How to Check If a Company Is GDPR-Compliant
Before you hand a vendor your customers' personal data — or invest in a company that holds a lot of it — it's worth asking whether they actually take privacy seriously. You can't audit a company's internal systems from the outside, but you can learn a surprising amount from what the GDPR requires them to disclose. A company's privacy policy and public data practices are, by law, a window into its compliance posture. Here's how to read them.
Start with the privacy policy — as a disclosure, not marketing
Under the GDPR, a privacy policy is a legally-required statement of what data a company collects, why, on what legal basis, and who it shares with. Read it the way you'd read a risk factor. A vague, boilerplate policy that could belong to any company is a signal in itself — it often means privacy hasn't been thought through, not that there's nothing to disclose.
Look for a legal basis for processing
The GDPR requires a company to state a clear legal basis for each kind of processing — consent, legitimate interest, contractual necessity, or another Article 6 ground — rather than gesturing vaguely at "your consent" for everything. When a policy lists no bases at all, it usually means no one mapped the processing to the law. This is one of the fastest tells of a mature versus a superficial privacy program.
Check that data-subject rights actually work
A GDPR-compliant company gives people a working way to exercise their rights — access, deletion, correction, portability and objection. Look for a named contact, a form, or a request address. Rights granted on paper with no route to exercise them are a gap. A real mechanism signals the company expects to receive and handle these requests.
International transfers: where does the data go?
Once EU personal data leaves the EEA — usually to U.S. servers or vendors — the GDPR requires a lawful transfer mechanism, typically the EU-U.S. Data Privacy Framework for certified recipients or Standard Contractual Clauses for everyone else. A policy that names its transfer mechanism and lists the providers involved is telling you the company has thought this through. Silence on transfers, for a company with EU users and vendors abroad, is a red flag.
Retention, a DPO, and a DPA
Three quieter signals round out the check. Retention: does the policy say how long data is kept, rather than an open-ended "as long as necessary"? Accountability: does the company name a Data Protection Officer or EU representative where required, with a real way to reach them? And a DPA: for a vendor, does it offer a data processing agreement that commits it to handle your data on defined terms? A staffed privacy function and a real DPA separate a program that operates from one that only writes.
The one-minute cookie test
The fastest check of all is the consent banner. Open the site in a private window and watch what loads before you click. A compliant banner lets you refuse non-essential cookies as easily as you accept them, and it doesn't drop tracking cookies before you consent. A banner with only an "Accept" button, or one that loads trackers on arrival, reveals a gap between the policy's promises and the site's behavior — exactly what regulators look for.
The bottom line
You can gauge a company's GDPR posture in minutes from what it's legally required to publish: clear legal bases, working data-subject rights, a named transfer mechanism, stated retention, a real privacy contact, and an honest cookie banner. Just remember the limit — a polished policy proves a company can write one, not that it lives by it, so verify the high-stakes items directly. This is general information, not legal advice; privacy law is jurisdiction-specific and evolving.