Skip to main content

What Is GDPR Compliance? A How-To Guide and GDPR Compliance Checklist (2026)

"What is GDPR Compliance?" header banner. Lock icon with legal docs.

If you have ever clicked “accept cookies” on a European website or received an email from a company about updated privacy terms, you have already encountered GDPR and the likely effects of a company’s GDPR compliance efforts. It is one of the most influential privacy laws in the world, and it affects far more organizations than most people realize.

This GDPR compliance guide covers GDPR requirements, who it applies to, and what happens when companies get it wrong. From there, we’ll walk through GDPR compliance strategies and how to become GDPR compliant, plus a GDPR compliance checklist you can use to track your progress.

What Does it Mean to be GDPR Compliant?

GDPR compliance is meeting the legal requirements the General Data Protection Regulation sets for how organizations collect, use, share, and protect the personal data of anyone located in the EU or EEA, and being able to prove it when asked. The regulation does not just list practices to avoid. It specifies the technical and organizational safeguards you need in place, the legal basis required for every use of personal data, and the documentation you need to keep on hand to show a regulator that your practices hold up under scrutiny, not just that they exist on paper.

Compliance rests on two pillars. The first is a set of obligations that shape how you’re allowed to collect and use personal data in the first place: having a valid legal basis before you process anything, limiting that processing to a stated purpose, keeping data accurate and secure, and having a breach response plan ready. The second is a set of eight rights guaranteed to every individual whose data you handle. These give individuals real, enforceable control over their own information and give your organization real, documented work to do in order to honor it.

What Is GDPR?

GDPR, or the General Data Protection Regulation, is a data privacy law passed by the European Union in 2016 and enforced starting May 25, 2018. GDPR governs how organizations collect, store, use, and share the personal data of people in the EU and the European Economic Area.

Personal data under GDPR covers anything that can identify a person, directly or indirectly. This includes names, email addresses, phone numbers, IP addresses, location data, cookie identifiers, and biometric information.

Why was the GDPR introduced? The EU adopted it to replace the outdated 1995 Data Protection Directive, which had grown inconsistent across member states and never anticipated how much personal data would move through cloud storage, mobile apps, and global networks by the 2010s.  

The Core Principles of GDPR

These principles exist because GDPR treats data protection as a fundamental right. Article 1 of GDPR states this purpose plainly: to protect people’s fundamental rights and freedoms, particularly their right to protect their personal data, while ensuring that free movement of that data “shall be neither restricted nor prohibited” within the EU. The principles below carry out both halves of that purpose. They give individuals control over their information, and they give businesses one consistent standard to build on instead of a patchwork of conflicting national rules that would slow data and commerce from moving across EU borders. The principles below aren’t just guardrails against fines, but the terms of the trust that makes it possible for data to flow across borders in the first place.

Here are the core principles that organizations must follow when handling personal data:

  • Lawfulness, fairness, and transparency. Data must be collected with a valid legal basis and processed in ways people would reasonably expect.
  • Purpose limitation. Data collected for one purpose should not be reused for an unrelated purpose without new consent.
  • Data minimization. Organizations should only collect data that is necessary for the stated purpose.
  • Accuracy. Personal data must be kept accurate and up to date.
  • Storage limitation. Data should not be kept longer than necessary.
  • Integrity and confidentiality. Organizations must secure data against unauthorized access, loss, or damage.
  • Accountability. Organizations must be able to demonstrate their compliance, not just claim it.

Following these principles is what earns a company the right to keep collecting and using data at all; fines are just the enforcement mechanism behind them. A principle-based approach also helps an organization to keep compliance in mind as they launch marketing campaigns and build websites.

Who Does GDPR Apply To?

GDPR’s scope has nothing to do with where a company’s headquarters sits. A company headquartered anywhere in the world is still covered if it has an established presence in the EU or EAA, such as a branch or subsidiary, and GDPR applies to its processing regardless of where the person whose data it is happens to be located. Separately, even a company with no EU presence at all falls under GDPR if it offers goods or services to, or monitors the behavior of, someone physically located in the EU or EEA at the time their data is collected.  

EU and EEA Organizations

Any business, nonprofit, or government body operating in the EU or EEA must comply with GDPR when it processes personal data. There’s a narrow exemption from one specific requirement, record-keeping, for organizations under 250 employees, but it only applies to occasional, low-risk processing, which rules out nearly every business collecting customer or website data on an ongoing basis.

