GDPR and CCPA Compliance for Websites: Practical Checklist

A practical GDPR/CCPA checklist for marketing sites: what to disclose, what to collect, cookies, and the vendor list most privacy pages forget.

Written and reviewed by Artem Palamarchuk, Founder of BLEX STUDIO.

What does a marketing website need for GDPR and CCPA?

Tell people what you collect, why, who you share it with, and how they can say no or delete. Then make the site behave that way. A 4,000-word privacy policy with a cookie banner that rejects nothing is theater.

The practical checklist

Privacy policy that names real vendors (analytics, CRM, host, email, chat)

Contact form collects only what you use

Marketing cookies wait for consent where required

Reject must work — not a fake button

Analytics in consent mode or a privacy-respecting default

Do I need GDPR if I am a Texas business?

If you have EU visitors or customers, treat GDPR as in play. If you truly have none, still be honest about US state privacy and ads pixels.

Is a cookie plugin enough?

Only if it actually blocks scripts. Many default installs are cosmetic.

Can we skip analytics?

Yes. Server logs and Search Console already tell you a lot. Less tracking is a valid strategy.

What about chat widgets?

They are vendors. Name them, DPA them, and do not auto-load if you claim a strict banner.

How much does a privacy pass cost?

A marketing-site implementation is often $800–$4,000 plus legal review. Apps that store customer data are a different project.