The General Data Protection Regulation (GDPR) applies to any organisation that processes the personal data of people in the EU and UK, wherever that organisation is based. For a business outside Europe, GDPR often arrives through a customer or a market you want to sell into. This GDPR compliance checklist covers the essentials in plain terms, so you can see where you stand and what to address. It is a practical starting point, not legal advice.

GDPR compliance checklist: the 10 essential steps from data inventory to DPO appointment

1. Know your data: run a data inventory and data mapping

You cannot protect or govern data you have not mapped. Document what personal data you collect, why, where it comes from, where it is stored, who has access, who you share it with (including third parties and processors), and how long you keep it. This record of processing activities (required under Article 30 for most organisations) underpins almost everything else in your GDPR compliance programme. Data mapping helps you understand your data flows and identify where personal data outside the EU travels.

2. Establish a lawful basis for processing

GDPR requires a lawful basis for each type of data processing activity. Options include consent, contract, legal obligation, vital interests, public task, and legitimate interests. Identify and document the basis for each processing activity in your records. Where you rely on consent, make sure it is freely given, specific, informed, and as easy to withdraw as to give. Where you rely on legitimate interests, conduct and document a balancing test.

3. Update your privacy policy and privacy notice

People have a right to know how their personal data is used. Provide a clear, accessible privacy policy that explains what personal data you collect, why, your lawful basis for processing, how long you retain it, who you share it with, and the data subject rights individuals can exercise. Plain language beats legalese. GDPR requires organisations to implement transparent privacy notices that reflect actual data processing activities.

Not sure where your GDPR gaps are?

Run the free 15-question self-assessment and get an instant readiness score across data protection, security, and governance.

Start the assessment →

4. Be ready to honour data subject rights

GDPR gives individuals fundamental data subject rights including access to their personal data, rectification of inaccuracies, erasure (the right to be forgotten), restriction of processing, data portability (the right to data portability), and objection. Put a process in place to recognise and respond to these requests within the required timeframe (generally one month). Make sure your systems can actually find, access their personal data, and act on a person's data.

5. Apply data protection by design and by default

Build privacy in: collect only the data you need (data minimisation), limit how long you retain it (data retention), secure it appropriately, and restrict access. Data protection by design and by default means privacy should be the default setting, not an afterthought. This is one of the core data protection principles under the GDPR.

6. Secure personal data

GDPR requires appropriate technical and organisational measures to protect personal data. This includes access controls, encryption where appropriate, and ongoing security management. Implement and document your information security controls. Good data privacy and security practice is a GDPR requirement. Where processing is likely to result in a high risk to the rights and freedoms of individuals, a Data Protection Impact Assessment (DPIA) is required.

7. Manage your processors and contracts

If vendors process personal data on your behalf, GDPR requires a data processing agreement with each processor, and you must use processors that provide sufficient guarantees. Map your processors, assess them against the GDPR standard, and put the contracts in place. Know where each processor is located, particularly for international data transfers.

8. Plan for data breaches

GDPR requires you to detect, document, and, where required, report personal data breaches to the relevant supervisory authority within 72 hours of becoming aware, and in some cases notify data subjects without undue delay. Report data breaches to the supervisory authority whenever the breach is likely to result in a risk to individuals. Notify the data subjects themselves when the risk is high. Having a breach response process ready before you need it is essential.

9. Handle international data transfers

If you transfer personal data outside the EU or UK, you need a valid transfer mechanism. Options include adequacy decisions (where the destination country provides an equivalent level of protection), Standard Contractual Clauses, and Binding Corporate Rules. Know where your data flows and ensure each transfer of personal data outside the EU is covered. A transfer impact assessment may be required for certain transfers.