Companies Outside the EU

GDPR also applies to organizations outside the EU if they offer goods or services to people in the EU, or if they monitor the behavior of people in the EU, for example through analytics or advertising cookies on a website. A retailer based in the United States that ships to European customers, or a SaaS company with European site visitors, falls under GDPR’s reach even without a physical presence in Europe.

What Rights Does GDPR Give Individuals?

GDPR gives people, referred to as data subjects, a set of rights so that they have legal power over their own information rather than leaving it entirely in the hands of whoever collects it. The rights below are what control actually looks like in practice:

  • The right to be informed about how their data is collected and used, typically satisfied through a clear privacy notice
  • The right to access the data a company holds about them
  • The right to correct inaccurate data
  • The right to erasure, often called the right to be forgotten
  • The right to restrict how their data is processed
  • The right to data portability, so that they can transfer their data between services
  • The right to object to certain processing, including direct marketing
  • Rights related to automated decision making and profiling

Companies typically fulfill these through a data subject access request, or DSAR, process. If your organization cannot locate or produce someone’s data within the required timeframe, that is a compliance issue worth addressing before a regulator or a customer surfaces it for you.

GDPR Penalties and Fines

What happens if a company commits a GDPR violation?

GDPR fines follow a two-tier structure. The upper tier reaches 20 million euros or 4 percent of a company’s total global annual revenue, whichever is higher, and applies to serious violations like unlawful processing, ignoring data subject rights, or unauthorized international data transfers. The lower tier caps fines at 10 million euros or 2 percent of global revenue, and covers issues like inadequate record-keeping or missing data protection impact assessments.

Some of the biggest GDPR fines illustrate how seriously regulators enforce these rules. 

In 2023, Meta was fined €1.2 billion by Ireland’s Data Protection Commission for transferring EU user data to the United States without adequate safeguards.

In 2025, TikTok received a €530 million fine over unlawful data transfers to China. 

Enforcement has extended well beyond large tech companies, with Spain alone issuing nearly 1,000 fines since 2018. 

Fines are only part of the risk. GDPR also allows individuals to sue for damages.

Why Is It Important to Adhere to GDPR?

A public enforcement action or lawsuits from customers are not only a huge unexpected expense, they can also do lasting damage to customer trust. That damage directly affects your bottom line. 75% of consumers said they will not buy from a company they don’t trust with their data in Cisco’s 2024 Consumer Privacy Survey. A high-profile compliance failure can shrink your addressable market.

The reverse also holds. Companies that invest in privacy compliance have found that it helps create the infrastructure necessary to innovate and move quickly as regulations continue to become more complex, with returns averaging about 1.6x

Building consumer loyalty and continuing to advance in an increasingly competitive technological landscape are more compelling reasons to adhere to GDPR than simply following the rules.

Biggest Challenges to Becoming GDPR Compliant

Getting compliance right is difficult, and most companies aren’t failing because they don’t care; they’re failing because GDPR touches nearly every part of the business at once: marketing, engineering, legal, and all the vendors in between, and making sure existing tech is communicating to each other is difficult. Most GDPR compliance risks trace back to a handful of common GDPR mistakes.

  • Treating GDPR as a one-time project. Compliance work often gets built for launch date and never revisited. Regulations change, vendors change, and consent management requires constant monitoring.
  • Incomplete or outdated records of processing. Article 30 requires an ongoing inventory of what data you process and why.
  • Consent that doesn’t meet GDPR’s standard. Pre-checked boxes, “accept” options being more obvious than “reject,” and banners that let trackers fire before a visitor responds are among the most common violations regulators cite.
  • Missed or mishandled data subject access requests. Requests arrive through whatever channel a customer chooses unless there’s an established method along with processes that log, verify, and respond to them within the 30-day window.
  • Weak oversight of third-party vendors. Your compliance responsibility doesn’t end at your own systems. Verizon’s 2026 Data Breach Investigations Report found that third-party involvement in breaches jumped to 48%, a 60% increase from the year before. Communication with third-party vendors is key.
  • Unclear internal data access. Access to personal data often gets granted broadly and rarely reviewed, which works against GDPR’s data minimization principle.

When it comes to the mechanics of the website, these three challenges are the ones we often see:

  • Having an accurate, accessible privacy policy. GDPR’s transparency requirement means your privacy policy needs to clearly and specifically explain what data you collect and why, and it needs to actually be live and reachable at every point someone might enter your site.
  • Running a consent management platform that actually works. Since consent is the lawful basis most companies rely on, a CMP needs to manage both the consent itself and the cookies and tags tied to it, and it needs regular auditing to confirm it’s still doing that correctly as your site changes.
  • Keeping track of where data goes once it leaves your site. Transferring personal data outside the EU requires a valid legal mechanism, so you need visibility into the network calls your site makes to catch the data heading somewhere it shouldn’t. 

