GDPR Compliance Checklist (Free PDF Download)

A practical 26-page self-assessment that maps every operational, technical, and governance practice the EU and UK GDPR expect. Built from the workflows we use with 800+ organisations across Europe. Download the GDPR compliance checklist PDF below and turn your compliance work into something you can prove.

TRUSTED BY

What is a GDPR Compliance Checklist?

A GDPR compliance checklist is a structured self-assessment that turns every requirement of the EU and UK General Data Protection Regulation into a yes/no question you can evidence. It covers governance, data inventory, lawful basis, transparency, data subject rights, security, breach response, vendor management, international transfers, retention, and training.

The accountability principle in Article 5(2) makes this kind of document core to compliance. Controllers must demonstrate compliance, not simply claim it. A working privacy compliance checklist gives you the artefacts to do that. It surfaces gaps before a regulator, customer, or auditor surfaces them for you.

Many privacy teams run it as both a working document and a GDPR audit checklist for internal review and external assurance. The same structure also functions as a data protection audit checklist when preparing for regulator inspections or customer due diligence.

For a clause-by-clause walkthrough that sits underneath the checklist itself, read our GDPR compliance checklist guide. If you are still mapping the scope of what GDPR applies to, start with our what is GDPR compliance primer.

What is included in the PDF?

The GDPR compliance checklist PDF covers 20 control areas across 26 pages. Each section ends with a sign-off slot for the responsible owner, so you can route reviews across DPO, security, HR, engineering, and procurement teams. Two appendices give you the templates you will need to act on it.

The GDPR compliance checklist PDF covers 20 control areas across 26 pages. Each section ends with a sign-off slot for the responsible owner, so you can route reviews across DPO, security, HR, engineering, and procurement teams. Two appendices give you the templates you will need to act on it.

Governance and accountability

DPO appointment, privacy KPIs, risk register, internal policies, board-level oversight, and documentation readiness.

Section A

Data inventory and RoPA

Article 30 records of processing, data flow mapping, processor and sub-processor visibility, review cadence.

Section B

Data subject rights

Channel definition, identity verification, response templates, fulfilment workflows, exemption handling, metrics.

Section E

Privacy by design GDPR checklist

Project lifecycle privacy checkpoints, procurement review, role-based access, anonymisation, change management.

Section I

Security of processing

Technical and organisational controls covering RBAC, MFA, encryption, patch management, BCP, secure SDLC, pen testing.

Section K

Vendors, transfers, retention

DPAs, sub-processor controls, transfer risk assessments, retention schedules, and deletion and disposal practices.

Sections M, N, O

How to use the PDF?

Once you have the GDPR compliance checklist PDF, here is the workflow we recommend. It mirrors what we run with audit clients on engagements.

  1. Assign owners per section. Each of the 20 sections has a named reviewer slot. Map them to your DPO, security lead, HR, engineering, and procurement owners before you start working through it.
  2. Work through it as a GDPR audit checklist. Tick what is implemented and evidenced. Leave anything unproven unticked, even if it feels obvious. The checklist is only useful if the ticks are honest.
  3. Log gaps in the Action Register. Every unticked item moves into Appendix 1 with a risk rating (High, Medium, Low), an owner, and a due date. Clear the High items first.
  4. Build your evidence pack. Use the 12-folder structure in Appendix 2 as your single source of truth. Map every Action Register entry to the folder that holds its proof, so any reviewer can find it in one place.
  5. Consult the privacy by design GDPR checklist (Section I) before any new initiative. Before kicking off a new product, market, or vendor, walk Section I as a pre-flight check.
  6. Re-review on a cadence. Treat it as a privacy compliance checklist you revisit each quarter, and after any material change (new product, new market, new vendor, new regulation).
The data collected on this form are intended for DPO Consulting. They are used to process your request. They are also used for sending you our newsletter if you have consented to it by checking the box below. Mandatory data are indicated on the form by an asterisk. In accordance with the EU Regulation 2016/679 of 27 April 2016 on the protection of personal data and the amended Law "Informatique et Libertés" of 6 January 1978, you have the right to the access, rectification, deletion, portability as well as limitation and opposition to the processing of your personal data. You can exercise that right by sending an email to the following address: dpo@dpo-consulting.com.

For more information about the processing of your personal data by DPO Consulting, you can consult the Data Protection Policy.
Oops! Something went wrong while submitting the form.