Consent and Cookies
Consent is where most website GDPR failures concentrate, and where regulators fine first. The ePrivacy Directive requires consent for non-essential cookies BEFORE they are set — meaning no tracking scripts fire until the visitor clicks accept. Pre-ticked boxes are invalid (Planet49 ruling), rejecting must be as easy as accepting, and the banner may not nudge users toward yes.
1. Consent before scripts
No analytics/marketing tag fires pre-consent. Verify in DevTools: block the banner and confirm no _ga/_fbp/gtag requests appear.
2. Equal reject button
"Reject all" is equally prominent and clickable as "Accept all". No hidden reject links in grey footers.
3. Granular choices
Separate categories (necessary / preferences / statistics / marketing), not one all-or-nothing toggle.
4. Consent log
Store timestamp, categories chosen, banner version. You must be able to prove consent, not just obtain it.
5. Legit interest assessed
Where you rely on legitimate interest instead of consent, a documented balancing test exists.
6. Cookie list & lifetimes
Cookie policy lists every cookie, purpose and expiry — regenerate it when tags change.
Transparency and Content
Users must be able to find out what happens to their data without effort. That means a privacy notice written in plain language, reachable from every page, that names each role correctly: you are the controller for your own site data, and often a processor for client data if you run client sites.
7. Privacy policy current
Names legal basis per processing activity, retention periods, third countries transfers, and your DPO/contact.
8. Policy reachable everywhere
Linked from footer AND from the cookie banner and every form that collects data.
9. Forms declare purpose
Each form says what the data will be used for and links to the policy. No "we may use it for marketing" surprises.
10. No unnecessary collection
Fields collecting data you never use are a liability, not an asset. Delete them.
Processors and Transfers
Every third-party tool that touches personal data — analytics, email marketing, hosting, fonts, chat widgets — needs a Data Processing Agreement and a transfer mechanism if data leaves the EU. US-based tools need an EU-US Data Privacy Framework certification or SCCs. Google Analytics type tools remain legally sensitive in several member states after the Schrems II line of cases.
11. Processor inventory
List every tool touching personal data with its role and DPA status.
12. DPAs signed
Standard contractual clauses or provider DPAs on file for each processor.
13. Transfer mechanism
Non-EU processors: DPF certified or SCCs + transfer impact assessment documented.
14. Sub-processors known
You know who your vendors sub-contract, and object rights are respected.
Rights and Response
Data subject rights are operational, not theoretical: when someone emails "delete my data" you have one month to respond (Art. 12(3)). Sites fail audits because nobody knows where the data lives or who answers such requests.
15. Request channel
A named contact (privacy@…) that is monitored. Response within one month, documented.
16. Access/deletion procedure
Written steps: identify the person across systems, export, delete, confirm. Test it once a year.
17. Breach plan
72-hour supervisory-authority notification path documented, with templates ready before an incident.
18. Retention enforced
Old form submissions, exports and CRM entries auto-delete on schedule. Indefinite storage is indefensible.
Going Deeper
Our GDPR e-book includes DPA templates, a records-of-processing sheet and an 8-clause contract pack for agencies.
Frequently Asked Questions
Is a cookie banner enough for GDPR compliance?
No. The banner handles consent (checks 1–6 above), but processors, transparency, rights-handling and retention are independent requirements — and they are where fines actually originate.
Do I need consent for anonymous analytics?
In most member states, yes, if cookies are involved. Some tools without cookies and with IP anonymisation can rely on legitimate interest, but that requires the documented balancing test in check 5. When in doubt, ask consent — it is always defensible.
What is the biggest fine risk for a normal website?
Practically: ignoring data subject requests and having no processor agreements. Both are trivially provable violations that regulators encounter constantly, unlike exotic cross-border questions.
We run client websites — what is OUR exposure?
You are usually a processor for client data: you need DPAs with clients (see our DPA guide), and your own site practices signal whether you take GDPR seriously. Enterprise clients check.
Related Guides
GDPR Fines in 2026: Trends and Numbers
Free Cookie Consent Checker
GDPR vs NIS2: Where the Two Laws Overlap
Free e-book: GDPR Compliance for Small Web Agencies
The complete guide is available as a free EPUB — no signup required.
Get the free e-book →Want all six guides? Complete EU Compliance Bundle — combined PDF + all EPUBs, $29.