For a deeper look at each of these, along with practical suggestions for addressing them, see our breakdown of common pain points.

How Is GDPR Different From Other Privacy Laws?

GDPR was the first major privacy law of its kind and became a model for many that followed, including California’s CCPA, Brazil’s LGPD, and dozens of state-level laws now in effect across the US. (You can see how a principles-centered approach can also be applied to state laws.)

However, there are some key differences to highlight.

GDPR vs CCPA 

The GDPR consent model runs on opt-in: you need a valid, legal basis before you collect or process someone’s data in the first place. 

CCPA, as amended by CPRA, works the opposite way. Businesses can collect, sell, or share personal information by default, and the burden falls on the consumer to opt out. California requires a “Do Not Sell or Share My Personal Information” link (or a combined “Your Privacy Choices” link) on your site, and businesses must also honor Global Privacy Control, a browser-level signal that lets someone opt out of every site once instead of on each site.

The scope of GDPR applies based on whose data is processed, regardless of where the company operates. CCPA applies to businesses that meet specific revenue or data volume thresholds and protects California residents specifically, so a small company with no California customers may fall outside of its scope.

GDPR vs LGPD

Brazil’s LGPD is the closest global match to GDPR structurally: similar principles, similar data subject rights, and a comparable legal basis requirement, although LGPD provides ten lawful bases for processing instead of GDPR’s six. 

Enforcement is where they diverge the most. LGPD has lighter penalties with fines capped at 2% of a company’s revenue in Brazil specifically, not global revenue, up to roughly R$50 million (around US$9 million) per infraction, a fraction of GDPR’s €20 million or 4% global revenue ceiling. 

Record-keeping requirements are also easier to escape under LGPD: it exempts organizations by size or by sensitivity of the data they handle, with no added restriction on how routine the processing is. 

GDPR has a similar size-based exemption, but it only covers occasional, low-risk processing, which rules out nearly every business with an ongoing data practice.

How GDPR Is Changing: The EU’s Digital Omnibus

GDPR itself is not static. The EU tried to replace the 2002 ePrivacy Directive with a more modern ePrivacy Regulation, but that effort deadlocked in Council negotiations for eight years and was formally withdrawn in February 2025. In November 2025, the European Commission proposed the Digital Omnibus, a package that would fold cookie consent rules directly into the GDPR through two new articles.

Article 88a would: 

  • Require a single-click option to refuse non-essential cookies with Accept and Reject given equal visual prominence. Regulators already treat this as a requirement in practice; CNIL has fined companies over exactly this kind of button asymmetry under Article 7(3), but Article 88a would write it directly into the GDPR’s text rather than leaving it to interpretation and enforcement precedent. 
  • Bar a site from re-requesting consent for the same purpose for at least six months after someone refuses. Most current consent platforms would need reconfiguring to track refusal timestamps rather than re-prompting on the next visit, as many do by default today.

A companion provision, Article 88b, would require companies to honor browser-level consent signals, an EU equivalent to California’s GPC, but the Council has already dropped it from its position, and it’s now an open question whether Parliament brings it back.

Nothing here is law yet, and the earliest realistic timeline for any of it taking effect is 2027, likely later given the EU’s history with digital legislation. We’ll be updating this section as the Digital Omnibus moves through negotiations. For the latest official status, see the European Parliament’s Legislative Train tracker for this file.

GDPR Compliance Strategies

Understanding GDPR regulations and requirements is the first step on the path to compliance. 

So how do you become GDPR compliant? It is an ongoing effort that involves four key steps:

  1. Mapping what personal data you collect.
  2. Establishing a lawful basis for processing the collected data.
  3. Honoring data subject rights requests.
  4. Maintaining records that prove your practices hold up under scrutiny.

