GDPR & CCPA Compliance Checklist
Answer 18 questions to score your website's privacy compliance. Covers cookie consent, privacy policy, data processing, user rights, and more — free, no sign-up required.
Cookie Consent
Do you display a cookie consent banner before setting non-essential cookies?
Can users accept or reject cookies by category (e.g., analytics, marketing)?
Can users withdraw their consent at any time and is it as easy as giving consent?
Do you keep records of when and how consent was obtained?
Privacy Policy
Do you have a publicly accessible privacy policy?
Does your privacy/cookie policy list all cookies and their purposes?
Is your privacy policy reviewed and updated at least annually?
Data Processing
Do you have a documented lawful basis for each type of personal data processing?
Do you collect only the personal data that is necessary for the stated purpose?
Do you have Data Processing Agreements (DPAs) with all third-party vendors?
User Rights
Can users request a copy of their personal data (Subject Access Request)?
Can users request deletion of their personal data?
Do you provide a clear 'Do Not Sell or Share My Personal Information' link? (CCPA)
Do you ensure users are not penalized for exercising their privacy rights?
Security
Is personal data encrypted in transit (HTTPS) and at rest?
Data Breach
Do you have a data breach notification plan?
International Transfers
If you transfer data outside the EU/EEA, do you use Standard Contractual Clauses or an adequacy decision?
Google Consent Mode
Have you implemented Google Consent Mode v2 for Google Ads and Analytics?
Answer at least one question to see results
Key Compliance Areas
Cookie Consent
GDPR requires explicit opt-in consent before setting non-essential cookies. Your consent banner must clearly explain what data is collected, by whom, and for what purpose.
User Rights
Both GDPR and CCPA grant users rights over their personal data — including access, deletion, and portability. You must provide clear mechanisms for exercising these rights.
Data Security
Regulations require appropriate technical and organizational measures to protect personal data. This includes encryption, access controls, and documented breach notification procedures.
Frequently Asked Questions
Automate your cookie compliance
CookieBoss handles cookie consent banners, privacy policies, and GDPR/CCPA compliance automatically. Start free with a 14-day Pro trial.