Most GDPR checklists are written for corporations with legal departments. This one is for a small business with a website, a handful of marketing tools, and no spare week to spend on compliance reading.
It comes in two parts. Part one covers your website's visible behaviour: the things a visitor, a competitor or a regulator can verify from the outside in minutes, and that you can verify too. Part two covers the paperwork behind the website, briefly, because a checklist that pretends the website is the whole job would be misleading.
Scan your website for free
Every item in part one is something a free scan measures automatically on your site. Run it first and you will know which boxes you can already tick.
Scan your sitePart one: what your website does (verifiable today)
1. Nothing tracks visitors before they consent
The core rule of consent is that it happens first. If analytics, advertising pixels or session-recording tools load while your cookie banner is still on screen, the banner is asking a question your website has already answered. In the scans we run, loading trackers before consent is the most common measurable problem on the web.
2. The cookie banner has a real reject option
Rejecting must be as easy as accepting: one click, visible without scrolling, not hidden behind a settings maze. Consent obtained by wearing the visitor down is not the freely given consent Article 7 describes.
3. Rejecting actually stops the tracking
Click reject on your own banner, then browse a few pages. If the tracking requests keep flowing, the banner is decoration. This pattern, a banner that changes nothing, is what we flag as fake consent, and it undermines the very consent record the banner was meant to create.
4. You can name every third party your site talks to
Plugins load scripts, scripts load other scripts, and most site owners are surprised by the resulting list. You are responsible for the data those third parties receive, so the list needs to be known, current and deliberate. Remove what you no longer use.
5. Embedded content and fonts are accounted for
The forgotten corners: a YouTube embed, a Google Fonts stylesheet, a social feed widget. Each one sends the visitor's IP address to a third party the moment the page loads. Our fonts measurement alone currently lists over a thousand websites loading fonts from third-party servers before consent. Self-hosting fonts and using privacy-friendly embed modes solves most of this.
6. Nothing is stored on the visitor's device before consent (cookies and beyond)
The rule behind the cookie banner is broader than cookies. Under the EU ePrivacy rules, which every member state has written into national law, a website may not store information on a visitor's device, or read information already stored there, without consent. The only exceptions are storage strictly necessary for the service the visitor asked for (a shopping basket, a login session) or for the communication itself.
That wording is deliberately technology-neutral: it covers cookies, but equally localStorage and other browser storage that tracking tools use precisely because no one is watching for it. Check what lands in a visitor's browser before they have answered the banner, and remember that third-party scripts sometimes write cookies under your own domain name, which makes them easy to miss.
7. Your privacy policy matches measured reality
The policy should name the third parties your site actually uses, what they receive, and why. A policy that lists two tools while the site contacts fifteen is a public, checkable gap. Update the policy whenever the toolset changes.
8. The site runs on HTTPS everywhere
Encrypted transmission is baseline security for any form field, from a contact form to a checkout. Mixed content (an HTTPS page loading HTTP resources) counts against this too. Most hosting providers make full HTTPS a checkbox these days.
Part two: the paperwork behind the website
A scan cannot see these, and this guide will not pretend to cover them fully, but a small-business checklist that stopped at the website would give you false comfort. This is the deliberate minimum: the duties that apply to a typical small business anywhere in the EU, Finland included, with none of the extras that only large or high-risk organisations need. In plain terms:
- Know your lawful basis. For each thing you do with personal data (newsletter, orders, analytics), be able to say which legal ground it rests on: consent, contract, or legitimate interest.
- Keep a simple record of processing. A one-page table of what data you collect, why, where it lives and how long you keep it covers the core of the Article 30 duty for a small operation.
- Have agreements with your processors. The companies handling data for you (email provider, host, payment service) should each have a data-processing agreement. Established providers offer one as standard; the task is knowing you have accepted it.
- Be ready for data-subject requests. If a customer asks what data you hold or wants it deleted, you need a way to answer within a month.
- Know the breach basics. Serious personal-data breaches must be reported to your data-protection authority within 72 hours of discovery. Knowing who would do that, and where, is the small-business version of a breach plan.
A sensible order to work in
Measure first: scan the site and see which part-one items already pass. Fix the website behaviour next, because it is the publicly visible part and usually a configuration job rather than a legal one. Then bring the policy in line with the now-clean measurement, and finish with the part-two paperwork at a calm pace. Re-scan after each change; the score moving is your confirmation that the fix took.
Common questions
If I tick every box, am I fully GDPR compliant?
No checklist can honestly promise that, including this one. Part one covers what is measurable on the website, part two sketches the main internal duties, and together they cover the ground where small businesses most often have problems. Compliance in full is broader and depends on what your business does with data.
Do I need a data protection officer?
Most small businesses do not. The duty applies to public authorities and to organisations whose core activities involve large-scale monitoring or large-scale processing of sensitive data. A typical small company website is nowhere near that threshold, though nothing stops you naming a person responsible anyway.
My site was built from a template. Does the checklist still apply?
Yes, and template sites deserve extra attention: themes and plugins often bundle fonts, analytics and embed widgets that load third-party resources you never consciously chose. The measurement shows what your template actually shipped with.
How long does it take to fix the website items?
Usually hours rather than weeks. Most part-one failures come down to tag and consent-tool configuration, removing unused services, and self-hosting fonts. A developer with the scan report in hand has a precise task list to work from.
This checklist and any scan result are factual measurements and general information, not legal advice. For questions about your specific obligations, a data-protection professional is the right person to ask.
Scan your website for free
Start with the measurement: a free scan checks every part-one item on your website in about thirty seconds and shows exactly what loads before consent.
Scan your site