GDPR Compliance Checker
Checker
GDPR Compliance Checklist
Walk your form through the checklist below to spot the consent mechanisms, privacy links, data minimization, and other requirements you need. Then build a compliant form in minutes with WittyForm.
Start building freeWhat We Check
Consent Mechanism
Your form must collect explicit, informed consent before processing personal data. Pre-checked boxes are not valid.
Privacy Policy Link
A clearly visible link to your privacy policy must be accessible from the form, ideally near the consent checkbox.
Data Purpose Statement
Tell users exactly what their data will be used for: marketing, support, analytics, etc.
Data Minimization
Only collect fields that are strictly necessary for the stated purpose. Extra fields violate the minimization principle.
Right to Withdraw
Users must be informed they can withdraw consent at any time, with instructions on how to do so.
Data Retention Period
Disclose how long personal data will be stored and when it will be deleted.
Third-Party Disclosure
If data is shared with third parties (analytics, CRM, email tools), this must be disclosed.
Data Processing Agreement
If you use third-party processors, ensure you have a Data Processing Agreement (DPA) in place.
REQ = Required under GDPR, REC = Recommended best practice
GDPR Penalties
Lower Tier
Up to EUR 10 million or 2% of global annual turnover
Examples: Data breach notifications, record-keeping failures, DPIA omissions
Upper Tier
Up to EUR 20 million or 4% of global annual turnover
Examples: Consent violations, data subject rights violations, unlawful data transfers
Compliance Tips
- 1
Use granular consent: separate checkboxes for different processing purposes (marketing, analytics, third-party sharing).
- 2
Make consent active: use unchecked checkboxes that users must explicitly tick. Pre-checked consent is not valid under GDPR.
- 3
Add a privacy policy link directly on the form, not buried in a footer on a different page.
- 4
Implement a data deletion workflow: if a user requests erasure, you must be able to comply within 30 days.
- 5
Review third-party integrations: every tool that touches personal data (Google Analytics, Mailchimp, etc.) must be disclosed and covered by a DPA.