Only the rules this site faces
Tick EU/EEA, UK or US states on the first task and conditional logic shows the consent banner checks, the PECR exception task or the opt-out and GPC tests to match. A clean first scan hides the fix-and-retest phase.
This free website privacy checklist is for privacy leads, DPOs and the web and marketing teams who own a site’s tags. It reviews one website every quarter or after a major release: a cookie and tag scan, the consent banner and its configuration, the privacy notice, forms, pixels and embedded tools, US opt-out links and Global Privacy Control, and children. Each review ends with dated scan evidence, a fix-and-retest record where needed and an approved, published notice.
A website changes faster than any privacy policy. Every campaign tag, plug-in update and new widget can set a cookie before the visitor has chosen anything, and regulators test exactly that: they load the page in a clean browser and look at what fires. The annual GDPR compliance audit gives cookies one line; this review goes deep on one site, often enough to catch drift.
Europe works on consent first: nothing non-essential is stored on or read from the device until the visitor agrees. The US works on opt-out: tracking can run, but the visitor must be able to stop the sale or sharing of their data, and a browser signal counts as that request.
Rule: consent before storing or reading information on the device, unless strictly necessary for a service the user asked for. It applies whether or not the data is personal.
Courts: in Planet49 (C-673/17, 1 October 2019) a pre-ticked box was not consent, and users must be told how long cookies last and which third parties get access.
Regulators: the EDPB’s cookie banner taskforce (January 2023) and its Guidelines 2/2023, final in October 2024, which bring pixels and URL tracking within the rule.
Rule: consent unless an exception in new Schedule A1 applies, in force from 5 February 2026. Instigating a third party’s cookie counts too.
Exceptions: strictly necessary, plus analytics to improve your own site and remembering a visitor’s display or feature preferences, if you explain them and offer a simple, free way to object.
Fines: up to £17.5 million or 4% of worldwide turnover since 5 February 2026. The regulator is the Information Commission, still known as the ICO.
Rule: a business that sells or shares personal information needs a “Do Not Sell or Share My Personal Information” link, and ad pixels often count as sharing.
Signals: Global Privacy Control must be honoured as an opt-out in California, and since 1 January 2026 the site must show that it was.
Other states: Colorado has required opt-out signals to be honoured since 1 July 2024 and Connecticut since 1 January 2025.
Enforcement is aimed at the obvious failures. In January 2025 the ICO said it had assessed the top 200 UK websites, raised concerns with 134 of them and would work through the top 1,000. In September 2025 California, Colorado and Connecticut announced a joint sweep of businesses that ignore Global Privacy Control. The full Californian programme lives in the CCPA/CPRA Compliance Checklist.
Six phases, one checklist per website per review. The jurisdictions you pick and the first scan’s result decide which phases appear.
The jurisdictions chosen on the first task decide whether Phases 2 and 4 appear. The answer on the second task decides whether Phase 5 appears.
Shown when the review covers EU/EEA or UK visitors. The exception task appears only when the UK is selected.
Shown when the review covers California or other US states.
Shown only when the first scan found non-essential cookies set before consent.
The approval is assigned to the privacy lead named in Phase 1.
The table maps each rule a website review tests to its source, where it applies and the phase that records the evidence. National laws and regulator guidance add detail, such as the CNIL’s conditions for consent-free audience measurement in France, so treat the table as a starting point, not legal advice.
