Compliance · GDPR
GDPR website compliance
GDPR website compliance means a site serving EU or UK visitors handles their data lawfully: a privacy policy with the Article 13/14 disclosures, a lawful basis for processing, a working path for data-subject requests, and cookie consent that is real (no tracking before opt-in, no pre-ticked boxes, rejecting as easy as accepting). Complidar checks those website-visible basics on up to 120 pages and tags which findings carry EU/UK jurisdiction.
Does GDPR reach a US small business?
It can, through Article 3's extraterritorial scope: GDPR applies if you offer goods or services to people in the EU/UK (think EUR pricing, EU shipping, localized marketing) or monitor their behavior, which is what advertising trackers and analytics do. A US site with no EU customers and no EU-targeted tracking has a weaker nexus; a site that ships to Berlin or retargets EU visitors should assume it's in scope. The UK GDPR mirrors the EU regime post-Brexit.
Whether GDPR applies to you is a counsel determination. What your site does to EU visitors (which trackers fire before consent, what your policy discloses) is observable, and that's the part a scan settles.
What enforcement looks like
The headline tier of GDPR fines reaches €20 million or 4% of worldwide annual turnover, whichever is higher (Article 83(5)); the UK mirror is £17.5M/4%. Cookie-consent design is enforced aggressively under the companion ePrivacy rules: France's CNIL fined Google €150M and Meta €60M over consent banners where rejecting was harder than accepting. Pure interface mechanics.
For small businesses the realistic exposure is rarely the 4% headline; it's DPA complaints from EU users, cease-processing orders, and the commercial cost of failing a customer's vendor diligence. All three start from the same visible failures a scan surfaces.
What Complidar checks for GDPR
- Cookie/tracker behavior before and after consent: nothing non-essential should fire pre-opt-in
- Reject parity: whether declining is as easy as accepting (the CNIL enforcement pattern), pre-ticked boxes, consent dark patterns
- Privacy-policy elements from Articles 13/14: controller identity, purposes, lawful basis, retention, recipients
- A stated mechanism for data-subject access requests (DSARs)
- EU representative and DPO mentions where the policy claims they're required
- Cross-referenced state-privacy and CCPA findings, so US + EU exposure reads as one picture
Honest limits: A scan verifies website-visible GDPR basics: consent mechanics and policy disclosures. It cannot audit your internal records of processing, data-transfer agreements, or breach procedures. The report says exactly which layer each finding lives in, and where counsel takes over.
GDPR questions
I'm a US business with occasional EU visitors. Do I need to care?
Occasional, untargeted EU traffic is the gray zone, but if your analytics or ad stack profiles those visitors, you're 'monitoring behavior' under Article 3 and the safer posture is compliant cookie consent. A Complidar scan shows what your stack actually does to an EU visitor, which is the fact pattern counsel needs to make the call.
Is a cookie banner enough for GDPR?
Only if it works: consent must be opt-in before non-essential trackers fire, rejecting must be as easy as accepting, and the choice must actually control the trackers. Banners that load Google Analytics before the click (extremely common) fail the core requirement. That's the first thing the scan checks.
How is GDPR different from CCPA?
GDPR is opt-in (no tracking until consent); CCPA is largely opt-out (track, but honor opt-outs like GPC and disclose). GDPR fines scale to turnover; CCPA penalties are per-violation dollars. A site serving both markets needs both mechanics, which is why Complidar reports tag every finding with its jurisdiction.
GDPR is 1 of the 22 checks in every scan · up to 120 pages · no card
Last updated 2026-06-11 · Informational, not legal advice: how to read this