DLC Tech Solutions - IT Support for Small Business
    Compliance Assessment

    GDPR Compliance Checklist

    A comprehensive checklist to help you assess and verify your organisation's GDPR compliance.

    How to Comply

    Using This Checklist

    This GDPR compliance checklist covers the key requirements that most organisations need to address. Use it as a starting point to identify gaps in your compliance programme and prioritise remediation efforts.

    For a thorough assessment, we recommend combining this checklist with a professional GDPR audit that examines your specific processing activities, documentation, and technical controls.

    Remember that compliance is an ongoing process. This checklist should be reviewed regularly, particularly when you introduce new processing activities or systems.

    Lawfulness & Transparency

    • Identified and documented lawful basis for each processing activity
    • Privacy notices are clear, accessible, and up-to-date
    • Processing purposes are clearly defined and communicated
    • Consent is freely given, specific, informed, and unambiguous where relied upon
    • Consent can be easily withdrawn

    Data Subject Rights

    • Procedures in place to handle Subject Access Requests (SARs) within one month
    • Process for rectification of inaccurate personal data
    • Erasure procedures ('right to be forgotten') documented
    • Data portability mechanisms available where applicable
    • Right to object processes implemented
    • Automated decision-making and profiling safeguards in place

    Data Protection by Design

    • Privacy by design embedded in new projects and systems
    • Data minimisation principle applied - only necessary data collected
    • Storage limitation - data retained only as long as needed
    • Data Protection Impact Assessments (DPIAs) conducted for high-risk processing
    • Default settings favour privacy

    Security Measures

    • Appropriate technical measures in place (encryption, access controls)
    • Organisational measures implemented (policies, training)
    • Regular testing and evaluation of security effectiveness
    • Personnel security and confidentiality obligations
    • Physical security controls for data processing facilities

    Breach Management

    • Breach detection and investigation procedures documented
    • 72-hour notification process to ICO for qualifying breaches
    • Data subject notification procedures for high-risk breaches
    • Breach register maintained
    • Root cause analysis and remediation procedures

    Third Parties & Transfers

    • Data Processing Agreements with all processors
    • Due diligence conducted on third-party processors
    • International transfer mechanisms documented (SCCs, adequacy decisions)
    • Sub-processor management and approval procedures
    • Controller-to-controller data sharing agreements where applicable

    Additional Considerations

    Governance & Accountability

    • Data Protection Officer appointed (if required)
    • Records of Processing Activities maintained
    • Regular compliance reviews scheduled
    • Board-level accountability established

    Special Categories

    • Special category data identified and justified
    • Criminal conviction data handled appropriately
    • Children's data extra protections in place
    • Health data additional safeguards implemented

    If you're a data processor, additional requirements apply to your contracts and responsibilities. Learn how to audit your GDPR compliance systematically.

    Next Steps

    1

    Complete Assessment

    Work through each checklist item and document your current status

    Compliance guidance
    2

    Identify Gaps

    Prioritise areas where you need to improve based on risk

    Control framework
    3

    Get Expert Help

    Consider a professional audit to validate your assessment

    Audit services

    Need Help Completing Your Compliance Review?

    Our experts can conduct a comprehensive GDPR audit and help you address any compliance gaps.

    Speak to a Cyber Security Consultant

    If your organisation needs stronger assurance around identity, access, compliance, risk, or security improvement planning, we can help you define the right next steps and deliver them pragmatically.

    Start the Conversation

    30-minute consultation

    Prefer to book a call?

    Choose a suitable time and book a 30-minute consultation directly through our calendar.

    Explore xAudit

    Discover our purpose-built audit readiness platform for managing compliance across multiple frameworks.

    Visit xaudit.dlcts.co.uk

    Consultancy with Optional Platform Support

    Many clients combine consultancy support with xAudit to maintain visibility, evidence and momentum across remediation and audit readiness work.