This checklist organises a review. It does not certify compliance, and not every item has the same answer for every organisation.
For each item, record an owner, evidence link, last test, open issue, and next review trigger. The EDPB’s SME data-protection guide provides official background for many of these controls.
Scope and governance
- Record which entities, establishments, products, and jurisdictions are in scope.
- Apply the Article 3 territorial test to non-EU activity.
- Identify controller, joint-controller, and processor roles per activity.
- Assign a data-protection owner with access to product and leadership decisions.
- Decide whether Article 27 requires an EU representative.
- Apply the Article 37 DPO test and record the conclusion.
- Maintain policies proportionate to the nature and risk of processing.
Data inventory and purpose
- Map collection points, fields, sources, recipients, locations, and deletion paths.
- Define each purpose specifically.
- Choose and record an Article 6 basis before processing.
- Record an Article 9 condition and national-law support for special categories.
- Review purpose compatibility before any later reuse.
- Remove fields and copies that are not necessary.
- Maintain an Article 30 record where required, including the narrow conditions around the under-250 exception.
Transparency and choice
- Provide Article 13 information at direct collection points.
- Provide Article 14 information where data comes from elsewhere, subject to its conditions.
- Keep notices consistent with live forms, code, vendors, and retention.
- Separate optional purposes such as marketing.
- Record valid consent and make withdrawal as easy as giving it.
- Provide a usable objection route for legitimate-interest processing and direct marketing.
- Inspect cookies and other terminal storage under applicable ePrivacy rules.
Processors and transfers
- Keep a current vendor and subprocessor register.
- Confirm roles and execute Article 28 terms where needed.
- Review technical and organisational measures.
- Document data locations and onward transfers.
- Identify the Chapter V mechanism for each restricted transfer.
- Complete transfer assessments and supplementary measures where required.
- Test vendor exit, export, and deletion.
Rights and retention
- Publish a contact route for rights.
- Define proportionate identity verification.
- Test access, correction, deletion, restriction, portability, and objection.
- Record deadlines, extensions, refusals, and communications.
- Set a period or operational criterion for every data category.
- Apply retention to logs, tickets, devices, archives, and backups.
- Preserve records required by law without reusing them for unrelated purposes.
Security, risk, and incidents
- Apply access control, least privilege, authentication, logging, patching, and recovery measures appropriate to risk.
- Encrypt data where appropriate and manage keys separately.
- Review security before material releases and vendor changes.
- Apply the Article 35 DPIA test to likely high-risk processing.
- Consult the authority where Article 36 requires it.
- Maintain a breach register, including events not notified.
- Test the Article 33 assessment and 72-hour escalation path.
- Prepare Article 34 communication where high risk to people remains.
Product and organisational change
- Include privacy requirements in design and acceptance criteria.
- Review AI inputs, training uses, outputs, human oversight, and providers.
- Review children’s data, location, biometrics, health, employment, scoring, and systematic monitoring with specialist care.
- Train people who handle personal data and test understanding.
- Keep material approvals, version history, test results, and remediation evidence.
- Re-run this review after new purposes, fields, countries, vendors, or incidents.
How to close an item
Do not mark an item complete because a document exists. Close it when the documented statement matches an implemented control and there is evidence that the control works.
Example:
| Item | Weak evidence | Stronger evidence |
|---|---|---|
| Retention | Policy says 30 days | Configured job, test result, exception log, and owner |
| Access request | Procedure document | Completed test request across every data store |
| Processor control | Vendor privacy link | Signed Article 28 terms, security review, locations, subprocessors |
| Consent | Banner screenshot | Notice version, preference record, pre-consent network trace, withdrawal test |
GDPR.Direct can create editable documents and a hosted legal hub from supplied facts. Its public-page review covers only visible pages and a limited issue set. Use it alongside engineering, procurement, security, and qualified legal or data-protection review.
This checklist is educational information, not legal advice.