Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
18-Point Statutory Audit Articles 5, 6, 12-22, 28, 32-34 Zero Data Retention

GDPR Compliance Audit Checklist & Readiness Scanner

Perform an interactive self-audit of your website, web application, or SaaS platform against European Union General Data Protection Regulation (Regulation 2016/679) requirements. Calculate your readiness score, uncover legal gaps, and export a formal audit summary.

Overall GDPR Compliance Score
0% (0 / 18 Verified)
0 / 18
Requirements Met
18 Remaining
Compliance Gaps
Severe Risk
Regulatory Exposure
€20M / 4%
Max Statutory Fine
1. Lawful Basis & Cookie Consent (Articles 6 & 7) 0/4 Met
2. Transparency & Notice (Articles 12, 13 & 14) 0/4 Met
3. Data Subject Rights & DSAR Workflows (Articles 15–22) 0/4 Met
4. Security & Technical Safeguards (Article 32) 0/3 Met
5. Governance & Breach Protocol (Articles 28, 30 & 33) 0/3 Met

5 Fatal Traps in GDPR Compliance Audits

Trap 1: Relying on 'Legitimate Interest' for Behavioral Ad Tracking (Art. 6(1)(f) Misuse) Many ad-funded web properties claim that running invasive third-party tracking cookies (such as Meta Pixel, Criteo, or Google Remarketing) falls under "legitimate business interest." The European Data Protection Board (EDPB) and Court of Justice of the EU (e.g. Meta v. Bundeskartellamt) have explicitly ruled that cross-site behavioral tracking and profiling CANNOT rely on legitimate interest—it requires unambiguous, explicit opt-in consent.
Trap 2: Failure to Execute Data Processing Agreements (DPAs) with Subprocessors (Art. 28) Using third-party SaaS tools (error monitoring like Sentry, support widgets like Intercom, hosting on AWS) without an executed Data Processing Agreement makes any data transfer to that service legally unauthorized. Even if the vendor is GDPR-compliant, your company is in direct breach of Article 28(3) until the DPA contract with standard contractual terms is signed and logged.
Trap 3: Missing the Mandatory 72-Hour Data Breach Notification Window (Art. 33) When a security breach occurs (stolen database, compromised credentials, or ransomware), Article 33 mandates that the lead Data Protection Authority must be notified within 72 hours of becoming aware of the incident. Companies that spend two weeks investigating internally before alerting authorities routinely receive the harshest Tier 2 administrative penalties.
Trap 4: Charging Fees or Creating Friction for Data Subject Access Requests (DSARs - Art. 12) Article 12(5) strictly establishes that information provided under access, erasure, or portability requests must be provided entirely free of charge. Requiring users to send notarized physical letters, call international telephone numbers, or pay administrative processing fees violates European transparency rules and triggers immediate regulatory investigation.
Trap 5: Pre-Ticked Cookie Banners & Implied Consent (Planet49 & EDPB Guidelines) Designing cookie consent banners where analytics or marketing categories are checked by default, or where scrolling the webpage is treated as "implied consent", is legally invalid. Under CJEU jurisprudence, only an active affirmative action constitutes legal assent. Pre-ticked boxes provide zero legal cover during an audit.

Frequently Asked Questions

Who does the European Union GDPR apply to?
The General Data Protection Regulation (GDPR) applies to any organization worldwide that processes the personal data of individuals located within the European Union (EU) or European Economic Area (EEA), regardless of whether the business is physically based in Europe or charges for goods and services.
What is the maximum penalty for non-compliance under GDPR?
Under GDPR Article 83, severe infringements (such as violating core data processing principles, lack of valid consent, or illegal cross-border data transfers) can result in administrative fines of up to €20 million or 4% of the company's total global annual turnover of the preceding financial year, whichever is higher.
What is the difference between a Data Controller and a Data Processor?
A Data Controller determines the purposes and means of processing personal data (i.e. your website or business). A Data Processor processes personal data solely on behalf of the controller (e.g. AWS, Stripe, Google Analytics). Controllers must execute Data Processing Agreements (DPAs) with all processors under Article 28.
What qualifies as valid cookie consent under GDPR?
Under GDPR Article 4(11) and Recital 32, consent must be freely given, specific, informed, and unambiguous. It requires an active affirmative opt-in (e.g. clicking "Accept"). Pre-ticked checkboxes, implied consent via scrolling, and cookie walls that deny access unless tracking is accepted are illegal.
How long do I have to respond to a Data Subject Access Request (DSAR)?
Under Article 12(3), you must respond to a user access, rectification, or erasure request without undue delay and at the latest within one calendar month of receipt. This may be extended by two further months where requests are complex or numerous, provided the user is notified within the first month.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement