How to audit a website for privacy compliance (GDPR / CCPA / Privacy Act 2026)
The 8 observable signals that decide whether your website is GDPR / CCPA / Privacy Act compliant in 2026 - privacy policy completeness, cookie consent mechanism, pre-consent tracking, tracker inventory, form lawful basis, multi-jurisdiction coverage, DSAR mechanism, and modern signals (Consent Mode v2, GPC, Privacy Sandbox).
Frequently asked questions
Do I need a cookie banner if I only use first-party analytics?
In the EU/UK, probably yes - even first-party analytics typically uses cookies that fall under the UK's PECR regulations, which require opt-in for any non-essential cookie.
Is the Australian Privacy Act actually enforced for small businesses?
Currently most small businesses (under A$3M annual turnover) are exempt from the Privacy Act. The reform proposals under the Attorney-General are likely to remove that exemption.
My privacy policy is from 2021. Is it still valid?
Probably not. Major regulatory changes since 2021: California CPRA (2023), Google + Yahoo email auth (2024), Google Consent Mode v2 (2024), India DPDP Act (2023), Quebec Law 25 (2023-2024).
Do I need a DPO (Data Protection Officer)?
Under GDPR Article 37, only if you're a public authority, or you do large-scale systematic monitoring, or you process special-category data at scale.
What's the single highest-risk privacy issue for an SMB website?
Pre-consent tracking. Google Analytics or Meta Pixel firing before the user clicks Accept. This is the most-cited GDPR violation in regulator decisions against SMB sites.