How-To

Website Privacy Checklist 2026: 30 Checks Before You Launch

·7 min read

Quick answer: Use this 30-point checklist to verify your website's privacy compliance in 2026. It covers GDPR, ePrivacy, cookies, consent banners, security headers, third-party scripts, and the latest EU AI Act requirements. Run a free scan with PrivacyChecker to automate most of these checks.

Cookie & Consent Compliance

#CheckWhy It MattersStatus
1Cookie consent banner is presentRequired under ePrivacy Directive for EU visitors
2No cookies are set before consentPre-consent cookies violate GDPR — fines up to €20M
3Banner has a clear "Reject All" buttonRequired by CNIL, EDPB, and most EU DPAs
4Reject is as easy as Accept (no dark patterns)Dark patterns are explicitly illegal under DSA
5Cookies are categorized (essential, analytics, marketing)Users must be able to accept specific categories
6Consent Mode V2 is implementedRequired for Google Ads in EEA since March 2024 — setup guide
7Cookie policy lists all cookies with purposes and durationsTransparency requirement under GDPR Art. 13

Privacy Policy

#CheckWhy It Matters
8Privacy policy is accessible from every pageGDPR Art. 12 requires easy access
9Policy lists all data processing purposesGDPR Art. 13(1)(c)
10Legal basis stated for each processing activityGDPR Art. 13(1)(c)
11Third-party processors are disclosedGDPR Art. 13(1)(e-f)
12Data retention periods are specifiedGDPR Art. 13(2)(a)
13Data subject rights are listed (access, erasure, portability)GDPR Art. 13(2)(b-d)
14Contact information for DPO or privacy contactGDPR Art. 13(1)(a-b)
15Cross-border transfers are disclosed with safeguardsGDPR Art. 13(1)(f), Chapter V

Security

#CheckWhy It Matters
16HTTPS enabled with valid SSL certificateBasic requirement — insecure sites get browser warnings
17Security headers configured (CSP, X-Frame-Options, HSTS)Prevents XSS, clickjacking, and data injection
18SPF, DKIM & DMARC configured for emailPrevents email spoofing and phishing
19Domain not on any blacklistsBlacklisted domains trigger spam filters and lose trust
20SSL certificate is not expiring soonExpired certs cause trust warnings and service disruptions

Third-Party Scripts & Trackers

#CheckWhy It Matters
21All third-party scripts are inventoriedHidden trackers are a major GDPR compliance risk
22Analytics scripts load only after consentGA4, Meta Pixel must wait for opt-in
23Google Analytics configured with IP anonymizationRequired by most EU DPAs
24No unknown or suspicious external connectionsMalicious scripts can exfiltrate user data
25External scripts use SRI (Subresource Integrity)Prevents supply chain attacks via tampered CDN files

AI & Emerging Requirements

#CheckWhy It Matters
26AI usage disclosed in privacy policyEU AI Act transparency obligation (effective Aug 2025)
27AI-generated content is labelledRequired under EU AI Act Art. 50
28Accessibility meets WCAG 2.1 AAEuropean Accessibility Act applies from June 2025
29Core Web Vitals pass (LCP, FID, CLS)Google ranking factor + third-party scripts impact
30Automated compliance monitoring is activeCompliance drifts — a one-time audit is not enough

How to Use This Checklist

  1. Scan first: Run a free PrivacyChecker scan to automatically check items 1-25
  2. Fix critical issues: No-consent cookies and missing privacy policies are the highest-risk violations
  3. Document compliance: Keep evidence of your checks for accountability (GDPR Art. 5(2))
  4. Re-scan monthly: Websites change — new plugins, scripts, and updates can introduce new compliance gaps

Frequently Asked Questions

How often should I check my website's privacy compliance?

At minimum, monthly. Every time you add a new plugin, script, or third-party integration, your compliance posture changes. Automated monitoring tools like PrivacyChecker can alert you to new issues as they appear.

What's the fastest way to check all 30 items?

A PrivacyChecker scan automatically verifies most technical checks (cookies, headers, scripts, SSL) in under 60 seconds. The remaining items (privacy policy content, AI disclosure) require manual review against the checklist above.

My website passed all checks. Am I fully GDPR compliant?

This checklist covers website-side compliance. Full GDPR compliance also includes organizational measures: staff training, data processing records, DPAs with vendors, DSAR procedures, and breach response plans.

Check your website now — free

Run a complete privacy audit in under 60 seconds. Get your score, find issues, and learn how to fix them.

Start Free Audit