GDPR Compliance Checklist
GDPR compliance starts with knowing what personal data you hold and why. Here's the order most companies work through it in.
Book a 20-min deal readiness callDetermine if GDPR applies to you
If you handle personal data of anyone in the EU, regardless of where your company is based, GDPR likely applies.
Map your data
Document what personal data you collect, where it's stored, who can access it, and where it flows, including third-party processors.
Establish your lawful basis
Every instance of personal data processing needs a documented lawful basis: consent, contract, legal obligation, or legitimate interest.
Update privacy notices
Tell people clearly what you collect, why, how long you keep it, and their rights, in plain language, not legalese.
Build a data subject rights process
Have a working process for access, correction, deletion, and portability requests, with realistic response timelines.
Sign Data Processing Agreements
Any vendor processing personal data on your behalf needs a DPA that meets GDPR's Article 28 requirements.
Run Data Protection Impact Assessments
For high-risk processing, like large-scale profiling or sensitive data, a DPIA is required before you start.
Implement security measures
Encryption, access controls, and pseudonymization appropriate to the risk of the data you hold.
Prepare a breach response plan
GDPR requires notifying regulators within 72 hours of a breach becoming known. Have the process ready before you need it.
Appoint a DPO if required
Public authorities and companies doing large-scale monitoring or special category data processing need a designated Data Protection Officer.
What auditors actually ask for
- Can you produce a Record of Processing Activities (Article 30)?
- Is there a documented lawful basis for each processing purpose?
- Can you evidence a data subject access request handled within one month?
- Are DPAs signed with every processor?
- Have you run DPIAs for high-risk processing?
Where teams most often trip up
- Relying on consent where legitimate interest or contract is the better basis
- No Record of Processing Activities, an immediate regulator red flag
- Privacy notices written in legal language nobody reads
- Missing the 72-hour breach notification window
- International transfers without a valid transfer mechanism
Realistic timeline
GDPR is continuous rather than certified. Initial readiness typically takes 8-12 weeks, driven mostly by data mapping.