Skip to main content
Back to knowledge base
Checklist

GDPR compliance checklist for SMEs

The GDPR imposes various requirements on organisations that process personal data. This checklist helps SMEs get and stay compliant.

28 March 20266 min read

1. Processing register (Art. 30)

2. Legal basis for processing (Art. 6)

  • A legal basis has been established for each processing activity
  • Consent is freely given, specific, informed and unambiguous
  • You can demonstrate the legal basis for each processing activity

3. Data processing agreements (Art. 28)

  • A DPA is in place with every processor
  • DPAs contain all mandatory provisions of Art. 28
  • Expiry dates and renewal terms are tracked
  • Sub-processor lists are monitored
  • Learn more: What is a data processing agreement?

4. Privacy policy (Art. 13-14)

  • You have a privacy notice that complies with Art. 13 and 14
  • The notice is easily accessible (website, intranet)
  • All mandatory elements are included
  • The notice is updated when changes occur

5. Data subject rights (Art. 12-22)

  • You have a procedure for handling data subject requests
  • Requests are answered within 30 days
  • Access, rectification, erasure, restriction, portability and objection rights are supported
  • Requests are logged and documented

6. Breach procedure (Art. 33-34)

7. Security (Art. 32)

  • Appropriate technical measures: encryption, access controls, backups, updates
  • Appropriate organisational measures: policies, training, confidentiality agreements
  • Regular evaluation of security measures
  • Access to personal data is limited to those who need it

8. DPIA (Art. 35)

  • You assess whether a DPIA is needed for new processing activities
  • For high-risk processing you conduct a DPIA before starting
  • The DPO (if appointed) is involved
  • Learn more: Conducting a DPIA: step-by-step guide

9. Data Protection Officer (Art. 37-39)

  • You have assessed whether you are required to appoint a DPO
  • If required: the DPO has been appointed and registered
  • The DPO has sufficient resources and independence

10. International transfers (Art. 44-49)

  • You have mapped whether personal data is processed outside the EEA
  • Appropriate safeguards are in place (adequacy decisions, SCCs, BCRs)
  • Standard contractual clauses are up to date

11. Privacy by design and by default (Art. 25)

  • Privacy is considered from the start when developing new systems or processes
  • Default settings are privacy-friendly
  • Data minimisation is applied

12. Awareness and training

  • Staff are trained to recognise privacy risks
  • New employees receive a privacy introduction
  • Training is repeated periodically

Summary

GDPR compliance is not a one-time exercise but an ongoing process. By regularly reviewing this checklist and keeping documentation up to date, you reduce the risk of fines and demonstrate that you take privacy seriously. DPAkit helps you manage DPAs, the processing register, breaches and more from a single platform.

Start GDPR compliance today

DPAkit helps you tick off this checklist: DPAs, processing register, breaches and more from a single platform.

Start for free