10. Decide whether you need a Data Protection Officer (DPO)

Some organisations must appoint a Data Protection Officer depending on the nature and scale of their processing: public authorities, organisations that conduct large-scale systematic monitoring of individuals, or those that process special categories of personal data (such as health, biometric, or genetic data) or data relating to criminal convictions at scale. Assess whether you are required to appoint a DPO. If not, still assign clear responsibility for data protection. Controllers and processors both need someone accountable. Supervisory authorities and data subjects need a point of contact.

The bottom line

GDPR compliance comes down to knowing your personal data, establishing a lawful basis for processing, being transparent, honouring data subject rights, applying data protection by design (privacy by design) and by default, securing data, managing processor contracts, planning for data breaches, controlling data transfers outside the EU, and assigning responsibility for data protection. Work through this GDPR compliance checklist to see where you stand, and get specialist help where the gaps are material. This is a practical guide, not legal advice.

The regulation requires organisations to comply with the GDPR wherever they are based if they process the personal information of EU or UK residents. GDPR requires organisations to protect the data they hold through appropriate technical and organisational measures. EU data, including sensitive data such as health, biometric, or genetic data, receives the highest level of protection. Data collection must be limited to what is necessary, and organisations must be able to demonstrate that every step in this GDPR checklist has been addressed.

GDPR defines clear accountability obligations: individuals must have control over their personal data, and organisations must handle data responsibly. A comprehensive GDPR compliance checklist like this one can help organisations assess where they stand and simplify compliance by working through each area systematically. Dedicated GDPR compliance programmes work better when compliance workflows are documented and owned, so that customer data and all personal data you hold is governed consistently. When a person exercises their rights and asks you to delete or restrict how their data is processed, your systems must be able to respond in time. Data subjects and supervisory authorities both expect prompt, documented responses.

How Onyx helps

Onyx's data protection services support organisations working through GDPR requirements as a practical programme rather than a compliance exercise. We map your data flows, identify the gaps against the regulation, and work with you to close them: lawful basis documentation, privacy notices, data subject rights processes, DPIA reviews, processor contract frameworks, and breach response planning. We provide practical guidance, not legal advice, and we scope the work to your environment.

Where ongoing data protection oversight is needed, our DPO as a Service gives you an independent expert on a contracted basis, so there is always a clear owner for GDPR accountability. For a broader view of your security posture alongside data protection, our data protection assessment benchmarks you against the controls that matter.

See also: outsourced DPO: what it is and who needs it, GDPR compliance service.

Facing a GDPR deadline or audit?

We scope a practical path to compliance on a short call. No obligation.

Book a scope call →

FAQ

Who does GDPR apply to?

GDPR applies to any organisation that processes the personal data of individuals in the EU and UK, regardless of where the organisation is based. For businesses outside Europe, it commonly applies because they offer goods or services to, or monitor, people in those regions. Data controllers and data processors both have obligations under the regulation.

What are the key steps to GDPR compliance?

Run a data inventory and data mapping exercise, establish a lawful basis for each processing activity, publish a clear privacy policy, honour data subject rights, apply data protection by design and by default, secure personal data, manage processor contracts with data processing agreements, plan for data breaches, control international data transfers, and assign responsibility for data protection.

Do I need a Data Protection Officer for GDPR?

Some organisations are required to appoint a Data Protection Officer depending on the nature and scale of their processing, for example large-scale or systematic monitoring of individuals, or processing of special categories of personal data such as health or genetic data. Assess whether you meet the criteria. If not, still assign clear accountability for data protection.

What are data subject rights under GDPR?

Individuals have rights including access to their personal data, rectification of inaccuracies, erasure (right to be forgotten), restriction of processing, the right to data portability, and objection to certain processing. You need a process to recognise and respond to these requests within the required timeframe, and systems that can locate and act on a person's data.

What is the GDPR breach notification requirement?

You must detect, document, and report personal data breaches to the relevant supervisory authority within 72 hours of becoming aware, where the breach is likely to result in a risk to the rights and freedoms of individuals. In some cases you must also notify affected data subjects without undue delay. Having a breach response process ready in advance is essential.