Auto-saved in your browser Β· β members can white-label & sync across devices
About the GDPR Compliance Checklist template
A GDPR Compliance Checklist is a structured control list that maps your organisation's data-handling activities against the requirements of the EU General Data Protection Regulation. It helps you verify lawful bases for processing, data subject rights procedures, and breach-response readiness before a regulator or auditor asks. Working through it systematically reduces the risk of fines and evidences accountability under Article 5(2).
It's part of My QMS, MyPMP's Quality Management System: fill it in online, personalize it with your name and logo, then export a clean, branded PDF. Your work auto-saves in your browser.
When to use a GDPR Compliance Checklist
- βΈPreparing for a Data Protection Impact Assessment (DPIA) on a new system or product
- βΈOnboarding a processor or reviewing existing vendor contracts for Article 28 clauses
- βΈRunning a periodic internal privacy audit or preparing for a supervisory authority review
- βΈLaunching a project that collects personal or special-category data from EU residents
What a good GDPR Compliance Checklist includes
- βLawful basis and consent records for each processing activity
- βRecord of Processing Activities (RoPA) and data mapping status
- βData subject rights procedures (access, erasure, portability, objection)
- βTechnical and organisational security measures, including encryption and access controls
- βBreach detection, 72-hour notification and documentation process
- βThird-party processor agreements and international transfer safeguards (SCCs)
What's inside this template
The interactive form above gives you:
Tips & common mistakes
- π‘Assign an owner and target date to every unchecked item rather than treating it as a one-off tick-box exercise
- π‘Don't rely on consent as your default lawful basis; contract or legitimate interest is often more appropriate and less fragile
- π‘Keep evidence links against each item, since demonstrating compliance matters as much as achieving it
How it works
- 1. Fill it in β type directly into the fields, tables and sections above.
- 2. Brand it β add your organization name and logo with the Branding button.
- 3. Export β print to PDF, or become a member to white-label and sync across devices.
FAQ
Who is responsible for completing a GDPR compliance checklist?οΌ
Typically the Data Protection Officer or a designated privacy lead owns the checklist, but input is needed from IT, legal, HR and process owners who handle personal data day to day.
How often should we review our GDPR checklist?οΌ
Review it at least annually and whenever you introduce a new processing activity, system, vendor or significant business change; DPIAs may trigger interim reviews.
Does completing the checklist make us fully GDPR compliant?οΌ
No single checklist guarantees compliance; it provides structured evidence and highlights gaps, but ongoing governance, staff training and documented decisions are still required.
Membership unlocks white-label export (remove the MyPMP footer), cloud sync across devices, plus all apps & ScheduleX.
See membership