1. Lawful basis for every processing activity
Every use of personal data needs one of the six lawful bases before processing starts — you cannot swap basis later to fix a problem.
- Each processing activity is mapped to one lawful basis (consent, contract, legal obligation, vital interests, public task, legitimate interests). (Art. 6(1))
- Legitimate interests assessments (LIA) are documented for any activity relying on Art. 6(1)(f). (Art. 6(1)(f))
- Special category data (health, biometrics, beliefs) has an additional Art. 9 condition documented. (Art. 9)
- Children's data uses age assurance and, where applicable, parental consent. (Art. 8)
2. Privacy notice that meets Art. 13/14
The privacy notice must be reachable from every page and written in clear language, not legal boilerplate.
- Controller identity and contact details (and DPO, where appointed) are published. (Art. 13(1)(a)-(b))
- Purposes and lawful basis are listed per processing activity, not as one generic paragraph. (Art. 13(1)(c))
- Recipients and categories of recipients (analytics, hosting, payment, support vendors) are named. (Art. 13(1)(e))
- Retention periods — or the criteria used to set them — are stated. (Art. 13(2)(a))
- All data subject rights and the right to complain to a supervisory authority are described. (Art. 13(2)(b)-(d))
- Data obtained from third parties has an Art. 14 notice sent within one month. (Art. 14(3))
4. Data subject rights operations
Rights requests carry a one-month deadline, extendable by two months for complex cases.
- A monitored intake channel exists for access, rectification, erasure, restriction, portability and objection requests. (Art. 15-21)
- Identity verification is proportionate and does not collect excess data. (Art. 12(6))
- Responses are issued within one month, free of charge in ordinary cases. (Art. 12(3))
- Erasure propagates to backups, processors and analytics tools. (Art. 17(2))
- Portable data is exported in a structured, machine-readable format. (Art. 20)
5. Records of processing (ROPA)
The ROPA is the first document a supervisory authority asks for. The under-250-employee exemption rarely applies in practice.
- A ROPA exists covering purposes, data categories, recipients, transfers and retention. (Art. 30(1))
- Processor-side records are maintained where you process on behalf of others. (Art. 30(2))
- The ROPA is reviewed whenever a new tool, vendor or feature is launched. (Art. 30)
6. Processors and vendor contracts
Every vendor touching personal data needs a written data processing agreement.
- A DPA with Art. 28(3) clauses is signed with every processor, including analytics and AI vendors. (Art. 28(3))
- Sub-processor changes require notice and an objection window. (Art. 28(2))
- Vendor security is assessed before onboarding and re-reviewed periodically. (Art. 28(1))
7. International transfers
Post-Schrems II, a transfer tool alone is not enough — you need a transfer impact assessment.
- Transfers outside the EEA are mapped, including US-hosted SaaS and CDNs. (Ch. V)
- An adequacy decision, the 2021 SCCs, or BCRs cover each transfer. (Art. 45-47)
- A transfer impact assessment documents supplementary measures where needed. (C-311/18)
8. Security and breach response
72 hours is the notification clock, and it starts at awareness, not at diagnosis.
- Encryption in transit and at rest, access control and logging are implemented. (Art. 32)
- A breach response plan names the decision-makers and the 72-hour notification path. (Art. 33(1))
- An internal breach register records every incident, including non-notifiable ones. (Art. 33(5))
- High-risk breaches trigger notification to affected individuals without undue delay. (Art. 34)
9. DPIAs and privacy by design
High-risk processing needs an assessment before launch, not after.
- A DPIA is completed for large-scale monitoring, profiling, special category data or new AI features. (Art. 35)
- Data protection by design and by default is applied to new features. (Art. 25)
- Defaults collect the minimum data necessary for the stated purpose. (Art. 5(1)(c))
10. Retention and deletion
Storage limitation is one of the most commonly failed principles in audits.
- A retention schedule sets a period for each data category. (Art. 5(1)(e))
- Automated deletion or anonymisation runs on schedule, including in logs and backups. (Art. 5(1)(e))
- Marketing lists are pruned of inactive contacts and suppression lists are respected. (Art. 5(1)(e))
11. Governance and accountability
Accountability means being able to demonstrate compliance, not just claim it.
- A DPO is appointed where Art. 37 triggers apply, and contact details are published. (Art. 37)
- An EU or UK representative is appointed for non-established controllers. (Art. 27)
- Staff handling personal data receive documented training. (Art. 39(1)(b))
- Policies are version-controlled with review dates. (Art. 5(2))
12. Website and product surface checks
These are the checks an automated scan of your live site can verify in minutes.
- Privacy policy and terms are linked in the footer of every page. (Art. 12(1))
- Forms use unbundled, unticked opt-ins and explain what happens to the data. (Art. 7(2))
- No tracker fires before consent on first load. (ePrivacy Art. 5(3))
- TLS is enforced site-wide and mixed content is eliminated. (Art. 32(1)(a))
- Embedded third parties (maps, chat, video, fonts) are consent-gated or self-hosted. (Art. 5(3))
GDPR checklist FAQs
Who does the GDPR apply to?
The GDPR applies to any organisation established in the EU that processes personal data, and to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour — including through website analytics and advertising trackers (Art. 3).
Do I need a cookie banner to be GDPR compliant?
You need consent before storing or reading non-essential cookies and similar identifiers under Art. 5(3) of the ePrivacy Directive. A banner is the usual mechanism, but it only counts if non-essential scripts are actually blocked until the visitor opts in, rejecting is as easy as accepting, and consent is logged.
How long do I have to answer a data subject access request?
One month from receipt, extendable by a further two months for complex or numerous requests, provided you inform the requester of the extension within the first month (Art. 12(3)).
What are the GDPR fines for non-compliance?
Up to EUR 10 million or 2% of global annual turnover for administrative breaches, and up to EUR 20 million or 4% of global annual turnover for breaches of core principles, lawful basis or data subject rights (Art. 83(4)-(5)).
Can this checklist replace legal advice?
No. It is a structured starting point grounded in the GDPR text and EDPB guidance. Obligations vary by sector, jurisdiction and processing activity, so confirm your final position with a qualified adviser.
