GDPR applies to every website that processes data from UK or EU users. Most small business websites have at least one compliance failure — usually analytics firing before consent. Here is what the law requires and how to check your site.
The most common failure by far. Google Analytics, Facebook Pixel and other tracking scripts must not fire until the user has actively accepted cookies. If your analytics loads on page load before any cookie banner interaction, you are non-compliant. Fix this in Google Tag Manager by triggering analytics tags only after a consent_update event.
A banner that only has an Accept button is non-compliant. The ICO requires that rejecting cookies is as easy as accepting them. Add a clear "Reject all" option at the same level as "Accept all" — not buried in a settings menu.
A privacy policy is not sufficient — you need a separate cookies policy that lists every cookie used, its name, purpose, provider and retention period. Your consent banner must link to this policy.
You must be able to prove consent was given if challenged. Your consent management platform should log when consent was given, what version of the policy was shown, and what the user consented to.
Run the GDPR Auditor — it checks for cookie banners, analyses which trackers load before consent, validates your privacy policy presence and checks security headers. The audit is free and takes under a minute.
Run the GDPR Auditor and get actionable results in minutes. Pay as you go.
Run GDPR Audit →