EU Compliance Checklist for Small Businesses in 2026: GDPR, AI Act, DSA & Cookie Law

Running a small business in the EU means navigating a growing stack of regulations — GDPR, the AI Act, the Digital Services Act, cookie law, and the European Accessibility Act. Most of these aren’t optional, and fines for non-compliance are real. The good news: most requirements are straightforward once you know what to look for.

This checklist covers the four areas that matter most for EU SMEs in 2026, with concrete actions you can take this week.


1. GDPR — Data Privacy Fundamentals

GDPR applies to any business that collects or processes personal data from EU residents — including website visitors, customers, and newsletter subscribers. There is no minimum size threshold. A one-person shop selling online is in scope.

What you must have in place:

  • Privacy policy that explains what data you collect, why, how long you keep it, and who you share it with
  • Cookie consent banner that gets explicit consent before loading tracking cookies — pre-ticked boxes or “by continuing to browse” wording doesn’t count
  • Data processing records — an internal log of what personal data you hold and why (even a spreadsheet works for most SMEs)
  • Vendor agreements — Data Processing Agreements (DPAs) with any third-party tools that handle personal data on your behalf (email providers, CRMs, analytics platforms)
  • Breach response plan — you have 72 hours to notify your supervisory authority if a breach occurs

Common gaps Clerify finds:

  • Google Analytics or Meta Pixel loading before consent is given
  • No lang attribute on the HTML page (affects data subject rights communication)
  • Privacy policy missing the legal basis for each category of processing

2. EU AI Act — What SMEs Need to Do Now

The AI Act became fully enforceable in stages throughout 2025–2026. If you use AI tools in your business — a chatbot on your website, an automated hiring tool, a customer scoring system — you may have obligations.

The key question: what risk category does your AI use fall into?

  • Minimal risk (spam filters, AI-written blog posts, recommendation engines): no mandatory requirements, but transparency best practice is encouraged
  • Limited risk (chatbots interacting with users): you must inform users they are talking to an AI — this is now legally required
  • High risk (AI used in HR decisions, credit scoring, access to essential services): full technical documentation, human oversight, and registration in the EU database required

Practical actions for most SMEs:

  • Add a visible disclosure on any page where an AI chatbot is active (“You are chatting with an AI”)
  • Review your SaaS tools — if a vendor’s AI makes decisions about your customers, ask for their AI Act compliance documentation
  • If you built or customised an AI system yourself, document its purpose, training data, and how humans can override its outputs

3. Digital Services Act (DSA) — For Businesses With Online Platforms

The DSA primarily targets large platforms, but smaller online services still have baseline obligations if they host user-generated content.

You are likely in scope if:

  • You run a marketplace, forum, or review section where third parties post content
  • You offer a service that intermediates between buyers and sellers

Baseline obligations for smaller platforms:

  • Publish a single point of contact for authorities
  • Have a mechanism for users to report illegal content
  • Act on illegal content notices in a reasonable timeframe
  • If you’re based outside the EU but serve EU users, appoint an EU legal representative

Most SMEs with a standard website — a product page, a blog, a contact form — are not covered by the DSA’s platform obligations. If in doubt, the test is whether third parties can post content visible to other users.


Cookie law in the EU is enforced under national implementations of the ePrivacy Directive, reinforced by GDPR consent requirements. Despite being over a decade old, it remains the most commonly failed check in Clerify’s free scans.

The rules, in plain language:

  • Strictly necessary cookies (session, login, cart): no consent required
  • All other cookies (analytics, advertising, personalisation): explicit opt-in consent required before the cookie is set
  • The consent mechanism must be as easy to withdraw as it is to give — a simple “Accept all” with no “Reject all” option is increasingly being fined across EU member states

What compliant looks like:

  • Cookie banner appears on first visit, before any non-essential scripts load
  • User can choose “Accept”, “Reject”, or manage preferences granularly
  • Consent choice is stored and respected on subsequent visits
  • A record of consent is kept (most cookie platforms handle this automatically)

Tools that make this easy: Cookiebot, CookieYes, and OneTrust all have SME tiers. Configuration takes under an hour if you haven’t set one up yet.


How to Audit Your Own Site Today

You don’t need a lawyer to do a first-pass compliance check. Here’s what to look at:

  1. Open your site in an incognito window. Do any third-party scripts load before you interact with the cookie banner? Check your browser’s Network tab.
  2. Search your site for “Privacy Policy”. Does the link in the footer actually go somewhere? Is the document up to date?
  3. Find every place you collect personal data — contact forms, newsletter signups, checkout flows, account creation. Does each one have a clear explanation of what happens to the data?
  4. Check your AI tools. List every SaaS product you use. Does any of them make automated decisions about people? If so, it warrants a closer look under the AI Act.

Or run a free Clerify scan — it checks your public-facing site against GDPR, AI Act, DSA, Cookie Law, and Accessibility requirements in under 60 seconds, and gives you a plain-language report with prioritised fixes.


The Cost of Getting It Wrong

EU data protection fines can reach €20 million or 4% of global annual turnover under GDPR — whichever is higher. In practice, most SME fines are smaller, but regulators across France, Italy, Ireland, and Germany have been increasingly active since 2024, and the trend is toward more enforcement, not less.

More importantly: compliance builds customer trust. A transparent privacy policy and a clean cookie setup tell your customers you take their data seriously. That matters.


Start With One Thing

Don’t try to fix everything at once. Pick the highest-risk gap — usually the cookie banner — and get that right first. Then move to your privacy policy, then your vendor agreements.

If you’re not sure where your biggest gap is, run the free Clerify scan. You’ll get a prioritised checklist in 60 seconds, no account required.