1. Processing register (Art. 30)
- You maintain a register of all processing activities
- It contains all mandatory fields (purpose, categories, retention periods, etc.)
- It is updated at least annually
- Learn more: Processing register: obligations and examples
2. Legal basis for processing (Art. 6)
- A legal basis has been established for each processing activity
- Consent is freely given, specific, informed and unambiguous
- You can demonstrate the legal basis for each processing activity
3. Data processing agreements (Art. 28)
- A DPA is in place with every processor
- DPAs contain all mandatory provisions of Art. 28
- Expiry dates and renewal terms are tracked
- Sub-processor lists are monitored
- Learn more: What is a data processing agreement?
4. Privacy policy (Art. 13-14)
- You have a privacy notice that complies with Art. 13 and 14
- The notice is easily accessible (website, intranet)
- All mandatory elements are included
- The notice is updated when changes occur
5. Data subject rights (Art. 12-22)
- You have a procedure for handling data subject requests
- Requests are answered within 30 days
- Access, rectification, erasure, restriction, portability and objection rights are supported
- Requests are logged and documented
6. Breach procedure (Art. 33-34)
- You have an internal breach procedure
- All staff know what to do when a breach is suspected
- You can notify the authority within 72 hours
- You maintain an internal breach register
- Learn more: Data breach notification: procedure and deadlines
7. Security (Art. 32)
- Appropriate technical measures: encryption, access controls, backups, updates
- Appropriate organisational measures: policies, training, confidentiality agreements
- Regular evaluation of security measures
- Access to personal data is limited to those who need it
8. DPIA (Art. 35)
- You assess whether a DPIA is needed for new processing activities
- For high-risk processing you conduct a DPIA before starting
- The DPO (if appointed) is involved
- Learn more: Conducting a DPIA: step-by-step guide
9. Data Protection Officer (Art. 37-39)
- You have assessed whether you are required to appoint a DPO
- If required: the DPO has been appointed and registered
- The DPO has sufficient resources and independence
10. International transfers (Art. 44-49)
- You have mapped whether personal data is processed outside the EEA
- Appropriate safeguards are in place (adequacy decisions, SCCs, BCRs)
- Standard contractual clauses are up to date
11. Privacy by design and by default (Art. 25)
- Privacy is considered from the start when developing new systems or processes
- Default settings are privacy-friendly
- Data minimisation is applied
12. Awareness and training
- Staff are trained to recognise privacy risks
- New employees receive a privacy introduction
- Training is repeated periodically
Summary
GDPR compliance is not a one-time exercise but an ongoing process. By regularly reviewing this checklist and keeping documentation up to date, you reduce the risk of fines and demonstrate that you take privacy seriously. DPAkit helps you manage DPAs, the processing register, breaches and more from a single platform.