GDPR Compliance Checklist

The full text of the General Data Protection Regulation runs to 99 articles and 173 recitals. For most small web products the practical surface is much smaller: do we have a lawful basis, is the privacy policy current, can we honour access and deletion requests, and do we have processor agreements in place? This checklist walks the ticks that matter most on day one.

How to use the checklist

  1. 1

    Read each item

    Eight areas cover the operational heart of the GDPR for a typical SaaS or marketing site.

  2. 2

    Tick what is actually done

    Evidence matters: a privacy policy that nobody updates does not count.

  3. 3

    Note gaps

    Turn unchecked items into tickets. Missing DPA or missing DSAR procedure are the most common.

  4. 4

    Revisit quarterly

    Data flows and processors change; so should the checklist.

Core items and the articles behind them

Checklist item GDPR article Notes
Lawful basis documented Art. 6 Consent, contract, legal obligation, etc.
Privacy policy published Arts. 12–14 Plain language, easily accessible
Consent collected where needed Art. 7 Freely given, specific, unambiguous
DSAR process (access, deletion) Arts. 15, 17 Reply within one month
DPA signed with every processor Art. 28 Analytics, email, hosting, each one
Breach response plan Art. 33 Notify authority within 72 hours of discovery
Data minimisation Art. 5(1)(c) Only collect what the purpose needs
Access controls & encryption Art. 32 Principle of “appropriate” security

What the checklist is not

  • Not a substitute for a DPO when the regulation requires one (large-scale monitoring, sensitive data).
  • Not legal advice. Jurisdiction-specific interpretations (national data-protection laws, ePrivacy) need a lawyer.
  • Not a cookie-banner generator. Cookies are governed by ePrivacy Directive + GDPR, related but separate.

Getting started order

  1. Map data: what you collect, from whom, for what purpose, stored where, shared with whom.
  2. Pick a lawful basis per purpose.
  3. Publish a policy that honestly reflects the map.
  4. Build the DSAR inbox (a single email address is fine; 30-day SLA matters more).
  5. Sign DPAs before going live with any new processor.

Frequently Asked Questions

If your site uses non-essential cookies (analytics, advertising, third-party embeds) you need prior consent, usually a banner with accept, reject and preferences. Strictly necessary cookies are exempt.

One calendar month from receipt, extendable by two more months for complex requests (Art. 12(3)). Acknowledge quickly even if the full export takes longer.

No. It applies whenever you offer goods or services to people in the EU/EEA, or monitor their behaviour there, regardless of where your company is based.

No. Your selections live in the browser session only. Export them to a project tracker if you need a record.

Related Tools

Tool available in other languages