GDPR Compliance Checklist
A comprehensive checklist to help you assess and verify your organisation's GDPR compliance.
Using This Checklist
This GDPR compliance checklist covers the key requirements that most organisations need to address. Use it as a starting point to identify gaps in your compliance programme and prioritise remediation efforts.
For a thorough assessment, we recommend combining this checklist with a professional GDPR audit that examines your specific processing activities, documentation, and technical controls.
Remember that compliance is an ongoing process. This checklist should be reviewed regularly, particularly when you introduce new processing activities or systems.
Lawfulness & Transparency
- Identified and documented lawful basis for each processing activity
- Privacy notices are clear, accessible, and up-to-date
- Processing purposes are clearly defined and communicated
- Consent is freely given, specific, informed, and unambiguous where relied upon
- Consent can be easily withdrawn
Data Subject Rights
- Procedures in place to handle Subject Access Requests (SARs) within one month
- Process for rectification of inaccurate personal data
- Erasure procedures ('right to be forgotten') documented
- Data portability mechanisms available where applicable
- Right to object processes implemented
- Automated decision-making and profiling safeguards in place
Data Protection by Design
- Privacy by design embedded in new projects and systems
- Data minimisation principle applied - only necessary data collected
- Storage limitation - data retained only as long as needed
- Data Protection Impact Assessments (DPIAs) conducted for high-risk processing
- Default settings favour privacy
Security Measures
- Appropriate technical measures in place (encryption, access controls)
- Organisational measures implemented (policies, training)
- Regular testing and evaluation of security effectiveness
- Personnel security and confidentiality obligations
- Physical security controls for data processing facilities
Breach Management
- Breach detection and investigation procedures documented
- 72-hour notification process to ICO for qualifying breaches
- Data subject notification procedures for high-risk breaches
- Breach register maintained
- Root cause analysis and remediation procedures
Third Parties & Transfers
- Data Processing Agreements with all processors
- Due diligence conducted on third-party processors
- International transfer mechanisms documented (SCCs, adequacy decisions)
- Sub-processor management and approval procedures
- Controller-to-controller data sharing agreements where applicable
Additional Considerations
Governance & Accountability
- Data Protection Officer appointed (if required)
- Records of Processing Activities maintained
- Regular compliance reviews scheduled
- Board-level accountability established
Special Categories
- Special category data identified and justified
- Criminal conviction data handled appropriately
- Children's data extra protections in place
- Health data additional safeguards implemented
If you're a data processor, additional requirements apply to your contracts and responsibilities. Learn how to audit your GDPR compliance systematically.
Next Steps
Complete Assessment
Work through each checklist item and document your current status
Compliance guidanceNeed Help Completing Your Compliance Review?
Our experts can conduct a comprehensive GDPR audit and help you address any compliance gaps.
Speak to a Cyber Security Consultant
If your organisation needs stronger assurance around identity, access, compliance, risk, or security improvement planning, we can help you define the right next steps and deliver them pragmatically.
Start the Conversation
Prefer to book a call?
Choose a suitable time and book a 30-minute consultation directly through our calendar.
Explore xAudit
Discover our purpose-built audit readiness platform for managing compliance across multiple frameworks.
Visit xaudit.dlcts.co.ukConsultancy with Optional Platform Support
Many clients combine consultancy support with xAudit to maintain visibility, evidence and momentum across remediation and audit readiness work.
