OpenDD
← All articles

How to Check If a Company Is GDPR-Compliant

Privacy · Updated August 2026

Before you hand a vendor your customers' personal data — or invest in a company that holds a lot of it — it's worth asking whether they actually take privacy seriously. You can't audit a company's internal systems from the outside, but you can learn a surprising amount from what the GDPR requires them to disclose. A company's privacy policy and public data practices are, by law, a window into its compliance posture. Here's how to read them.

Start with the privacy policy — as a disclosure, not marketing

Under the GDPR, a privacy policy is a legally-required statement of what data a company collects, why, on what legal basis, and who it shares with. Read it the way you'd read a risk factor. A vague, boilerplate policy that could belong to any company is a signal in itself — it often means privacy hasn't been thought through, not that there's nothing to disclose.

Look for a legal basis for processing

The GDPR requires a company to state a clear legal basis for each kind of processing — consent, legitimate interest, contractual necessity, or another Article 6 ground — rather than gesturing vaguely at "your consent" for everything. When a policy lists no bases at all, it usually means no one mapped the processing to the law. This is one of the fastest tells of a mature versus a superficial privacy program.

Check that data-subject rights actually work

A GDPR-compliant company gives people a working way to exercise their rights — access, deletion, correction, portability and objection. Look for a named contact, a form, or a request address. Rights granted on paper with no route to exercise them are a gap. A real mechanism signals the company expects to receive and handle these requests.

International transfers: where does the data go?

Once EU personal data leaves the EEA — usually to U.S. servers or vendors — the GDPR requires a lawful transfer mechanism, typically the EU-U.S. Data Privacy Framework for certified recipients or Standard Contractual Clauses for everyone else. A policy that names its transfer mechanism and lists the providers involved is telling you the company has thought this through. Silence on transfers, for a company with EU users and vendors abroad, is a red flag.

Retention, a DPO, and a DPA

Three quieter signals round out the check. Retention: does the policy say how long data is kept, rather than an open-ended "as long as necessary"? Accountability: does the company name a Data Protection Officer or EU representative where required, with a real way to reach them? And a DPA: for a vendor, does it offer a data processing agreement that commits it to handle your data on defined terms? A staffed privacy function and a real DPA separate a program that operates from one that only writes.

The one-minute cookie test

The fastest check of all is the consent banner. Open the site in a private window and watch what loads before you click. A compliant banner lets you refuse non-essential cookies as easily as you accept them, and it doesn't drop tracking cookies before you consent. A banner with only an "Accept" button, or one that loads trackers on arrival, reveals a gap between the policy's promises and the site's behavior — exactly what regulators look for.

Check a company's GDPR posture. OpenDD's Privacy Due Diligence builds a GDPR/CCPA scorecard from a company's own disclosures — legal bases, data-subject rights, retention, transfers, DPO and cookie consent — and flags the gaps. Run a privacy check →

The bottom line

You can gauge a company's GDPR posture in minutes from what it's legally required to publish: clear legal bases, working data-subject rights, a named transfer mechanism, stated retention, a real privacy contact, and an honest cookie banner. Just remember the limit — a polished policy proves a company can write one, not that it lives by it, so verify the high-stakes items directly. This is general information, not legal advice; privacy law is jurisdiction-specific and evolving.

Related guides

Privacy Due Diligence: GDPR & CCPA Signals → Data Governance Due Diligence → Third-Party & Vendor Due Diligence →