GDPR compliance checklist: the complete guide to successful compliance

A GDPR compliance checklist helps ensure your organization meets the key requirements of the General Data Protection Regulation. It covers ten pillars: an up-to-date record of processing activities, clearly defined governance, identified legal bases for each process, compliant privacy notices, documented management of data subject rights, compliant processor contracts, an appropriate security policy, data breach management procedures, controlled retention periods, and documentation ready for a CNIL audit. It is used in five steps—inventory, assess, prioritize, remediate, and monitor—and should be reviewed at least once a year, as well as with any significant change: new processing, new tools, organizational shifts, or security incidents.

By
Rémy Bozonnet
1
Min
Share this article
Checklist

A GDPR compliance checklist helps verify that your organization meets the main requirements of the General Data Protection Regulation (GDPR). It serves as an essential management tool for DPOs, legal counsel, CISOs, and compliance officers.

An effective compliance approach relies on:

  • an up-to-date record of processing activities
  • clearly defined governance
  • identified legal bases for each process
  • compliant privacy notices
  • documented management of data subject rights
  • compliant processor contracts
  • an appropriate security policy
  • data breach management procedures
  • controlled retention periods
  • documentation ready for a CNIL audit

This checklist is an excellent starting point, but it must be updated regularly to keep pace with changes in processing activities, tools, and regulatory requirements.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Why use a GDPR compliance checklist?

Since the GDPR came into effect, compliance is no longer about performing a one-off audit and filing it away. It is now part of a process of continuous improvement.

Organizations are constantly creating new processes, deploying new software, working with new subcontractors, and collecting more personal data. Without a tracking method, it becomes difficult to maintain a clear view of your compliance status.

This is precisely the role of a GDPR checklist. It allows you to verify, in a structured way, that every regulatory requirement is properly covered and documented.

In practical terms, a checklist can be used to:

  • prepare for an internal audit
  • anticipate a regulatory inspection
  • support a new DPO onboarding
  • standardize practices across multiple subsidiaries
  • track an annual action plan
  • prepare for certification or a quality initiative

Take an example. An international company has a dozen subsidiaries, each using its own HR tools, CRM, and marketing solutions. Without a common repository, it becomes complex to know if each entity is keeping its register up to date, respecting retention periods, or properly documenting requests to exercise rights.

A shared checklist makes it possible to standardize controls and quickly detect discrepancies.

As an organization grows, however, maintaining this documentation in a simple file becomes increasingly complex. This is why many companies choose to rely on GDPR compliance software, capable of centralizing processing activities, proof of compliance, and action plans within a single repository.

The 30 essential points for a GDPR compliance checklist

Compliance does not rely on a single document, but on a set of elements that demonstrate that the organization is concretely applying the principles of the GDPR. Here are the main points to check.

Is GDPR governance clearly defined?

Clear governance is the foundation of any compliance initiative. Even before examining data processing activities, it is essential to verify that responsibilities are well defined.

Does your organization have:

  • a DPO when required?
  • clearly defined governance?
  • an internal data protection policy?
  • an annual compliance plan?
  • regular employee awareness initiatives?

Effective governance ensures that compliance does not rely on a single person. Every department must understand its role: HR, marketing, IT, procurement, legal, or executive management.

Is the record of processing activities up to date?

The record is often the first document reviewed during an audit. It must accurately reflect the reality of the processing activities carried out within the company.

Specifically, verify that:

  • all processing activities are listed
  • each purpose is clearly described
  • data categories are specified
  • recipients are identified
  • retention periods are defined
  • security measures are documented
  • processors are mentioned where necessary

An outdated record quickly gives the impression that compliance is not being managed effectively.

Are the legal bases correctly documented?

Every processing activity must be based on a clearly identified legal ground. Your checklist should allow you to verify that this basis is justified and documented.

The primary legal bases are:

  • consent
  • performance of a contract
  • legal obligation
  • protection of vital interests
  • public interest task
  • legitimate interest

For example, processing job applications is generally based on pre-contractual measures, while certain marketing activities may require the consent of the individuals concerned.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Are individuals properly informed?

Transparency is one of the fundamental principles of the GDPR. Individuals must understand:

  • what data is collected
  • why it is collected
  • how long it is kept
  • who it is shared with
  • what are their rights

Your checklist should specifically verify:

  • information notices
  • the privacy policy
  • data collection forms
  • cookie banners
  • clauses included in contracts

Incomplete information is often one of the first discrepancies identified during audits.

Are data subject rights being managed correctly?

Every organization must be able to handle requests from data subjects efficiently. Your procedure must cover:

  • the right of access
  • the right to rectification
  • the right to erasure
  • the right to restriction of processing
  • the right to object
  • the right to data portability

Your checklist could include the following questions:

  • Is there a documented procedure in place?
  • Do employees know how to direct these requests?
  • Are deadlines being tracked?
  • Are responses being archived?
  • Is there a history of requests kept?

Let's look at an example. A former employee requests all the data held about them. Without a clear procedure, searching for this information can tie up several departments for days. Conversely, an organization with a documented process will be able to quickly identify the relevant processing activities, centralize the information, and respond within the required timeframes.

