Use this GDPR compliance checklist to test evidence, not to declare compliance from checked boxes. The GDPR is risk-based and fact-specific: each item should have an owner, supporting record, decision rationale, unresolved gap and review trigger.
1. Scope and accountability
- Identify legal entities and controller, joint-controller and processor roles.
- Document whether Article 3 applies to each relevant establishment or non-EU activity.
- Name accountable business owners for processing activities.
- Maintain governance, reporting and escalation routes.
- Assess whether an EU representative is required under Article 27.
- Assess whether a DPO is mandatory under Article 37 or national law.
- Keep evidence for decisions that no representative or DPO is required.
2. Processing inventory and lawful basis
- Maintain a current data map and Article 30 records where required.
- Record specific purposes and Article 6 lawful bases by activity.
- Record an Article 9 condition where special-category data is processed.
- Address Article 10 conditions for criminal-conviction data.
- Test necessity where relying on contract, legal obligation, public task or legitimate interests.
- Keep consent demonstrable, specific, informed, freely given and withdrawable where consent is used.
- Define retention or deletion criteria and verify they operate in systems and backups.
3. Transparency and individual rights
- Provide the applicable Articles 13 or 14 information in clear language.
- Keep notices aligned with actual purposes, recipients, transfers and retention.
- Authenticate rights requests proportionately.
- Route access, rectification, erasure, restriction, portability and objection requests.
- Respond without undue delay and generally within one month; document any lawful extension and notice.
- Identify automated decision-making that may fall within Article 22 and assess safeguards.
- Keep request decisions and communications as evidence.
Rights are qualified; for example, erasure does not override every legal retention duty. Procedures should support reasoned decisions rather than promise every requested outcome.
4. Privacy by design and high-risk processing
- Include data-protection review before new or materially changed processing starts.
- Minimise fields, defaults, access, audiences and retention.
- Screen for processing likely to result in high risk.
- Complete a DPIA before high-risk processing and record necessity, proportionality, risks and measures.
- Seek prior supervisory-authority consultation under Article 36 if high residual risk cannot be mitigated.
- Revisit DPIAs when risk or processing changes.
5. Processors and sharing
- Perform proportionate due diligence before appointment.
- Put Article 28 terms in place with processors.
- Control sub-processor authorisation and changes.
- Document instructions, confidentiality, security, assistance, deletion/return and audit information.
- Identify independent controllers and joint-controller arrangements rather than labelling every vendor a processor.
- Monitor material vendors and verify exit and deletion.
6. Security and personal-data breaches
- Select technical and organisational measures appropriate to risk under Article 32.
- Control identity, privilege, logging, patching, resilience, backup and recovery.
- Train people for their roles and test incident escalation.
- Keep an internal record of personal-data breaches, including facts, effects and remedial action.
- Notify the competent authority without undue delay and, where feasible, within 72 hours after awareness when Article 33’s risk threshold is met.
- Notify affected individuals without undue delay when Article 34’s high-risk threshold is met, subject to its exceptions.
The 72-hour rule is not a universal deadline to report every security event; it applies to supervisory-authority notification of qualifying personal-data breaches.
7. International transfers
- Inventory transfers and remote access from third countries.
- Verify current adequacy scope where relied on.
- Select an appropriate Article 46 safeguard where there is no applicable adequacy decision.
- Assess whether the transfer tool works effectively and add supplementary measures where necessary.
- Use Article 49 derogations only when their conditions are met.
- Monitor legal, recipient, sub-processor and technical changes.
8. Ongoing assurance
- Run a risk-based monitoring and audit programme.
- Track remediation to accountable owners and approved risk decisions.
- Report material issues and resource constraints to senior management.
- Review the programme after incidents, complaints, system changes and regulatory developments.
- Retain evidence that controls operate, not only policy documents.
For an independent evidence review, see our GDPR audit service. For help building missing controls and records, see data protection services.
Sources and review
- Regulation (EU) 2016/679, official text
- European Commission: GDPR obligations for businesses and organisations
- EDPB: endorsed GDPR guidance
Reviewed on 8 August 2026. Deadlines and notification thresholds are stated with their legal qualifiers.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.