GDPR Privacy Checklist

GDPR Privacy Checklist

In need of advice on putting together a GDPR-compliant privacy policy? Here’s a helpful GDPR Privacy Checklist for you.
You may already be aware that a privacy notice is an essential element when it comes to producing appropriate documentation for a GDPR-compliant website.
If you are not sure what GDPR is or need further clarification, see this post.
So, whether you’ve already published a privacy policy or are only just getting round to creating one – this GDPR Privacy Checklist is here to help.

GDPR Privacy Checklist

GDPR Checklist

1. An introduction

Start with a short introduction. Explain what the privacy policy is for, why it’s needed, and when it takes effect. This shows transparency and builds trust.

2. Who you are

Make it clear who you are — include your business or company name and location.

Example: “In terms of this privacy policy, ‘we’ or ‘us’ or ‘our’ means the owners of 23 Business Street, based in Happy Town, located in the Happy Islands.”

3. What types of data you’re collecting

Be specific about what data you collect (e.g. names, email addresses, payment details) and how it’s collected (directly, indirectly, via cookies, etc.).

4. The reason for collecting it

State your legitimate reasons for collecting personal data. Ensure every piece of data you hold has a justified purpose.

5. Any third parties involved

List any third parties with whom you share or receive data. You may also note conditions where data could be transferred, such as business acquisitions.

6. How personal data will be used

Explain how data will be used — be specific. You can include uses such as:

  • Sending updates or offers
  • Keeping a record of communication
  • Meeting legal obligations
  • Responding to complaints or requests

7. How long data will be stored for

Define how long you’ll store data, and why. You may note that certain data (e.g. for tax purposes) must be stored for legal reasons.

8. How an individual’s data is protected

Reassure users that their data is stored securely and responsibly. Mention security measures and state clearly that you will never sell data for marketing purposes.

9. The rights of the individual

  • The right to access their personal information
  • The right to correct inaccurate data
  • The right to restrict use of personal information
  • The right to be forgotten
  • The right to data portability
  • The right to object to data processing

10. How individuals can make data requests

Explain how users can contact you to access, amend, or delete their data, and note that you’ll respond within one month.

11. Use of cookies

Mention how you use cookies and for what purpose (e.g. analytics, performance, preferences). Include links to any third-party cookie or privacy policies.

12. Changes to your privacy policy

State that your policy may change over time, and that you’ll notify users on your website or by email if significant changes occur.

13. Contact details

Provide contact details such as the name or title (“Data Protection Officer”), email address, postal address, and phone number.

Key GDPR resources to keep bookmarked