If you run a business website, you have probably asked yourself this exact question. Maybe a customer asked. Maybe a competitor added a cookie banner and you wondered if you need one too. Maybe you just want to know where you stand.
Here is the honest answer: nobody can tell you "yes, fully compliant" from the outside, because GDPR covers more than your website. But the website part, the part your visitors and any regulator can see within seconds, is checkable. Today. In about five minutes.
This guide shows you what "compliant" actually means for a website, the five things to check, and how to check them yourself.
Scan your website for free
The fastest way to run every check below is a free scan. It measures what your website actually does when a visitor arrives, before they click anything.
Scan your siteWhat "GDPR compliant" means for a website
GDPR is a big regulation, and most of it lives inside your business: what data you store, why, for how long, and who can access it. A website check cannot see any of that.
What a website check can see is how your site treats a visitor in the first seconds. And that part carries a surprising amount of legal weight, because it is where consent happens, or fails to happen.
The core rule is simple. Under the GDPR and the ePrivacy rules that sit alongside it, your website needs a legal basis before it processes personal data, and for things like advertising trackers and analytics cookies that basis is almost always consent. Consent has to be given freely, be specific, be informed, and happen before the tracking starts, not after. That is Article 7 of the GDPR in one sentence.
So the practical question is not "do I have a cookie banner". It is: what does my website do before anyone answers the banner?
The five-minute check
Five questions. Each one is something you can verify, not something you have to take on faith.
1. Does anything load before consent?
This is the single most common problem we measure. A site shows a consent banner, and while the banner is still on screen, advertising and analytics scripts are already loading and already sending data about the visitor to third parties.
To check manually: open your site in a private browsing window, open your browser's developer tools (press F12), select the Network tab, and reload the page. Do not touch the banner. Now look at the list of requests. Domains like googletagmanager.com, facebook.net, doubleclick.net or hotjar.com in that list mean those services loaded before anyone consented.
2. Can visitors actually say no?
Look at your own banner as a stranger would. Is there a real "reject" or "decline" option, as easy to find and click as "accept"? A banner that only offers "Accept" or hides rejection behind three menus is not collecting the freely given consent the regulation describes.
3. Does saying no actually work?
This is the check almost nobody does. Click reject, then watch the Network tab again while you browse a page or two. If tracking requests keep flowing after a rejection, the banner is decoration, not consent management. We call this pattern fake consent, and it is one of the specific behaviours a scan looks for.
4. Do you know every third party on your site?
Most website owners can name two or three services they added on purpose. The average site we measure contacts many more than that, because tools load other tools. Your privacy policy is supposed to tell visitors who receives their data, and you cannot disclose what you do not know about.
5. Does your privacy policy match reality?
Read the cookies and third-parties section of your own policy next to the list from check 4. If the policy says "we use Google Analytics" and the measurement shows six advertising networks, the gap is the problem, and it is a gap anyone can find.
What a scan can and cannot tell you
A scan automates checks 1, 3 and 4, and gives you the evidence for 5. It loads your site like a first-time visitor, records every request, every cookie and every tracker that fires before consent, and shows you the list. What it reports is measurement: what your website did, at that moment, observed directly.
- A scan can show: which third parties loaded before consent, which cookies were set and by whom, whether tracking continued despite the banner, and how your site compares to others.
- A scan cannot show: how you store customer data internally, your contracts with processors, your data retention practice, or anything else that lives inside your business.
That is why we never phrase results as a legal verdict. A score of 100 means the scan found no measurable problems on the website itself. A low score means it found specific, listed behaviours worth fixing. Both are facts you can act on, not judgements.
If you find problems
The good news: website-side problems are usually configuration, not catastrophe. The typical fixes are mechanical.
- Configure your tag manager or consent tool so marketing and analytics tags wait for consent instead of firing on page load.
- Give the banner a genuine reject option, and test that rejection actually stops the tags.
- Remove third-party services you no longer use. Old marketing pixels have a way of outliving the campaign.
- Update the privacy policy to match what the measurement shows, then re-scan to confirm the two now agree.
If an agency or developer runs your site, the scan report is the exact list to hand them. "These services load before consent, please make them wait" is a clear ticket, and a re-scan afterwards shows whether it worked.
Common questions
Does GDPR even apply to my small business?
If your website has visitors from the EU and processes their personal data, the regulation applies regardless of company size. There is no small-business exemption for how a website treats visitor data. Some internal record-keeping duties are lighter for small organisations, but the consent rules your website follows are the same ones the big sites follow.
Do I need a cookie banner if I only use analytics?
Usually yes. Most analytics tools set cookies or similar identifiers, and the ePrivacy rules require consent for those in most EU countries. A small number of privacy-focused analytics tools are designed to work without consent, but standard tools like Google Analytics are not among them.
My website was built by an agency. Is compliance their problem or mine?
Legally, the website owner is the controller, so the responsibility sits with you even when the implementation was someone else's work. Practically, that means it is worth verifying what your site does rather than assuming the build was configured correctly. A measurement gives you exactly that.
I fixed everything. How often should I re-check?
Whenever the site changes: a new plugin, a new marketing tool, a redesign. Third-party scripts also change behaviour on their own over time, so an occasional re-scan even without changes is sensible. Scanning is free, so the cost of checking is a minute of your time.
One honest note to finish: this guide and any scan result are factual measurements and general information, not legal advice. For questions about your specific obligations, a data-protection professional is the right person to ask.
Scan your website for free
Ready to see where your own website stands? The scan takes about thirty seconds and shows you everything this guide described, measured on your site.
Scan your site