simpl.
Cybersecurity GRC 16 items

GDPR Data Protection Compliance Checklist

Assesses compliance with core General Data Protection Regulation obligations covering lawful processing, data subject rights, and accountability.

GDPREU 2016/679

Free PDF · enter your email to download.

Lawfulness & Principles

  • Is a lawful basis identified and documented for each processing activity? *
  • Are the data protection principles (minimization, purpose limitation, accuracy) applied? *
  • Where consent is the basis, is it freely given, specific, and withdrawable? *
  • Are additional conditions met for processing special category data? *

Records & Accountability

  • Is a Record of Processing Activities (RoPA) maintained? *
  • Are Data Protection Impact Assessments (DPIAs) performed for high-risk processing? *
  • Is a Data Protection Officer appointed where required? *
  • Is data protection by design and by default implemented? *

Data Subject Rights

  • Is a process in place to respond to access requests within one month? *
  • Can data be rectified, erased, or restricted upon valid request? *
  • Is data portability supported where applicable? *
  • Are transparent privacy notices provided to data subjects? *

Security & Transfers

  • Are appropriate technical and organizational security measures implemented? *
  • Are personal data breaches notified to the supervisory authority within 72 hours? *
  • Are international transfers covered by an adequacy decision or appropriate safeguards (e.g., SCCs)? *
  • Are processor agreements in place with all data processors? *

Download the full GDPR Data Protection Compliance Checklist checklist

Get it as a clean, printable PDF — free.