| Requirement | Source | Applies to | Evidenced in |
|---|---|---|---|
| Consent before storing or reading on the device | ePrivacy Directive Art. 5(3) and national laws | EU/EEA | Phases 1, 2 and 5 |
| No pre-ticked boxes; cookie duration and third-party access explained | CJEU, Planet49 (C-673/17) | EU/EEA | Phase 2 |
| Reject alongside accept; no misleading design or legitimate interest | EDPB cookie banner taskforce report, 17 January 2023 | EU/EEA | Phase 2 |
| Pixels, URL tracking and similar techniques | EDPB Guidelines 2/2023, version 2.0 of 7 October 2024 | EU/EEA | Phases 1 and 3 |
| Withdrawing consent as easy as giving it | GDPR Art. 7(3) | EU/EEA, UK | Phase 2 |
| Storage and access rule, including instigating it | PECR reg. 6, substituted from 5 February 2026 | UK | Phases 1 and 2 |
| Strictly necessary, statistical and appearance exceptions | PECR Schedule A1 | UK | Phase 2 |
| Data minimisation and notice on forms | GDPR Arts. 5(1)(c) and 13 | EU/EEA, UK | Phase 3 |
| Children’s consent | GDPR Art. 8; COPPA Rule | EU/EEA, UK, US | Phase 3 |
| Do Not Sell or Share link | CCPA, Cal. Civ. Code §1798.135 | California | Phase 4 |
| Opt-out preference signals | CCPA regulations §7025; Colorado and Connecticut laws | US states | Phase 4 |
| Notice and evidence kept current | GDPR Art. 5(2) accountability | EU/EEA, UK | Phase 6 |
Two things were moving at the time of review. The Commission’s Digital Omnibus proposal of 19 November 2025 would move the cookie rules for personal data into the GDPR, require a single-click refusal, bar asking again for six months after a refusal, allow consent-free audience measurement for the site’s own use and require websites to accept automated browser signals. It was still at first reading without a Council mandate in September 2026, so Article 5(3) and national laws apply as they stand. In California, the agency’s Board asked staff in August 2026 to draft rules naming Global Privacy Control as a valid signal, and from 1 January 2027 browsers must offer an opt-out signal setting. Nothing on this page is legal advice.
Tick EU/EEA, UK or US states on the first task and conditional logic shows the consent banner checks, the PECR exception task or the opt-out and GPC tests to match. A clean first scan hides the fix-and-retest phase.
Scan reports, banner screenshots and GPC test results attach to the task they belong to, with who completed it and when.
A quarterly schedule starts each review automatically, and you can start an extra run when a redesign ships. The updated notice cannot be published until the privacy lead approves it, and template versioning carries rule changes forward.
CheckFlow is not a cookie scanner, a consent management platform or a legal adviser. Your scanner finds the cookies and your consent platform shows the banner; CheckFlow runs the review around them, holds the evidence and tracks every fix to an owner. Run it on a recurring schedule alongside the rest of your privacy calendar in CheckFlow’s compliance checklist software.
The website is one part of a privacy programme. The GDPR Compliance Audit Checklist reviews the whole programme each year, and the CCPA/CPRA Compliance Checklist covers California beyond the site. Requests that arrive through your web form follow the DSAR Response Checklist. The banner must also work by keyboard, which the WCAG 2.2 Accessibility Audit Checklist tests, and a new tracking tool such as session replay may need a DPIA first.
In the EU, generally yes, unless a national regulator allows a narrow exemption. The CNIL, for example, accepts audience measurement without consent only where it produces anonymous statistics for the publisher alone. In the UK, since 5 February 2026 analytics used only to improve your own site or service can run without consent if you explain it and offer a free way to object. The ICO’s April 2026 guidance excludes advertising measurement, profiling and cross-site tracking.
In practice, yes. In the EDPB taskforce report, most European authorities agreed that a banner offering Accept without a reject option on the same layer does not obtain valid consent, and that a reject link hidden in text can also fail. The ICO expects accept and reject to be equally easy. A visible ‘Reject all’ next to ‘Accept all’ is the safest design.
GPC is a browser setting that tells every site the visitor wants to opt out of the sale or sharing of their data. California requires businesses that sell or share to treat it as a valid opt-out, and Colorado and Connecticut require opt-out signals to be honoured too. Test it with a GPC-enabled browser and check that advertising tags actually stop.
No law sets a frequency. Quarterly suits most marketing sites, plus a run after any redesign, new consent platform or new tag. A busy e-commerce site with weekly releases is better served by a scan in every release, with this checklist each quarter.
Since 5 February 2026, PECR breaches carry the UK GDPR’s higher maximum: £17.5 million or 4% of total worldwide annual turnover, whichever is higher. The previous cap was £500,000.
Not soon, and not entirely. The proposal would exempt some uses, such as audience measurement for the site’s own use, and push towards browser-level signals, but advertising cookies would still need consent. It was not law at the time of review and could change substantially in negotiation, so keep reviewing against Article 5(3) as it stands.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.