The Small-Business GDPR Compliance Checklist
A structured, step-by-step GDPR compliance checklist covering data mapping, vendor agreements, breach response, and recordkeeping, the program-level steps beyond the cookie banner basics.
Our original small-business GDPR checklist covers the fastest-to-fix basics: cookie consent, a privacy policy, and DSAR handling. This is the follow-up for going a step further, the program-level habits that make GDPR compliance durable rather than a one-time fix you did once and never revisited.
1. Build a real data inventory (not a mental one)
Write down, in an actual document: what personal data you collect, where it comes from, where it’s stored, who inside your business can access it, and which third parties it gets shared with. Update it when you add a new tool or integration, the biggest source of GDPR drift is data flows nobody wrote down in the first place.
2. Confirm your lawful basis for each type of processing
For every category of data you process, customer accounts, marketing emails, analytics, support tickets, identify which lawful basis applies: consent, contract necessity, legal obligation, or legitimate interest. See our piece on legitimate interest vs. consent for the distinction that trips people up most often, specifically around cookies and marketing.
3. Get data processing agreements (DPAs) in place with vendors
Any third-party tool that processes personal data on your behalf, your email platform, your analytics provider, your CRM, should have a data processing agreement covering how they handle that data. Most established vendors provide a standard DPA on request or in their terms; check before assuming one exists. See our full guide on what a DPA has to cover and how to get one in place if you’re starting from zero.
Usercentrics
Vendor and consent management overlap more than people expect, Usercentrics' consent records give you documentation that supports this exact recordkeeping requirement, not just the visitor-facing banner.
4. Have an actual breach response plan
GDPR requires notifying the relevant supervisory authority within 72 hours of becoming aware of certain personal data breaches, and in some cases notifying affected individuals directly. Having a plan doesn’t need to be elaborate, it needs to exist: who gets notified internally, who decides whether a regulator notification is required, and a rough timeline for both.
5. Keep records of processing activities
Depending on your size and the nature of your processing, GDPR may require maintaining a formal record of processing activities (a “ROPA”). Even where it’s not strictly mandatory at your scale, keeping a simple internal log of what you process and why is good practice and directly supports steps 1 and 2 above.
6. Revisit consent and cookie configuration periodically
Trackers and marketing tools get added over time, often by different people, without anyone re-checking that consent gating still covers everything running on the site. Make a quarterly review of your live tracker list a standing habit, not a one-time launch task, the same network-tab check described in our cookie consent requirements piece works well as a recurring audit.
7. Train whoever handles customer data directly
Anyone fielding support requests, marketing, or sales inquiries should know the basics: how to recognize a data subject access request even when a customer doesn’t use that term, and who to escalate it to.
Where this connects to the basics
If you haven’t done the fundamentals yet, a compliant cookie banner, an accurate privacy policy, a working DSAR process, start with our original checklist before this one. This list is about making that foundation durable as your business and tooling change, not a replacement for it.
This checklist is educational and not legal advice. For your specific situation, consult a privacy attorney.