Each of these four steps breaks down into several concrete actions outlined below, and most companies build them out over time rather than tackling everything at once. Some items apply to virtually every organization right away, like documenting your legal basis and setting up a request process, while others become priorities as your processing grows in scale or risk, like a formal breach response plan. Treat it less as a strict sequence and more as the full set of capabilities a mature privacy program needs to have in place:  

  1. Document your legal basis for processing: For every type of personal data you collect, you need a documented reason that satisfies one of GDPR’s lawful bases, whether that is consent, contract, or legitimate interest.
  2. Maintain records of processing activities: GDPR requires an up-to-date inventory of what data you process, why, and where it goes. This is often called an Article 30 record or a ROPA, short for Record of Processing Activities.
  3. Run data protection impact assessments where required: Any processing likely to create meaningful risk to individuals, like large-scale monitoring or profiling, needs a formal risk assessment before it goes live.
  4. Build a data subject rights request portal: People have the right to access, correct, delete, or transfer their data, and GDPR sets strict timelines for responding. Most companies need a dedicated intake process, often a self-service Data Subject Access Request (DSAR) portal to receive, verify, and fulfill these requests within 30 days. 
  5. Vet your processors and vendors: Your company is on the hook for how your vendors handle EU data too, so contracts and due diligence with every processor matter.
  6. Prepare a breach response plan: GDPR requires notifying regulators within 72 hours of discovering a qualifying breach. If the breach is likely to pose a high risk to affected individuals, you also have to notify them directly, without undue delay, though that notification has no fixed deadline the way the regulator one does. Either way, the process needs to exist before you experience one.
  7. Review how data moves across borders: Any transfer of EU personal data outside the EU needs a valid legal mechanism behind it, such as standard contractual clauses.
  8. Train your team and appoint a DPO if required: Staff who touch personal data need ongoing training, and companies that meet certain thresholds are required to designate a data protection officer. Since GDPR involves legal, IT, marketing, and customer support all at once, many companies also form a cross-functional privacy panel, pulling in stakeholders from each of those teams, so decisions about data use and vendor selection get made with the right people in the room.

Building and running all this by hand gets unwieldy fast, which is why most companies lean on a dedicated privacy management platform rather than spreadsheets and shared drives. OneTrust, TrustArc, Osano, Transcend, and Ketch are among the most established options, and each handles the data mapping, DSAR workflows, Data Protection Impact Assessments (DPIA) templates, and consent record-keeping described above, so it is worth evaluating a few to see which fits your team’s size and complexity. 

None of this replaces the work of actually proving your website behaves the way your privacy program says it does, which is where the practical steps below come in.

From GDPR Compliance to Website Compliance

Everything above is program-level work: legal basis, records of processing, vendor contracts, breach response. GDPR governs personal data wherever a company collects it, not just online. But websites are where a huge share of that collection happens in practice, where third-party tools multiply fastest, and where tags and cookies get added by different teams often without a central review. It’s also where regulators and plaintiffs’ attorneys tend to look first. That combination of rapid change and scattered ownership make the website one of the most common sources of GDPR compliance issues, and it’s the layer we’ll focus on next.

Is Your Website GDPR Compliant? 5 Starting Questions

Before diving into a full audit, these five questions will tell you roughly where you stand:

  1. Do you know every tag, cookie, and vendor request currently firing on your site?
  2. Does your consent banner actually stop non-essential tracking until a visitor responds?
  3. If someone clicks Reject-All, do those tags actually stop firing?
  4. If a data subject request came in today, could you find, verify, and respond to it within 30 days?
  5. When did you last audit your site for new tags, vendors, or consent categories?

Practical Steps for Website GDPR Compliance

If any of those questions above gave you pause, the detailed steps below explain what to fix and why it matters under GDPR.

