GDPR Compliance Checklist | Certifyi
Compliance checklist

GDPR Compliance Checklist

GDPR compliance starts with knowing what personal data you hold and why. Here's the order most companies work through it in.

Book a 20-min deal readiness call
  1. Determine if GDPR applies to you

    If you handle personal data of anyone in the EU, regardless of where your company is based, GDPR likely applies.

  2. Map your data

    Document what personal data you collect, where it's stored, who can access it, and where it flows, including third-party processors.

  3. Establish your lawful basis

    Every instance of personal data processing needs a documented lawful basis: consent, contract, legal obligation, or legitimate interest.

  4. Update privacy notices

    Tell people clearly what you collect, why, how long you keep it, and their rights, in plain language, not legalese.

  5. Build a data subject rights process

    Have a working process for access, correction, deletion, and portability requests, with realistic response timelines.

  6. Sign Data Processing Agreements

    Any vendor processing personal data on your behalf needs a DPA that meets GDPR's Article 28 requirements.

  7. Run Data Protection Impact Assessments

    For high-risk processing, like large-scale profiling or sensitive data, a DPIA is required before you start.

  8. Implement security measures

    Encryption, access controls, and pseudonymization appropriate to the risk of the data you hold.

  9. Prepare a breach response plan

    GDPR requires notifying regulators within 72 hours of a breach becoming known. Have the process ready before you need it.

  10. Appoint a DPO if required

    Public authorities and companies doing large-scale monitoring or special category data processing need a designated Data Protection Officer.

← Back to all checklists

What auditors actually ask for

  • Can you produce a Record of Processing Activities (Article 30)?
  • Is there a documented lawful basis for each processing purpose?
  • Can you evidence a data subject access request handled within one month?
  • Are DPAs signed with every processor?
  • Have you run DPIAs for high-risk processing?

Where teams most often trip up

  • Relying on consent where legitimate interest or contract is the better basis
  • No Record of Processing Activities, an immediate regulator red flag
  • Privacy notices written in legal language nobody reads
  • Missing the 72-hour breach notification window
  • International transfers without a valid transfer mechanism

Realistic timeline

GDPR is continuous rather than certified. Initial readiness typically takes 8-12 weeks, driven mostly by data mapping.

Scroll to Top