Home / Guides / Website GDPR Audit Checklist

Website Compliance

Website GDPR Audit Checklist

A website GDPR audit checklist for consent, cookies, trackers, policy consistency, evidence records, and post-launch monitoring.

Author

GDPRChecker Editorial Team

Reviewed by

Privacy & Compliance Research Team

Last updated

July 2026

Reading time

6 min read

Educational guidance for compliance readiness — not legal advice. Requirements vary by jurisdiction and your specific processing activities.

Introduction

A useful website GDPR audit is practical, repeatable, and tied to what the live site does in a browser. It should not be a static spreadsheet that someone updates once a year and then forgets. Marketing tags change, consent tools are reconfigured, and new pages go live. Your audit checklist needs to catch that drift.

This checklist focuses on the website layer: consent banners, cookie and tracker behavior, policy links, cookie declarations, consent records, and monitoring. It does not replace a full privacy program audit, but it gives teams a strong foundation for the part of GDPR and ePrivacy that visitors experience directly.

Use it before launch, after a redesign, after adding a new advertising or analytics vendor, or whenever a customer asks how you control website tracking. The strongest evidence comes from combining automated checks with manual review.

1. Define the audit scope

Start by listing the pages and systems in scope. Include your homepage, pricing page, signup flow, contact forms, blog or guide templates, campaign landing pages, embedded forms, and any subdomains that share the same marketing stack.

Also list who can change the website. In many companies, engineering owns templates, marketing owns tag manager, sales owns embedded booking tools, and customer success owns help center widgets. A website GDPR audit should understand these ownership boundaries because they explain how new trackers appear.

Scope itemWhy it mattersEvidence to collect
Public pagesVisitors see these before loginScan results and screenshots
Tag managerCan introduce trackers without deploysContainer owner and consent triggers
FormsCollect personal data directlyPrivacy notice and submission flow
Cookie bannerControls consent UXPreference states and button behavior
PoliciesExplain processingPublished text and version date

4. Compare policy text with live behavior

Policy consistency is where many audits find drift. The cookie policy may mention Google Analytics but not Meta Pixel. The cookie declaration may include reviewed cookies but omit a new tracker script. Or the privacy policy may mention a vendor that is no longer used.

The audit should compare three sources: the inventory, the published declaration, and the policy text. Differences are not automatically violations, but they are review items. If a tracker is detected but not disclosed, the policy needs review. If the policy mentions a tracker not detected anymore, the declaration may be stale or the vendor may still run on pages you did not scan.

  • Inventory item missing from declaration: review and publish a new declaration snapshot.
  • Declaration item not detected: confirm whether it is still used or only appears on other pages.
  • Policy mentions a vendor not detected: check other templates before removing it.
  • Detected vendor missing from policy: update policy language after internal review.
  • Missing withdrawal language: add clear instructions for changing preferences.

6. Add post-launch monitoring

A website can pass today and drift tomorrow. Scheduled scans reduce that risk by checking for new trackers, new cookies, and pre-consent network requests after the initial audit. Alerts should go to the people who can act: privacy, marketing operations, or engineering.

Monitoring is especially important when tag manager changes do not require a code deploy. A third-party script can appear on the live site without appearing in a pull request. Weekly scans may be enough for small sites; daily scans are better for high-change marketing teams.

  1. Set a baseline scan after the audit is complete.
  2. Enable scheduled scans for verified sites.
  3. Send alerts for new trackers, new cookies, and pre-consent requests.
  4. Route findings into the cookie inventory review queue.
  5. Update declaration and policy text when confirmed changes are legitimate.

How GDPRChecker supports the audit

GDPRChecker connects the audit steps into one workflow: run a website GDPR check, install runtime protection, collect consent records, review cookies and trackers, publish a declaration snapshot, monitor for new signals, and compare policy text against detected behavior.

The result is not a legal certification. It is an operational system for finding, fixing, and documenting website-level privacy issues.

Short disclaimer

This checklist is operational guidance for website privacy controls and technical testing. It is not legal advice and does not guarantee GDPR compliance.

FAQ

What should a website GDPR audit include?
It should include policy links, cookie banner behavior, pre-consent tracker testing, cookie and tracker inventory, consent records, declaration review, and ongoing monitoring.
Is a cookie scan enough for a GDPR audit?
No. A cookie scan is useful, but an audit also needs policy consistency, consent evidence, review of unknown items, and operational follow-up.
How often should I audit my website?
Audit before major launches and after marketing stack changes. Active sites should use scheduled scans so new trackers or cookies are caught quickly.
Can I publish a cookie declaration automatically?
You can generate a draft from detected items, but reviewed items are safer for a published declaration. Unknown trackers should be confirmed first.
Who should run the audit?
Privacy, marketing operations, and engineering should share ownership. Legal reviews wording and lawful basis; engineering verifies browser behavior.

GDPRChecker guides are educational resources and do not constitute legal advice. Use them to understand technical and operational privacy requirements, and consult qualified counsel for legal interpretation.

Check Your Website in Under 60 Seconds

  • No signup required
  • GDPR-focused checks
  • Cookie banner detection
  • Privacy policy verification