  1. Inventory every tag, cookie, and vendor request. This is the foundation for Article 30’s record-keeping requirement and Article 5’s transparency principle; you cannot document or categorize what you haven’t identified. Manually documenting via browser tools is near impossible at enterprise levels, so an automated scanning tool like ObservePoint is the best way to keep up-to-date inventories.
  2. Deploy a consent management platform with granular categories, not a single accept or reject toggle. GDPR’s conditions for valid consent under Article 7 require that consent be specific and informed, which a blanket toggle can’t satisfy. In practice, this is its own multi-step project.
    1. Connect the CMP to your tag management system so it can actually control what fires.
    2. Categorize every cookie and tag correctly (essential, functional, analytics, advertising, etc.), since a miscategorized tag could open you up to a violation.
    3. Configure consent to persist and apply consistently across pages, sessions, and any subdomains.
    4. Test every consent state to confirm that the CMP actually behaves differently, not just that the banner records the answer.
    5. Repeat this testing whenever the CMP, TMS, or site structure changes.
  3. No dark patterns in banner design. Article 7(3) requires that withdrawing consent be as easy as giving it, which regulators have interpreted specifically as design parity: Accept and Reject need equal size, visual prominence, and number of clicks to complete.
  4. Confirm nothing non-essential fires before a visitor interacts with the banner. Recital 32 requires consent to be given before processing begins. A banner that lets trackers fire while it’s still loading violates this. This is one of the most common and most easily missed GDPR violations and one that’s hard to test without an automated tool like ObservePoint that allows you to travel through a website as a user would. 
  5. Verify that Reject-All actually stops non-essential tags from firing. Under the ePrivacy Directive’s Article 5(3) and GDPR’s Article 6, tracking that continues after a visitor rejects it has no valid consent behind it, so the processing becomes unlawful.
  6. Honor Global Privacy Control signals in addition to your own consent banner. As opt-out signals gain legal weight in more jurisdictions, treating browser-level signals the same as manual Reject-All clicks keeps your site consistent across regulatory regimes.
  7. Document a lawful basis for each category of processing, and keep records of processing activities up to date. This is Article 6 and Article 30 directly, and it gets asked for in an investigation.  
  8. Put data processing agreements in place with any vendor or processor that touches EU personal data. Article 28 makes you responsible for your processors’ compliance, not just your own.
  9. Build a repeatable process for fulfilling data subject access requests within 30 days. Articles 12 and 15 through 22 set that timeline, and an ad hoc, email-only process is the most common reason companies miss it.
  10. Re-audit on a schedule. Article 5(2)’s accountability principle requires you to demonstrate ongoing compliance, not a single point-in-time effort, and tags added by marketing or sales outside change control are the most common way for things to be missed.

ObservePoint’s privacy compliance features fit directly into steps 1, 2b, 2d, 2e, 4, 5, 6, and 10. The platform inventories every tag and cookie on your site, audits consent behavior under different preferences, and runs those audits on a recurring schedule. 

Step 3 requires some manual visual checking. Steps 2a, 2c, 7, 8, and 9 are more process and documentation work that the software dev team, legal counsel, and a defined internal workflow handle. ObservePoint verifies that the technical outcomes match what those processes claim, rather than replacing them.

A Website GDPR Compliance Checklist

  • Map every tag, cookie, and vendor request firing on the site
  • Classify each cookie as essential or non-essential
  • Deploy a consent banner with granular category controls
  • Confirm Accept and Reject buttons have equal size, prominence, and click count
  • Confirm nothing non-essential fires before the user interacts with the banner
  • Confirm Reject-All actually stops non-essential tags from firing
  • Test that Global Privacy Control signals are honored the same way Reject-All is
  • Document a lawful basis for each category of processing
  • Maintain up-to-date records of processing activities
  • Complete data protection impact assessments for high-risk processing
  • Confirm data processing agreements are signed with all vendors
  • Build a process for fulfilling data subject access requests within 30 days
  • Schedule recurring audits rather than a one-time check
Download the Checklist as a PDF

How ObservePoint Helps with GDPR Compliance

ObservePoint is a web governance platform built to answer the technical half of this question: does your site actually behave the way your privacy program says it does? Check out this recent webinar to learn What Every Website Needs to Know About US Privacy Compliance and Tracking Risk.

Specifically, ObservePoint can:

  • Provide a tag and cookie inventory with more comprehensive detail than a CMP or DSAR platform can provide, so you know exactly what third parties are collecting data on your site
  • Audit your site under Default, Accept-All, Reject-All, and GPC consent states, and show exactly which tags fire in each to double-check your CMP’s functionality
  • Flag any non-essential tag firing before a visitor has accepted cookies
  • Confirm whether Reject-All and GPC genuinely suppress the tags they are supposed to
  • Produce cookie and vendor-level reports that serve as evidence for regulators, auditors, or your own privacy team
  • Run these audits on a recurring schedule, so drift from a new tag, a consent management platform update, or a site redesign gets caught before it becomes a violation

Learn More about how ObservePoint helps companies verify their GDPR compliance across every page, tag, and cookie on their site.

Felice Wu

Felice Wu

Felice has been a Content Marketer at ObservePoint since 2021 and enjoys getting to the heart of product benefits, compliance nuance, and illustrative diagrams. She writes about web governance, tag management, and privacy regulations, and has a soft spot for turning dense technical topics into something people actually want to read. When she's not untangling GDPR articles, she writes about vampires and makes western jewelry.

Read full bio

Tired of Manually tracking cookies, tags, and pages?

Automatically audit and monitor your analytics, key customer journeys, and privacy programs.

Get Started For Free