GDPR Website Audit: Scope, Data Flows and Evidence

Map website personal-data flows, purposes, legal bases, notices, processors, transfers, rights and security for an EU or UK GDPR legal review.

Updated

Published by AuditWeb

A GDPR website audit maps personal-data flows and collects evidence about purpose, legal basis, transparency, retention, recipients, transfers, rights and security. It supports a legal review but does not certify compliance. EU GDPR and UK GDPR scope must be assessed separately.

€20M
upper-tier maximum: up to €20m or 4% under EU GDPR Article 83, subject to its conditions
22
checkpoints in the full audit checklist below
72hrs
supervisory-authority notice where required: without undue delay and, where feasible, within 72 hours

Key takeaway

A data-protection review covers both governance and technical evidence. Website security is one part of that review. Cookie rules can also arise from the EU ePrivacy framework or the UK's PECR rather than GDPR alone.

This guide walks through every area your GDPR audit should cover, from cookie consent mechanics to third-party data sharing agreements, with a complete checklist at the end.

GDPR Requirements for Websites

GDPR establishes several core principles that apply directly to website operations. Understanding these principles is essential before diving into specific audit checks because they provide the reasoning behind each requirement.

Lawfulness, fairness, and transparency: Identify an Article 6 basis for each processing purpose and any additional condition required for special-category or criminal-offence data. Consent and legitimate interests are two possible bases, not defaults. Give the information required by Articles 13 or 14.

Purpose limitation: Specify purposes before collection and assess any later purpose for compatibility or another lawful route. Direct marketing also has separate ePrivacy or PECR rules; do not assume a transactional address can be added to marketing.

Data minimisation: Check that each collected field is adequate, relevant and limited to what is necessary for the stated purpose. Record the justification rather than assuming a standard contact-form schema.

Accuracy: Personal data must be kept accurate and up to date. Provide mechanisms for users to review and correct their data.

Storage limitation: Do not keep personal data longer than necessary for its original purpose. Define and enforce retention periods for every category of personal data you hold.

Integrity and confidentiality: Evaluate technical and organisational measures appropriate to risk. Encryption and access controls may form part of that assessment; GDPR does not promise that every breach can be prevented.

Cookie and similar-technology rules depend on jurisdiction and purpose. In the UK, PECR generally requires information and consent before storing or accessing information unless an exemption applies; UK GDPR defines the standard for valid consent and governs related personal-data processing.

For UK sites, test these consent characteristics when PECR requires consent:

  • Prior consent where the cookie rule requires it — test whether storage or access occurs before a valid choice. Document any statutory exemption instead of assuming a category name decides the result.
  • Freely given consent — check whether the user has genuine choice and control. Conditional access, power imbalance, detriment and whether processing is necessary to a service are fact-specific; apply current regulator guidance for the jurisdiction.
  • Informed consent — the consent request must clearly explain what cookies are used, what they do, and which third parties receive data. Vague statements like "we use cookies to improve your experience" are insufficient.
  • Specific and granular consent — separate distinct purposes where appropriate and avoid bundling a required service with optional processing. Test the actual vendor and purpose mapping behind each control.
  • Easy withdrawal — withdrawing consent must be as easy as giving it. Verify that the control remains findable and that withdrawal stops future storage, access and consent-based processing as configured.
  • Consent evidence — where processing relies on consent, record enough evidence to demonstrate the choice and information presented. A particular consent-management platform is not mandatory.

Audit your cookie consent by clearing all cookies and visiting your site. Check whether any non-essential cookies are set before you interact with the consent banner. Use browser developer tools to monitor network requests — are analytics or advertising scripts firing before consent is given? Test the reject flow — does clicking "reject" or "necessary only" actually prevent non-essential cookies from being set?

Privacy Policy

Transparency information may appear in a privacy notice and at relevant collection points. Check that required information is concise, transparent, intelligible, easily accessible and written in clear language for the intended audience.

Articles 13 and 14 require specified information in applicable circumstances. Check these common notice fields against the actual processing:

  • Identity and contact details of the data controller — who is responsible for the data processing. Include your company name, registered address, and a contact method for data protection queries.
  • Data Protection Officer contact — include DPO contact details where Article 37 requires a DPO; assess the controller or processor's activities against the Article's specific tests.
  • Categories of personal data — describe the categories actually processed and, for indirectly obtained data, the categories and sources required by Article 14.
  • Legal basis for each processing activity — for each type of data you collect, state whether you rely on consent, legitimate interest, contractual necessity, or another legal basis. Generic statements are not sufficient.
  • How long you retain data — state the retention period or, where that is not possible, the criteria used to determine it.
  • Who you share data with — list categories of recipients and, where practical, name specific third parties. If you use Google Analytics, Mailchimp, Stripe, or any other service that receives user data, it should be mentioned.
  • International transfers — identify actual restricted transfers, destination and the applicable adequacy decision, safeguard or derogation, with the required information about obtaining a copy.
  • User rights — clearly explain each right (access, rectification, erasure, portability, objection) and how to exercise them.
  • Right to complain — inform users of their right to lodge a complaint with their national supervisory authority.

Compare the notice with the data map, contracts and live requests. Date the reviewed notice and retain evidence of the version presented at relevant collection points.

Data Collection Audit

A data collection audit maps every point on your website where personal data is captured, processed, or transmitted. Many site operators are surprised by how many data collection points exist on their site beyond the obvious forms and login pages.

