← All guidesGuide

The Small-Business GDPR Checklist

A practical, no-jargon checklist for small businesses that need to get GDPR basics right without hiring a compliance team.

Published January 18, 2026·Last updated June 30, 2026

GDPR compliance sounds like it requires a legal department, but most of what applies to a small business comes down to a manageable set of concrete steps. This checklist covers the parts that actually get enforced against small sites: consent, transparency, and data subject rights.

1. Know what personal data you collect

Make a simple inventory: contact form submissions, email list signups, analytics data, payment details if you sell online, and anything collected via cookies. You can’t comply with rules about data you haven’t mapped.

  • Cookie banners must offer an equally easy reject option, not just accept.
  • Scripts that aren’t strictly necessary (analytics, ads) must not fire until consent is given.
  • Marketing emails require opt-in consent, not a pre-checked box.
Our recommendation

Termly

If your site is small and budget is the main constraint, Termly's free tier is a reasonable starting point for a compliant, script-blocking cookie banner.

Try Termly

3. Publish a real privacy policy

Your privacy policy should plainly state what data you collect, why, who you share it with (including analytics and payment processors), how long you keep it, and how someone can exercise their rights. Avoid copy-pasted boilerplate that doesn’t match what your site actually does — mismatches are one of the most common issues in complaints.

4. Have a process for data subject requests

Under GDPR, EU visitors can ask you to:

  • Tell them what data you hold on them (access)
  • Correct inaccurate data (rectification)
  • Delete their data (erasure, with some exceptions)
  • Export their data (portability)

You don’t need automated tooling for this at small scale, but you do need a documented process — who receives the request, how you verify identity, and your target response time (30 days under GDPR).

5. Vet your third-party tools

Every analytics tool, payment processor, and embedded widget is a place personal data flows to. Confirm each has its own GDPR-compliant terms, and list the significant ones in your privacy policy.

6. Keep records

Log consent events (what was agreed to, and when) and keep a short internal note of your data inventory and vendor list. If you’re ever asked to demonstrate compliance, having this on hand is most of the work.

Quick-reference checklist

  • Data inventory: what you collect, why, and where it’s stored
  • Cookie banner with equal accept/reject and pre-consent script blocking
  • Privacy policy that matches your actual data practices
  • Opt-in (not pre-checked) marketing consent
  • Documented process for access/deletion requests
  • List of third-party processors reviewed and disclosed
  • Consent event logging

This checklist is educational and not legal advice. For a legal opinion on your specific obligations, consult a privacy attorney.