About this tool
A GDPR checklist scoped to your blog's actual features — analytics, ads, newsletter, comments — with the article behind each item.
GDPR Compliance Checklist for Blogs turns a list of the features your blog actually uses — analytics, ads, a newsletter, comments, embeds, non-EU hosting — into the subset of obligations that follow from them, each labelled with the provision it comes from. It covers the GDPR duties most blogs meet in practice (Articles 6, 7, 12-17, 21, 28, 30, 32, 33 and 44-46) plus the cookie consent rule that actually bites, Article 5(3) of the ePrivacy Directive. Items are weighted by severity so the score reflects whether the critical things are done, not just how many boxes are ticked.
Open GDPR Compliance Checklist for Blogs on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Items appear only when a feature you actually use triggers them, so the list stays short and honest.
Critical items count triple, so a high score genuinely means the risky gaps are closed.
Each line names its GDPR article or ePrivacy provision, so you can read the original before acting.
Yes, if you process personal data of people in the EU or EEA — and analytics identifiers, comment records, IP addresses in server logs and newsletter emails all count. There is no small-blog exemption; what is relaxed for organisations under 250 employees is only the formal record-of-processing obligation in Article 30(5), and even that has exceptions for regular processing.
If the analytics tool stores or reads anything on the reader's device, yes — Article 5(3) of the ePrivacy Directive requires prior consent for anything not strictly necessary, which is why the requirement applies even to analytics you consider harmless. The script must stay blocked until consent is given, and rejecting must be as easy as accepting.
Without undue delay, and in any event within one month of receiving the request under Article 12(3). That can be extended by a further two months for complex or numerous requests, but you have to tell the person about the extension within the first month, and the first copy of their data must be free.
In practice a small blog is far more likely to receive a complaint and an order to fix something than a fine. The theoretical ceiling under Article 83(5) is EUR 20 million or 4% of worldwide annual turnover, whichever is higher, but supervisory authorities weigh the nature, gravity and duration of the infringement and whether you cooperated.