Skip to main content

GDPR Compliance

Requirements, penalties, and how to check your website against General Data Protection Regulation.

EUUKCH

Test your website for GDPR compliance for free

Enter your domain to start a free scan and open an account - no integration required.

Does GDPR apply to my business?

Answer a few questions for an instant, plain-English read on whether General Data Protection Regulation likely applies to you.

Answer a few questions to see whether the EU General Data Protection Regulation (GDPR) is likely to apply to your business. Note there is no revenue threshold - and your company’s location does not matter.

Is your business established in the EU or EEA (an office, branch, or staff there)?
Do you offer goods or services to people located in the EU/EEA (even for free)?

Accepting EU customers, pricing in euros, or shipping/serving the EU all count.

Do you monitor the behavior of people in the EU/EEA (analytics, ad tracking, profiling)?

Running analytics or advertising trackers that reach EU visitors counts as monitoring.

This tool offers general guidance, not legal advice. Applicability can turn on details specific to your business - confirm with qualified counsel.

Who GDPR applies to

  • The GDPR applies if your business is established in the EU/EEA, offers goods or services to people in the EU/EEA, or monitors the behavior of people in the EU/EEA.
  • There is no revenue or company-size threshold, and your company’s location is irrelevant - a business anywhere can be covered.
  • Running analytics or advertising trackers that reach EU visitors can by itself constitute "monitoring" and trigger the GDPR.

Common questions

Does the GDPR apply to US companies?
Yes, if the US company offers goods or services to people in the EU/EEA or monitors their behavior (for example via analytics or ad tracking). Location does not exempt you.
Is there a revenue threshold for the GDPR?
No. Unlike the CCPA, the GDPR has no revenue or size threshold. A one-person business can be fully in scope if it processes EU residents’ personal data.
Does the GDPR apply to my website if I just use Google Analytics?
It can. Using analytics or advertising that tracks EU visitors is treated as monitoring their behavior, which brings the GDPR into scope for that processing.

Overview

The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that governs the processing of personal data. It applies to all organizations that handle the personal data of EU citizens, regardless of where the organization is based.

Penalties

€10,000–€20,000,000 or 2–4% of global annual turnover

What Complyy checks

15 automated tests — 10 passive, 5 active

Passive (instant scan)

critical

Privacy policy exists and is accessible

Art. 12 requires a privacy notice that is easily accessible, in clear language, and reachable from every page. Absence of a privacy policy is a per-se Art. 13/14 violation.

high

Privacy policy contains all required GDPR elements

Art. 13/14 enumerate required disclosures: controller identity, purposes, legal basis, recipients, retention, transfers, rights, complaint mechanism. Missing any element is a documented finding in most EU DPA decisions.

high

Granular cookie opt-in/opt-out per category

Art. 7(2) and ePrivacy require consent to be specific per purpose: analytics, marketing and personalisation must each be opt-in-able and opt-out-able independently. A single global toggle is non-compliant.

high

Cookie consent banner present and functional

high

No tracking before consent is given

Loading analytics or marketing trackers before the user consents is one of the most-fined GDPR violations (e.g. CNIL's €150M Google decision). Art. 6 + ePrivacy require prior, freely-given, informed consent before any non-essential cookie or tracker fires.

high

Reject button dismisses banner and stops tracking

Many sites show a banner but the "Reject" button still allows tracking, which the EDPB treats as no consent at all. Rejecting must actually stop non-essential cookies and trackers from firing.

high

Cookie consent banner present with accessible reject option

A banner is the visible proof that consent is being collected. EDPB guidelines require an equally prominent "Reject" option alongside "Accept" - missing or buried reject is a top regulator finding.

medium

DPO or privacy contact details listed

Art. 37-39 require many controllers to designate a DPO and Art. 13 requires their contact to be published. Listing only a generic "info@" address fails this requirement.

medium

Data breach notification process documented

Art. 33-34 require a documented breach-notification process: 72-hour notice to the DPA and prompt notice to data subjects when high-risk. Absence is a structural compliance failure regulators check post-incident.

medium

Cookie consent banner free of dark patterns

Pre-ticked boxes, hidden reject, colour-tricks and "legitimate interest" toggles default-on are explicitly prohibited under EDPB 03/2022 dark-pattern guidance. Consent obtained this way is invalid and the site is treated as if no consent existed.

Active (synthetic identity tests)

critical

Right to erasure honored within 30 days (Art. 17)(waits up to 30d for response)

Art. 17 grants the right to be forgotten and Art. 12(3) sets the response window at 30 days (extendable to 90 with notice). Failure to honour deletion is the most-litigated GDPR right.

critical

DPO or privacy contact responds to inquiry within 72 hours(waits up to 3d for response)

Art. 12(3) requires the controller to respond to data-subject communications without undue delay; EDPB practice treats 72 hours as the reasonable upper bound for initial acknowledgment. Silent or auto-bounced DPO contacts indicate the role is nominal only.

critical

Right to access / data copy provided within 30 days (Art. 15)(waits up to 30d for response)

Art. 15 entitles individuals to a copy of their personal data within 30 days. Non-response or partial response triggers DPA complaints and is one of the most common enforcement actions.

high

Marketing opt-out honored within 30 days(waits up to 30d for response)

Art. 21 grants the right to object to direct marketing at any time, and the controller must stop processing immediately. 30 days is the practical limit DPAs apply before opening a complaint.

high

Data portability in machine-readable format (Art. 20)(waits up to 30d for response)

Art. 20 requires data provided by the user to be exportable in a structured, commonly-used, machine-readable format (CSV, JSON). PDF screenshots do not satisfy portability.

Learn More About General Data Protection Regulation

What is GDPR compliance?

