EU checklist

GDPR Compliance Checklist

Based on Regulation (EU) 2016/679, the General Data Protection Regulation. Covers processing principles, data subject rights, breach notification, and international transfer requirements.

This checklist gives you the information. The judgment on what it means for you is still yours. You'll need to enter your email at the end to see your score.

Your progress0 of 33 · 0%
Processing principles
Are all personal data processing activities conducted lawfully, fairly, and transparently in relation to the data subject?
Has the data been collected for specified, explicit, and legitimate purposes, and is all subsequent processing compatible with those initial purposes?
Is the volume and type of personal data collected adequate, relevant, and strictly limited to what is necessary for the specified purposes?
Are reasonable steps taken to ensure that inaccurate personal data is rectified or erased without undue delay?
Have time limits been established for the storage period, ensuring personal data is not kept in a form that permits identification for longer than necessary?
Are appropriate technical and organisational measures implemented to ensure the security, integrity, and confidentiality of personal data, including protection against unauthorised or unlawful processing?
Lawful basis & special categories
Has at least one valid lawful basis (e.g., consent, contractual necessity, legal obligation, legitimate interests) been established and documented for all processing activities?
Is the processing of sensitive personal data (e.g., genetic data, health data, political opinions, biometric data for unique identification) prohibited unless a specific explicit consent or substantial public interest exemption applies?
Transparency & data subject requests
Is all information related to processing provided to the data subject in a concise, transparent, intelligible, and easily accessible form, using clear and plain language (especially for children)?
Does the Controller provide information on action taken on a data subject request (Articles 15-22) without undue delay and at the latest within one month of receipt?
Data subject rights
Can the data subject obtain confirmation of processing, access to the personal data, and a copy of the data undergoing processing (free of charge for the first copy)?
Does the data subject have the right to obtain the rectification of inaccurate data and have incomplete data completed without undue delay?
Are procedures in place to erase personal data without undue delay when grounds apply (e.g., data no longer necessary, consent withdrawn, or unlawful processing)?
Is the data subject enabled to receive their personal data in a structured, commonly used, and machine-readable format and transmit it to another Controller, provided the processing is automated and based on consent or contract?
Is the data subject explicitly informed of, and able to exercise, the right to object at any time, free of charge, to the processing of personal data for direct marketing purposes, including related profiling?
When using automated processing (including profiling) that produces legal or similarly significant effects, are suitable measures implemented to safeguard the data subject's rights, including the right to obtain human intervention and contest the decision?
Accountability & governance
Has the Controller implemented appropriate technical and organisational measures to ensure and be able to demonstrate compliance with this Regulation?
Are T&O measures, such as pseudonymisation, integrated into the processing design to ensure, by default, that only data necessary for each specific purpose is processed?
Does the Controller maintain a written record of processing activities that includes purposes, categories of recipients (including in third countries), and a general description of security measures?
Is processing carried out by a Processor governed by a written contract or legal act that stipulates that the Processor processes data only on documented instructions from the Controller?
DPO & impact assessment
Is a Data Protection Officer (DPO) designated, particularly if core activities involve large-scale regular and systematic monitoring of data subjects or large-scale processing of special categories of data?
Does the DPO report directly to the highest management level and operate without receiving instructions regarding the exercise of their tasks?
Is a Data Protection Impact Assessment (DPIA) carried out prior to any processing operation that is likely to result in a high risk to data subjects' rights and freedoms?
If a DPIA indicates high risk that cannot be mitigated by reasonable means, is the Supervisory Authority consulted prior to commencing the processing activity?
Security & breach notification
Are T&O measures (e.g., pseudonymisation, encryption) implemented to ensure security appropriate to the risk, including integrity, availability, and the ability to restore data access in a timely manner?
If a breach occurs, is the Controller prepared to notify the Supervisory Authority within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to natural persons?
Does the Processor notify the Controller of a personal data breach without undue delay after becoming aware of it?
Is the data subject communicated the breach without undue delay when it is likely to result in a high risk to their rights and freedoms?
Is every personal data breach, including the facts, effects, and remedial action, thoroughly documented to enable verification by the Supervisory Authority?
International transfers
Are mechanisms in place to ensure that the level of protection guaranteed by this Regulation is not undermined when transferring personal data outside the Union?
When transferring data to a third country, has the Commission decided that the third country ensures an adequate level of protection, thus requiring no further specific authorisation?
In the absence of an adequacy decision, are transfers protected by appropriate safeguards (e.g., Standard Contractual Clauses or Binding Corporate Rules), ensuring enforceable data subject rights and effective legal remedies?
Is the assessment of suitable safeguards for international transfers documented in the Controller's Records of Processing Activities (ROPA)?

See your result

Enter your email to get your score and a copy of this checklist — we'll only use it to send your result and occasional relevant resources.

No spam. Unsubscribe anytime.

This toolkit is provided for informational and educational purposes only and does not constitute legal advice. It is designed to help you identify potential compliance gaps and organise your approach to data protection requirements. Using this tool does not guarantee compliance with GDPR. Each organisation's compliance needs are unique and depend on your specific circumstances, jurisdiction, data processing activities, and risk profile. We strongly recommend: engaging qualified legal counsel for compliance advice, conducting a formal compliance audit by qualified professionals, tailoring these templates to your specific context, and regularly reviewing and updating your compliance program. Acuity Data and its affiliates accept no liability for any compliance gaps, regulatory penalties, or damages arising from use of this toolkit.