Walk through your site and document every data collection mechanism:

  • Forms — contact forms, newsletter signups, account registration, checkout, quote requests, survey forms, comment forms. For each form, note what fields are collected, where the data is stored, and whether consent language is present.
  • Analytics tracking — list each analytics product and configuration, then verify the events, identifiers, device or network data and recipients observed in the tested states.
  • Advertising pixels — Facebook Pixel, Google Ads conversion tracking, LinkedIn Insight Tag, and other advertising scripts track user activity and share data with advertising platforms.
  • Live chat and support widgets — Intercom, Drift, Zendesk, and similar tools collect visitor information and conversation data.
  • Embedded third-party content — YouTube videos, Google Maps, social media feeds, and other embeds can set cookies and collect data from your visitors.
  • Server and edge logs — inspect which request data the actual server, CDN and security services retain. IP addresses, identifiers and request details may be personal data depending on the controller's means and context.
  • Email marketing integration — if your forms feed into email marketing platforms, data flows from your site to a third party.

For each processing purpose, record the controller, data, source, recipients, Article 6 basis, any additional condition, notice, retention, transfer and security controls. Record consent only where the controller actually relies on it.

User Rights

GDPR grants individuals specific rights over their personal data. Your website must facilitate the exercise of these rights. An audit checks whether each right can actually be exercised in practice, not just whether it is mentioned in your privacy policy.

  • Right of access — test intake, identity handling, search, exemptions and the response process. The controller generally responds without undue delay and within one month, subject to the GDPR's extension and notice rules.
  • Right to rectification — users can request correction of inaccurate data. Audit check: can users update their own information through account settings? Is there a process for handling rectification requests for data users cannot self-service?
  • Right to erasure — test whether the organisation can evaluate the Article 17 conditions and exceptions, propagate a valid outcome to relevant systems and processors, and handle protected backups under its retention and restoration controls.
  • Right to data portability — where processing is automated and based on consent or contract, test export of data the person provided in a structured, commonly used, machine-readable format.
  • Right to object — distinguish the absolute objection to direct marketing from objections that require the controller to assess compelling legitimate grounds or legal claims.
  • Right to restrict processing — users can request that their data be stored but not actively processed in certain situations. Audit check: can your systems flag a record for restricted processing without deleting it?

Use an approved synthetic record or controlled exercise to test rights workflows without exposing another person's data. Record intake, identity checks, system searches, decisions, communications and completion time.

Third-Party Data Sharing

Most websites share visitor data with multiple third parties through analytics tools, advertising platforms, payment processors, email services, CDNs, and embedded content. Each data sharing relationship carries GDPR obligations that must be documented and managed.

For every third party that receives personal data from your website, verify the following:

  • The relationship and contract are classified — where a vendor processes personal data on the controller's behalf, verify an Article 28 contract. Separate controller-to-controller sharing requires a different analysis.
  • The third party's privacy practices are adequate — you are responsible for choosing processors that provide sufficient security guarantees. Review their security certifications, data handling policies, and breach notification procedures.
  • International transfer mechanism is recorded — identify the destination, adequacy decision or other Chapter V mechanism and any required supplementary assessment. US certification and Standard Contractual Clauses are possible mechanisms, not the only universal outcomes.
  • Data sharing is disclosed in your privacy policy — every third party that receives personal data should be named or categorised in your privacy policy. Users must know who has access to their information.

Create a recipient inventory with data, purpose, role, basis, contract and any transfer mechanism. Assess separately whether Article 30 requires a record of processing activities and ensure that record contains the Article's required fields.

GDPR Audit Checklist

Use this checklist to collect evidence for a GDPR review. Record confirmed, partial, failed, not applicable or not tested. Ask the controller and qualified counsel to determine legal compliance and priority.

  • Where UK PECR consent is required, storage or access is blocked until a valid choice
  • Users can reject non-essential cookies with equal ease as accepting them
  • Cookie categories can be selected individually (granular consent)
  • Consent choices are recorded and can be evidenced
  • Consent can be withdrawn at any time via a persistent link or icon
  • Required privacy information is easily accessible at relevant collection points
  • Privacy policy names the data controller with contact details
  • Privacy policy lists all categories of personal data collected
  • Privacy policy states the legal basis for each processing activity
  • Privacy information gives retention periods or the criteria used to determine them
  • Privacy policy identifies third-party data recipients
  • Privacy policy explains international data transfers and safeguards
  • Privacy policy explains all user rights and how to exercise them
  • Each form has the required notice and a recorded legal basis for each purpose
  • Marketing choices follow the applicable ePrivacy or PECR rule and use no pre-ticked consent box
  • A process records and handles rights requests within the applicable one-month GDPR period, including any valid extension and notice
  • Where Article 20 applies, in-scope data can be exported in a structured, commonly used, machine-readable format
  • Erasure decisions and valid exceptions can be applied across active systems and processors
  • Article 28 contracts are in place for vendors acting as processors
  • Any required Article 30 record is maintained with the applicable fields
  • Breach assessment and notice procedures apply the risk test and conditional 72-hour rule
  • Staff with access to personal data have received data protection training

Priority order

Prioritise an active unlawful disclosure, exposed special-category data or a broken rights process from verified risk and regulator guidance. Do not apply one enforcement order to every organisation.

Revisit the data map when processing, vendors or purposes change. Use the European Commission's EU data-protection guidance or the ICO's UK GDPR guidance for the applicable regime. The cookie audit covers browser evidence in more detail.

Check Your Page HTML

Review titles, canonical links and other on-page signals from pasted HTML. Download your findings for follow-up.

Open HTML Checker

No signup required • Pasted HTML stays in your browser