Free download · EU-sovereign audit checklist
Audit your UK SMB website's compliance posture in 30 minutes.
The same 4-section checklist I run when I onboard a Tier 1 vertical client: where your forms post, where your analytics tracks, where your CRM stores, where your email sends. Pinpoints US-resident exposure + UK GDPR Article 30 gaps + sub-processor blind spots in under half an hour. Free PDF, no sign-up cost, no spam.
What's in the checklist
-
Section 1 — Forms + enquiry data
Where every form on your site posts. The four typical US-resident leaks (HubSpot embeds, Mailchimp signup, Typeform widgets, WordPress contact plugins) and what to replace them with.
-
Section 2 — Analytics + tracking
The Google Analytics / Facebook Pixel / LinkedIn Insight Tag question. Schrems II 2020 + the EU data-protection-authority rulings of 2022-2024. What "lawful basis" actually means for an analytics tag.
-
Section 3 — CRM + email marketing
Where your contacts sleep. HubSpot Free / Salesforce / Mailchimp / ActiveCampaign — the US-resident default stack and the EU alternatives. Capsule + Resend + Listmonk with named alternatives per use case.
-
Section 4 — Hosting + DNS + email forwarding
The infrastructure layer. WordPress on a US host vs Astro on Vercel London. Cloudflare DNS + Email Routing as the EU-sovereign default. The 8-row sub-processor disclosure template you can adapt for your own UK GDPR Article 30 records.
Who it's for
Specifically tuned for UK independent clinics, solicitors firms, schools + SEN providers, and accountancy practices — the four Tier 1 regulated verticals where data residency is part of the professional-conduct posture, not a footnote. Also useful for any UK B2B SaaS startup whose enterprise procurement is asking residency questions.
Not a generic GDPR overview — every action is concrete + named (specific tools to replace, specific replacements, specific URLs to verify).
Why it's free
Two reasons. First, the checklist is the start of the conversation, not the end — when you audit your site honestly and find five US-resident leaks, you'll want a builder who knows how to fix them. That's the UK Web Marketing pitch, made with evidence rather than slogans. Second, the more UK SMBs running compliant sites, the harder it is for cowboy agencies to keep selling "GDPR-ready" WordPress builds with HubSpot forms strapped on. Some honest competition is good for the market.
After you've audited
Want me to fix what the checklist flags?
The checklist is one half of the conversation. The other half is what to do about it. If the audit flags exposure you'd rather not carry, three paths: keep using the checklist as a roadmap and fix it yourself; WhatsApp me for a no-commitment second opinion; or start on the right tier and I'll do the rebuild on EU-sovereign infrastructure in a week.