GDPR & CCPA Compliance Checklist

Answer 18 questions to score your website's privacy compliance. Covers cookie consent, privacy policy, data processing, user rights, and more — free, no sign-up required.

0 of 18 answered0%

Cookie Consent

Do you display a cookie consent banner before setting non-essential cookies?

GDPR + CCPA

Can users accept or reject cookies by category (e.g., analytics, marketing)?

GDPR

Can users withdraw their consent at any time and is it as easy as giving consent?

GDPR

Do you keep records of when and how consent was obtained?

GDPR

Privacy Policy

Do you have a publicly accessible privacy policy?

GDPR + CCPA

Does your privacy/cookie policy list all cookies and their purposes?

GDPR + CCPA

Is your privacy policy reviewed and updated at least annually?

GDPR + CCPA

Data Processing

Do you have a documented lawful basis for each type of personal data processing?

GDPR

Do you collect only the personal data that is necessary for the stated purpose?

GDPR

Do you have Data Processing Agreements (DPAs) with all third-party vendors?

GDPR

User Rights

Can users request a copy of their personal data (Subject Access Request)?

GDPR + CCPA

Can users request deletion of their personal data?

GDPR + CCPA

Do you provide a clear 'Do Not Sell or Share My Personal Information' link? (CCPA)

CCPA

Do you ensure users are not penalized for exercising their privacy rights?

CCPA

Security

Is personal data encrypted in transit (HTTPS) and at rest?

GDPR + CCPA

Data Breach

Do you have a data breach notification plan?

GDPR + CCPA

International Transfers

If you transfer data outside the EU/EEA, do you use Standard Contractual Clauses or an adequacy decision?

GDPR

Google Consent Mode

Have you implemented Google Consent Mode v2 for Google Ads and Analytics?

GDPR

Answer at least one question to see results

Key Compliance Areas

Cookie Consent

GDPR requires explicit opt-in consent before setting non-essential cookies. Your consent banner must clearly explain what data is collected, by whom, and for what purpose.

User Rights

Both GDPR and CCPA grant users rights over their personal data — including access, deletion, and portability. You must provide clear mechanisms for exercising these rights.

Data Security

Regulations require appropriate technical and organizational measures to protect personal data. This includes encryption, access controls, and documented breach notification procedures.

Frequently Asked Questions

Automate your cookie compliance

CookieBoss handles cookie consent banners, privacy policies, and GDPR/CCPA compliance automatically. Start free with a 14-day Pro trial.