Cybersecurity GRC 16 items
GDPR Data Protection Compliance Checklist
Assesses compliance with core General Data Protection Regulation obligations covering lawful processing, data subject rights, and accountability.
GDPREU 2016/679
Free PDF · enter your email to download.
Lawfulness & Principles
- Is a lawful basis identified and documented for each processing activity? *
- Are the data protection principles (minimization, purpose limitation, accuracy) applied? *
- Where consent is the basis, is it freely given, specific, and withdrawable? *
- Are additional conditions met for processing special category data? *
Records & Accountability
- Is a Record of Processing Activities (RoPA) maintained? *
- Are Data Protection Impact Assessments (DPIAs) performed for high-risk processing? *
- Is a Data Protection Officer appointed where required? *
- Is data protection by design and by default implemented? *
Data Subject Rights
- Is a process in place to respond to access requests within one month? *
- Can data be rectified, erased, or restricted upon valid request? *
- Is data portability supported where applicable? *
- Are transparent privacy notices provided to data subjects? *
Security & Transfers
- Are appropriate technical and organizational security measures implemented? *
- Are personal data breaches notified to the supervisory authority within 72 hours? *
- Are international transfers covered by an adequacy decision or appropriate safeguards (e.g., SCCs)? *
- Are processor agreements in place with all data processors? *
Download the full GDPR Data Protection Compliance Checklist checklist
Get it as a clean, printable PDF — free.
