GDPR Readiness
Checklist for Startups
If you have EU or UK users, GDPR applies, wherever your company is based. Check off what you've actually handled across consent, data rights, security, and vendors to get a readiness score and the gaps that carry the most risk.
Legal basis & consent
Transparency
Data subject rights
Data handling & security
Third parties & transfers
Accountability
GDPR readiness score
0/100
High compliance risk
You are handling personal data without the basics in place. Start with the fixes below.
Fix these first
Want compliance built into the product, not bolted on?
Book a Free Call →A practical self-assessment, not legal advice. For a binding compliance opinion, consult a qualified data-protection lawyer or your DPO. Nothing you enter leaves your browser.
Need help getting your startup GDPR-compliant before it becomes a problem?
What each GDPR category actually requires
Legal basis and consent
Every act of processing personal data needs a documented lawful basis. For most startups the relevant bases are contract (you need the data to deliver the service the user signed up for), consent (freely given, specific, and as easy to withdraw as to give), and legitimate interest (a balancing test that most analytics and B2B marketing use). Cookie banners that pre-tick boxes or that have no reject option are not valid — consent must be an active, informed choice. If you send marketing emails, opt-in at the point of collection is required; soft opt-in is only available for existing customers.
Transparency
Users must know what you collect, why, how long you keep it, and who you share it with — in plain language, at the point of collection. A privacy policy buried in the footer is necessary but not sufficient. If you add a new tracker, change your data retention period, or sign up a new vendor, your policy needs to reflect it. Inaccurate policies can be treated as misleading, which is worse than having a simple policy that honestly describes a limited practice.
Data subject rights
GDPR gives users the right to access a copy of their data, correct inaccuracies, delete it (the “right to erasure”), restrict processing, and port it to another service. You must be able to action these requests within 30 days. The deletion right is the one most startups fail on: soft-deleting a record in your primary database is rarely enough if the data also exists in backups, third-party analytics, email systems, or data warehouses. Build the full deletion flow before you have many users, not after a formal request arrives.
Data handling and security
Data minimisation means collecting only what you genuinely need for the purpose stated — not fields you might find useful later. Technical security measures must be appropriate to the risk: encryption in transit (HTTPS) and at rest, access controls that limit who can query production data, and a retention policy that purges data you no longer need. Storing everything forever is a liability, not an asset.
Third parties and international transfers
Every vendor that processes personal data on your behalf is a data processor, and GDPR Article 28 requires a signed Data Processing Agreement (DPA) with each one. Most major providers — AWS, Stripe, Google, Vercel, Postmark, Intercom — offer a standard DPA in their settings panel. For transfers to countries outside the UK or EU, you need a legal mechanism: Standard Contractual Clauses (SCCs) cover most US vendors. Sending EU user data to a US service without SCCs in place has been the basis for several high-profile regulatory actions since Schrems II.
Accountability
Accountability means being able to demonstrate compliance, not just claim it. That includes keeping a Record of Processing Activities (ROPA) if you are required to (most startups with fewer than 250 employees are exempt unless processing is high-risk or regular), having a documented breach response process that can notify the relevant supervisory authority within 72 hours, and reviewing new features for privacy implications before shipping rather than after a complaint. Assigning one person accountable for data protection — even if that is the founder — forces the right habits before a formal DPO is needed.
Compliance is cheaper built in than bolted on
Most GDPR problems are not malice, they are architecture. Data gets collected because a form had an extra field, spread to vendors nobody signed agreements with, and stored in places no one can fully account for. By the time a user asks for deletion or a regulator asks a question, untangling it is expensive.
Handled early, the same requirements are cheap: collect less, encrypt it, sign the DPAs, and build a real path to export and delete a user. That is data protection by design, and it is far easier to bake in now than to retrofit after the product has scaled. This checklist shows you where you stand and what to fix first.
Frequently asked questions
Does GDPR apply to my startup?
If you offer goods or services to people in the EU or UK, or monitor their behaviour (analytics, ads), GDPR/UK GDPR applies regardless of where your company is based. A US startup with EU users is in scope. So is a tiny side project that collects EU emails.
What are the biggest GDPR risks for a small startup?
The common ones are: a cookie banner that does not let users actually reject tracking, no real way to delete a user's data on request, no Data Processing Agreements with the vendors that handle your data (hosting, analytics, Stripe, email), and sending EU data to US services without a transfer safeguard. Those are weighted highest in this checklist.
Is a privacy policy enough to be GDPR compliant?
No. A privacy policy is necessary but it is only the transparency piece. Compliance also requires a lawful basis for processing, valid consent where needed, the ability to honour data subject rights (access, deletion), security measures, vendor agreements, and accountability records. A policy describing things you do not actually do can make matters worse.
Do I need a Data Protection Officer (DPO)?
Most early startups do not, but you should assess it rather than assume. A DPO is required if your core activities involve large-scale systematic monitoring or large-scale processing of special-category data. If not required, you still benefit from naming someone accountable for data protection.
What is a Data Processing Agreement (DPA) and do I need one?
A DPA is a contract between you (the data controller) and any third party that processes personal data on your behalf (the processor). Under GDPR Article 28, you are legally required to have DPAs in place with every vendor that touches your users' personal data: your hosting provider, email service, analytics tool, payment processor, and any other SaaS that handles user information. Most major vendors (AWS, Stripe, Mailchimp, Vercel) offer a standard DPA you can sign through their portal, often in a few clicks.
What are the GDPR fines for non-compliance?
GDPR fines are tiered. Less severe infringements can be fined up to €10 million or 2% of global annual turnover (whichever is higher). More serious violations — including processing without a lawful basis, ignoring data subject rights, or international transfer failures — can reach €20 million or 4% of global annual turnover. Regulators also consider proportionality, so a startup that cooperated and fixed issues quickly typically faces lower penalties than one that ignored warnings.
Does GDPR apply to B2B startups that only collect business email addresses?
Business email addresses (e.g. john@company.com) are still personal data under GDPR if they identify an individual. Purely generic addresses like info@company.com are less clear-cut. If you collect first name, last name, and work email to identify a person, GDPR applies. B2B marketing emails also require a lawful basis — typically legitimate interest, but you must still offer a clear opt-out and honour unsubscribe requests promptly.
Is this checklist legal advice?
No. It is a practical self-assessment to help you find and prioritise gaps. For a binding compliance opinion, consult a qualified data-protection lawyer or your DPO. Nothing you enter is stored or leaves your browser.
Building for the European market?
I help European startups build GDPR and data protection into the product from the start, so compliance is an architecture decision, not a fire drill.