GDPR Compliance Checklist

GDPR compliance checks for data protection and privacy

Version 1.0.0Updated Jan 21, 2025
📝 Suggest Change

Checks

Privacy Policy

Verify privacy policy is published and accessible

Required by GDPR Article 13

critical

Consent Mechanism

Verify consent mechanism is implemented for data collection

Required by GDPR Article 6

critical

Granular Consent

Verify consent is granular (not all-or-nothing)

Required by GDPR for different processing purposes

critical

Consent Withdrawable

Verify users can withdraw consent easily

Required by GDPR Article 7

critical

Data Subject Rights

Verify mechanism for data subject rights requests (access, rectification, erasure)

Required by GDPR Articles 15-17

critical

Data Retention Policy

Verify data retention policy is defined and implemented

Required by GDPR Article 5

critical

Data Minimization

Verify only necessary data is collected

Required by GDPR Article 5

critical

Lawful Basis

Verify lawful basis for processing is documented

Required by GDPR Article 6

critical

Data Processing Agreement

Verify DPAs are in place with all processors

Required by GDPR Article 28

critical

Data Breach Procedure

Verify data breach notification procedure is documented

Required by GDPR Article 33

critical

DPO Appointed

Verify DPO is appointed if required

Required by GDPR Article 37 for certain organizations

major

Records of Processing

Verify records of processing activities are maintained

Required by GDPR Article 30

critical

Cross-Border Transfer

Verify adequate safeguards for transfers outside EEA

Required by GDPR Chapter V

critical

Data Encryption

Verify personal data is encrypted in transit and at rest

Required by GDPR Article 32

critical

Access Controls

Verify access controls limit who can access personal data

Required by GDPR Article 32

critical

Cookie Consent

Verify cookie consent banner is implemented

Required by ePrivacy Directive

critical

Cookie Policy

Verify cookie policy is published

Required by ePrivacy Directive

critical

Age Verification

Verify age verification for users under 16 (or local age)

Required by GDPR Article 8

major

Opt-Out Mechanism

Verify opt-out mechanism for marketing communications

Required by GDPR for marketing

critical

Data Portability

Verify mechanism for data portability requests

Required by GDPR Article 20

major

Profiling Consent

Verify consent for automated decision-making/profiling

Required by GDPR Article 22

major

Third-Party Disclosure

Verify privacy policy discloses all third parties

Required by GDPR Article 13

critical

Data Security Measures

Verify appropriate technical and organizational measures

Required by GDPR Article 32

critical

Regular Security Audits

Verify regular security audits are conducted

Required by GDPR Article 32

major

Staff Training

Verify staff are trained on GDPR requirements

Required by GDPR Article 32

major

Incident Response Plan

Verify incident response plan is documented

Required by GDPR Article 33

critical

Data Mapping

Verify data mapping documents all personal data flows

Required for GDPR compliance

critical

Privacy by Design

Verify privacy by design principles are applied

Required by GDPR Article 25

major