The General Data Protection Regulation (GDPR) is a robust data protection law formulated to ensure privacy and data protection for individuals within the European Union (EU). Its primary goal is to give individuals greater control over their personal data and simplify the regulatory environment for businesses operating in the EU. Compliance with GDPR means that a company adheres to stringent rules on the processing of personal data, which includes obtaining explicit consent, ensuring data protection, and respecting user rights, among other criteria.

Organizations must demonstrate compliance through both policies and practices. This involves deploying comprehensive data protection measures such as privacy by design, conducting regular data protection assessments, and implementing mechanisms to safeguard user data. Furthermore, businesses must provide data subjects with clear accessibility to their data, with the ability to rectify, erase, or transfer it as requested.

Who must comply with GDPR?

GDPR applies to any organization, regardless of location, that processes personal data of individuals within the EU. This includes entities offering goods or services to EU residents or monitoring their behavior within the EU. Notably, there are no specific revenue or user-count thresholds determining applicability—it's the nature of data processing activities that triggers GDPR compliance.

Firms typically engaging in data processing involving sensitive information, such as health data or biometrics, must exercise strict conformance with GDPR guidelines. Furthermore, even businesses located outside the EU, if targeting EU consumers, must ensure they meet GDPR's stringent data protection standards.

Key requirements and obligations

  • Lawful Processing: Companies must identify a lawful basis for processing personal data, such as consent or contractual necessity.
  • Data Subject Rights: Organizations must facilitate individuals' rights to access, rectify, and delete their data.
  • Data Protection Officer (DPO): Appoint a DPO if the organization processes large-scale categories of sensitive data.
  • Breach Notification: Mandates reporting data breaches to the relevant authority within 72 hours of awareness.
  • Data Protection Impact Assessments (DPIAs): Required when processing operations may pose increased risks to individual rights.

Penalties and fines for non-compliance

GDPR stipulates a two-tiered approach to penalties. For minor infringements, businesses can face fines up to €10 million or 2% of their annual global turnover, whichever is higher. Severe violations can attract fines up to €20 million or 4% of annual global turnover, whichever is greater. Furthermore, individuals may pursue claims for damages directly incurred due to non-compliance, enhancing the regulation's enforcement impact.

An example of a non-compliance issue can be seen when a company fails to appropriately secure personal data, leading to unauthorized access and data breaches, resulting in substantial financial penalties and reputational damage.

How to check if your website is compliant

To verify GDPR compliance, organizations should conduct detailed audits focusing on data collection, processing, and management practices. This includes validating consent mechanisms, ensuring transparency in data processing, and establishing robust security measures.

Checking whether a website employs encrypted connections for data transmission, offers users control over their data, and provides visible privacy policies can be essential practices. Conducting these checks is crucial as data regulations evolve, and Complyy tests these continuously from the outside and captures timestamped evidence.

Frequently asked questions

Who does GDPR apply to?

GDPR applies to any company, regardless of location, that processes personal data of EU residents. This includes offering goods or services to EU consumers or tracking their online behavior.

Does GDPR apply to small businesses or non-profits?

Yes, GDPR applies to organizations of all sizes, including small businesses and non-profits, as long as they process personal data of individuals in the EU.

What are the penalties under GDPR?

Organizations can face fines of up to €20 million or 4% of their global annual turnover, whichever is higher, for severe breaches of GDPR.

What is the deadline to respond to a data access request under GDPR?

Under GDPR, organizations must respond to data access requests from individuals without undue delay and at least within one month of receipt.

Are there any exemptions under GDPR?

Yes, GDPR provides certain exemptions, such as processing personal data for national security, defense, or other public interest purposes that may not fully apply to data protection rules.

Is explicit consent always required under GDPR?

Explicit consent is one valid legal basis among others, such as contract necessity or legitimate interests, for processing personal data under GDPR.

What are data protection impact assessments (DPIAs)?

DPIAs are processes designed to assess data processing practices that may significantly impact individuals' rights and freedoms, helping identify and mitigate potential privacy risks.

How can a non-EU business comply with GDPR?

A non-EU business must appoint an EU-based representative and ensure compliance with GDPR principles, particularly if offering products or services to EU residents or monitoring their behavior.

Recently Scanned Websites

Live compliance reports from Complyy's public directory.

Browse the full directory →

Related GDPR articles

Insights and analysis from Complyy on GDPR compliance.

Read the Complyy blog →

The Platform

How Complyy enforces GDPR compliance

Complyy continuously tests your site against General Data Protection Regulation using synthetic identities that behave exactly like regulators — and your customers.

01

Discover

We visit your website as a real user — finding your privacy policy, cookie banner, opt-out links, and contact details.

02

Scan & Test

Passive checks run instantly. Active agents sign up, submit deletion requests, and wait for responses — just like regulators do.

03

Score & Evidence

Every finding is timestamped, SHA-256 hashed, and RFC 3161 certified. Your compliance report is audit-ready from day one.

Why Complyy

The only platform that tests compliance the way regulators do

Real synthetic identities

We register actual accounts — adult and minor — on your platform. No theoretical checks. Real interactions, real evidence.

Active + passive tests

Most tools only check your privacy policy text. Complyy also submits DSAR requests, verifies deletion, and waits for real responses.

Court-admissible artifacts

Every screenshot, response, and timestamp is cryptographically sealed. Built for regulators, DPAs, and legal teams — not just developers.

4

Regulations monitored

19

Compliance tests

∞

Agentic identities

3 min

Avg. first evidence artifact

Is your company GDPR-compliant?

Get a free compliance scan in minutes. No credit card. No setup. Complyy visits your site, runs every test, and delivers a full evidence report.