The Small-Business GDPR Checklist
A practical, no-jargon checklist for small businesses that need to get GDPR basics right without hiring a compliance team.
GDPR compliance sounds like it requires a legal department, but most of what applies to a small business comes down to a manageable set of concrete steps. This checklist covers the parts that actually get enforced against small sites: consent, transparency, and data subject rights.
1. Know what personal data you collect
Make a simple inventory: contact form submissions, email list signups, analytics data, payment details if you sell online, and anything collected via cookies. You can’t comply with rules about data you haven’t mapped.
2. Get consent right for cookies and marketing
- Cookie banners must offer an equally easy reject option, not just accept.
- Scripts that aren’t strictly necessary (analytics, ads) must not fire until consent is given.
- Marketing emails require opt-in consent, not a pre-checked box.
Termly
If your site is small and budget is the main constraint, Termly's free tier is a reasonable starting point for a compliant, script-blocking cookie banner.
3. Publish a real privacy policy
Your privacy policy should plainly state what data you collect, why, who you share it with (including analytics and payment processors), how long you keep it, and how someone can exercise their rights. Avoid copy-pasted boilerplate that doesn’t match what your site actually does — mismatches are one of the most common issues in complaints.
4. Have a process for data subject requests
Under GDPR, EU visitors can ask you to:
- Tell them what data you hold on them (access)
- Correct inaccurate data (rectification)
- Delete their data (erasure, with some exceptions)
- Export their data (portability)
You don’t need automated tooling for this at small scale, but you do need a documented process — who receives the request, how you verify identity, and your target response time (30 days under GDPR).
5. Vet your third-party tools
Every analytics tool, payment processor, and embedded widget is a place personal data flows to. Confirm each has its own GDPR-compliant terms, and list the significant ones in your privacy policy.
6. Keep records
Log consent events (what was agreed to, and when) and keep a short internal note of your data inventory and vendor list. If you’re ever asked to demonstrate compliance, having this on hand is most of the work.
Quick-reference checklist
- Data inventory: what you collect, why, and where it’s stored
- Cookie banner with equal accept/reject and pre-consent script blocking
- Privacy policy that matches your actual data practices
- Opt-in (not pre-checked) marketing consent
- Documented process for access/deletion requests
- List of third-party processors reviewed and disclosed
- Consent event logging
This checklist is educational and not legal advice. For a legal opinion on your specific obligations, consult a privacy attorney.