by PrivScan (LX AI)

Blog · Home

A GDPR readiness checklist for SaaS teams

A GDPR readiness checklist is an ordered list of the disclosures, consents and records a SaaS product must have in place before it processes personal data of people in the EU or EEA. Its value is sequencing: it tells you which gap to close first, not just that gaps exist.

Key takeaways

What the checklist covers

  1. Purposes and lawful basis. Name the purpose for each category of personal data and the basis you rely on for it.
  2. Cookies, consent and trackers. Confirm nothing fires before the visitor has actually chosen.
  3. Data-collection surfaces. Signup forms, support widgets, analytics and AI features all collect — each needs to appear in the notice.
  4. Recipients and transfers. Processors, sub-processors and any transfer outside the EEA belong in the disclosure.
  5. Retention. State how long you keep each category, or the criteria used to decide.
  6. Data-subject requests. There must be a real path for access, correction, deletion and objection.
  7. Breach process. Who is told, by whom, and how quickly internally — before an incident, not during one.

Where PrivScan fits

Enter a URL and PrivScan scans the site or app for GDPR and consumer-privacy gaps — cookies, consent, trackers and data collection — then returns a prioritised remediation checklist your team can work through. The output is deliberately plain: a list of gaps, what each one relates to, and the order in which to close them.

What it does not do

It does not certify compliance, it does not replace a qualified reviewer, and it does not tell you what your internal records should say. A clean scan means no gaps were detected by these checks — not that your processing is lawful.

Frequently asked questions

Does passing a scan mean we are GDPR compliant?

No. It means the checks found no gaps at that URL at that time. Compliance depends on your processing, your records and your contracts, which still need human review.

What do we need to run it?

The URL you want scanned, and ideally a short note on how you collect user data. The more context you give, the more precise the checklist.

Does it look at cookies and trackers?

Yes. Cookie, consent and tracker findings are part of the scan, alongside data-collection review.

How often should we re-run it?

After any material change to tracking, forms, analytics or AI features, and again before a launch into a new market.

Is this legal advice?

No. It is a decision-support checklist. Have a qualified reviewer confirm the facts and the local requirements that apply to you.

Which regulations does it focus on?

GDPR and consumer-privacy themes. Other regimes have their own disclosure requirements that this scan does not cover.

References

Try the product: PrivScan

2026-09-20 · primary sources only · no fabricated traffic metrics · decision-support only