All Guides
Compliance Guide

GDPR Compliance: A Practical Checklist

The core building blocks of a defensible GDPR program, for organizations processing data on EU residents.

EaglesGuard Advisory Team3 min readLast updated

The short version

  • Map your data before documenting anything. Article 30 records and data subject requests both depend on knowing what you hold.
  • Every processing activity needs a lawful basis identified in advance, and consent is usually the weakest option available.
  • Breach notification to a supervisory authority runs to 72 hours from awareness, which is a process problem rather than a legal one.
  • GDPR reaches organizations outside the EU that offer goods or services into it or monitor behavior within it.

Who does GDPR actually apply to?

GDPR applies to organizations established in the EU, and to organizations outside it that offer goods or services to people in the EU or monitor their behavior. Being headquartered elsewhere does not remove the obligation. The common misreading is that a company without an EU office or EU customers on paper is out of scope, when in practice web analytics, targeted advertising, and self-serve signups from EU users can all bring an organization within reach.

Map before you document

You can't produce an accurate Article 30 Record of Processing Activities, or respond to a data subject access request within the required timeframe, without first knowing what personal data you hold, where it lives, and why you're processing it. Data mapping is unglamorous and it is the dependency for nearly everything else in the checklist below.

What are the core requirements to have in place?

  • Lawful basis identified for every processing activity
  • Records of Processing Activities (Article 30)
  • Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Data subject rights process covering access, erasure, and portability requests
  • Breach notification procedure meeting the 72-hour authority notification requirement
  • Data processing agreements with vendors acting as processors
  • Transfer mechanism documented for personal data leaving the EU
  • Privacy notices that match what the data map actually shows

Which lawful basis should I use?

There are six lawful bases, and consent is the one organizations reach for first and should usually reach for last. Consent must be freely given, specific, informed, and as easy to withdraw as to give, and withdrawal obliges you to stop. For most ordinary business processing, contract necessity or legitimate interests are both more robust and less operationally fragile. Legitimate interests requires a documented balancing test weighing your interest against the individual's rights, which is the step most often skipped and most often asked for.

How long do I have to report a data breach?

A personal data breach must be reported to the relevant supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Where the risk to individuals is high, they must also be informed without undue delay. The 72-hour clock makes this a process problem rather than a legal one: the organizations that miss it usually do so because nobody was clear on who declares a breach, who assesses risk, and who files, not because they disputed the obligation.

Common gaps in otherwise mature programs

  • No documented lawful basis for legacy processing activities
  • DPIAs treated as a one-time exercise instead of tied to new projects
  • Vendor contracts missing required processor obligations
  • Privacy notices that describe an older, simpler version of the business
  • Retention schedules written down but never enforced in the systems holding the data

Need hands-on help with this?

See how our GDPR Compliance engagement works.

See GDPR Compliance

Ready to put this into practice?

Reading the guide is the easy part. If you want practitioners who have run these implementations to scope the work with you, start with a free consultation.

16
Services to draw from
11
Frameworks covered
Free
Scoping consultation