GDPR Privacy Checklist
You may already be aware that a privacy notice is an essential element when it comes to producing appropriate documentation for a GDPR-compliant website.
If you are not sure what GDPR is or need further clarification, see this post.
So, whether you’ve already published a privacy policy or are only just getting round to creating one – this GDPR Privacy Checklist is here to help.
GDPR Privacy Checklist
- 1. An introduction
- 2. Who you are
- 3. What types of data you’re collecting
- 4. The reason for collecting it
- 5. Any third parties involved
- 6. How personal data will be used
- 7. How long data will be stored for
- 8. How an individual’s data is protected
- 9. The rights of the individual
- 10. How individuals can make data requests
- 11. Use of cookies
- 12. Changes to your privacy policy
- 13. Contact details
- Key GDPR resources
1. An introduction
Start with a short introduction. Explain what the privacy policy is for, why it’s needed, and when it takes effect. This shows transparency and builds trust.
2. Who you are
Make it clear who you are — include your business or company name and location.
Example: “In terms of this privacy policy, ‘we’ or ‘us’ or ‘our’ means the owners of 23 Business Street, based in Happy Town, located in the Happy Islands.”
3. What types of data you’re collecting
Be specific about what data you collect (e.g. names, email addresses, payment details) and how it’s collected (directly, indirectly, via cookies, etc.).
4. The reason for collecting it
State your legitimate reasons for collecting personal data. Ensure every piece of data you hold has a justified purpose.
5. Any third parties involved
List any third parties with whom you share or receive data. You may also note conditions where data could be transferred, such as business acquisitions.
6. How personal data will be used
Explain how data will be used — be specific. You can include uses such as:
- Sending updates or offers
- Keeping a record of communication
- Meeting legal obligations
- Responding to complaints or requests
7. How long data will be stored for
Define how long you’ll store data, and why. You may note that certain data (e.g. for tax purposes) must be stored for legal reasons.
8. How an individual’s data is protected
Reassure users that their data is stored securely and responsibly. Mention security measures and state clearly that you will never sell data for marketing purposes.
9. The rights of the individual
- The right to access their personal information
- The right to correct inaccurate data
- The right to restrict use of personal information
- The right to be forgotten
- The right to data portability
- The right to object to data processing
10. How individuals can make data requests
Explain how users can contact you to access, amend, or delete their data, and note that you’ll respond within one month.
12. Changes to your privacy policy
State that your policy may change over time, and that you’ll notify users on your website or by email if significant changes occur.
13. Contact details
Provide contact details such as the name or title (“Data Protection Officer”), email address, postal address, and phone number.
Key GDPR resources to keep bookmarked
- ICO (Information Commissioner’s Office, UK): Preparing for the General Data Protection Regulation (GDPR) – ‘Data protection self assessment’
- Full law text: GDPR, dated April 27th 2016
- European Commission Fact Sheet
- DMA UK: News, updates and webinars relating to GDPR
- Protection of Personal Data (via the European Commission)





