is the classic mistake.

So the test is simple: does your banner let people say no as easily as yes, and does it hold the trackers back until they choose? If the "reject" option is hidden, or the trackers fire regardless of what's clicked, the banner is decorative rather than compliant. Our guide to getting cookie consent right goes deeper on this.

2. A privacy policy people can actually find

A privacy policy is a plain page that tells visitors what data you collect, why, who you share it with, and how to contact you about it. It doesn't need to be pages of legalese — honest and readable is better than long and impenetrable. Link to it in your website footer so it's on every page, and mention it near any form where people hand over their details.

If you use a template, do read it through and make it match reality. A borrowed policy that mentions services you don't use, or misses ones you do, isn't doing its job.

3. Collect only the form data you need

Every contact form, newsletter sign-up and checkout collects personal data. GDPR asks you to collect only what you genuinely need for the task at hand. A newsletter sign-up needs an email address — it probably doesn't need a phone number and a date of birth. Next to each form, tell people briefly what you'll do with their details, and don't pre-tick boxes that opt them into marketing; let them choose.

4. A secure (https) website

When someone types their name or card details into your site, that information should travel encrypted, so it can't be read in transit. That's what the little padlock in the browser bar means — your site has a valid SSL certificate (the small file that turns "http" into the secure "https"). If your site shows "Not secure" instead of a padlock, personal data is travelling in the open, which is both a GDPR weak point and something that scares customers away. Your web host or agency can usually fix this quickly, and it's often free.

5. Data processor agreements

Your website almost certainly relies on other companies to handle data for you — your web host, your email newsletter tool, your online shop platform, your booking system. In GDPR terms these are your "data processors", and you're meant to have an agreement in place with each one (usually called a Data Processing Agreement, or DPA) setting out how they'll look after the data. The good news: most reputable providers publish a standard DPA you simply accept in your account settings. Make a short list of every service that touches customer data and check each one off.

6. Let people see or delete their data

People have the right to ask what personal data you hold about them, and to ask you to delete it. You don't need a fancy system — a monitored email address on your privacy policy and contact page is enough for most small businesses. What matters is that a request doesn't vanish into a void: someone should know how to find the person's data and act on it within a reasonable time.

7. Don't keep data forever

Old data you no longer need is a liability, not an asset. Decide roughly how long you keep things — old contact-form messages, newsletter subscribers who never open anything, expired customer records — and clear them out periodically. "We keep it because we always have" isn't a reason GDPR recognises.

Where TrustCtrl fits

A checklist is only useful if you can tell where you actually stand — and some items are hard to eyeball. TrustCtrl watches your website from the outside, so there's nothing to install, and points out the trust-and-privacy gaps in plain language. SiteControl includes an on-demand cookie and consent check that visits your site in three steps — before you choose, after you reject, and after you accept — so you can see whether trackers really are held back until consent, which is exactly the item most banners fail. It also checks that your site is served securely over https, flags broken links and other quality issues, and turns each finding into a simple view for you and a technical view for your developer, with steps to fix it and how to check the fix worked. It's free during early access. TrustCtrl watches and explains — it doesn't change your site for you — so think of it as the second pair of eyes that tells you which checklist items still need doing.

Do I need a cookie banner if I only use Google Analytics?

Yes. Analytics cookies aren't "strictly necessary", so they need consent before they load, even if you use nothing else. In practice that means a banner that keeps Analytics switched off until the visitor agrees, and a genuine option to decline. A site with only Analytics still needs to get consent right.

Is a privacy policy legally required for a small website?

If your website collects any personal data at all — and a contact form or newsletter sign-up counts — then yes, you're expected to tell people what you do with it, which is what a privacy policy is for. Size doesn't exempt you. The upside is that a small, honest policy that reflects what you actually do is perfectly acceptable; it doesn't need to be long.

What happens if my small business ignores GDPR?

The headline fines are aimed at large companies, and a small business is far more likely to receive a complaint or a request to put something right than a giant penalty. But the everyday cost is quieter: customers who don't trust a site that mishandles their data, and a "Not secure" warning or an intrusive tracker that drives them away. Getting the basics right is mostly about keeping that trust.

How do I know if my cookie banner is set up correctly?

The reliable way is to check what your site loads before anyone clicks the banner. If tracking cookies or scripts fire on the first page view, the banner isn't blocking them and it needs fixing. A tool like SiteControl's consent check does this for you by visiting the site before, during and after a consent choice, so you don't have to inspect it by hand.

If someone else built your website, the question of who is accountable is worth settling before you need the answer.