Are your processors properly managed?

Today, few companies process all their personal data on their own. Cloud hosting, CRM, HRIS, marketing solutions, collaborative tools: every service provider that handles personal data must be identified and managed.

Your checklist should allow you to verify the following points:

  • Are all processors accounted for?
  • Is a Data Processing Agreement (DPA) signed with each of them?
  • Are the responsibilities of each party clearly defined?
  • Are security measures documented?
  • Are any data transfers outside the European Union identified and regulated?
  • Are processors subject to regular reviews?

Take an example: a company uses a marketing automation tool hosted outside the European Union. If this transfer is not documented and governed by the appropriate mechanisms, the organization faces significant legal risk.

Compliance is therefore not just about choosing reliable service providers, but also about demonstrating that their use is properly documented.

Are the security measures appropriate?

The GDPR does not impose a fixed list of technical measures. Instead, it requires organizations to implement measures that are appropriate to the risks posed to personal data.

Your GDPR audit must specifically verify:

  • access management policies
  • multi-factor authentication where relevant
  • encryption of sensitive data
  • backups
  • restoration procedures
  • access logging
  • workstation management
  • cloud environment security
  • employee offboarding procedures

Security is not just the responsibility of the IT department. The DPO, legal teams, CISOs, and business units must work together to ensure that processing activities are designed according to the principles of privacy by design and privacy by default.

Are data breaches being handled correctly?

No organization is completely immune to human error, cyberattacks, or technical incidents. The difference lies in the ability to react quickly.

Your checklist should include verifying:

  • the existence of an incident management procedure
  • the identification of people to be alerted
  • the documentation of breaches
  • the criteria for assessing the level of risk
  • the procedures for notifying competent authorities when necessary
  • the procedures for informing the individuals concerned when the risk is high
  • the post-incident review process

A documented procedure helps avoid improvisation in the most critical situations.

Are retention periods under control?

Keeping data "just in case" is still a very common practice. However, one of the fundamental principles of the GDPR is to only keep data for as long as is necessary for the intended purpose.

Your checklist should verify:

  • that each processing activity has a defined retention period
  • that the retention periods are consistent with legal obligations
  • that data is archived when necessary
  • that deletions are actually carried out
  • that employees are aware of the applicable rules

For example, resumes received during recruitment should not be kept indefinitely if there is no legal basis to justify it.

Are Data Protection Impact Assessments (DPIAs) carried out when necessary?

Certain types of processing present a high risk to the rights and freedoms of individuals. In these situations, a Data Protection Impact Assessment (DPIA) must be conducted.

Your checklist can include the following questions:

  • have high-risk processing activities been identified?
  • is a methodology defined?
  • are the DPIAs documented?
  • are risk mitigation measures being monitored?
  • are the DPIAs updated when processing activities evolve?

In large organizations, having a single repository significantly facilitates the tracking of these assessments. A specialized platform makes it possible to centralize all GDPR documentation, link each DPIA to the relevant processing activity, and track associated action plans over time.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

GDPR documents to provide during a CNIL audit

During an audit, the CNIL may request to review various items demonstrating your organization's compliance. The goal is not just to have these documents, but to be able to produce them quickly and in their most recent version.

Here are the main documents to prepare.

Document Why does it matter?
Record of processing activitiesFull view of the processing carried out
Data protection policyFormalises internal governance
Breach registerEvidences incident follow-up
Data processing agreements (DPA)Frame relationships with vendors
Data protection impact assessments (DPIA)Justify high-risk processing
Data subject rights procedureSets out how individuals' requests are handled
Retention policyDefines the applicable retention periods
Privacy notice templatesEnsure transparency
Access rights management policyEvidences organisational measures
Awareness training recordsEvidence the actions taken with employees
Record of processing activities
Why does it matter? Full view of the processing carried out
Data protection policy
Why does it matter? Formalises internal governance
Breach register
Why does it matter? Evidences incident follow-up
Data processing agreements (DPA)
Why does it matter? Frame relationships with vendors
Data protection impact assessments (DPIA)
Why does it matter? Justify high-risk processing
Data subject rights procedure
Why does it matter? Sets out how individuals' requests are handled
Retention policy
Why does it matter? Defines the applicable retention periods
Privacy notice templates
Why does it matter? Ensure transparency
Access rights management policy
Why does it matter? Evidences organisational measures
Awareness training records
Why does it matter? Evidence the actions taken with employees

This documentation serves as the company's essential GDPR compliance kit. The more centralized and up-to-date it is, the easier audits are to prepare for.

How to conduct a GDPR audit using a checklist?

A checklist is particularly effective when integrated into a workflow. A five-step approach generally yields good results.

1. Inventory : list all processing activities, applications, and subcontractors.

2. Assess : compare each processing activity against GDPR requirements to identify gaps.

3. Prioritize : not all gaps have the same level of criticality. The most significant risks must be addressed as a priority.

4. Remediate : implement the necessary actions:

  • updating registers
  • drafting procedures
  • conducting DPIAs
  • updating contracts
  • strengthening security measures

5. Monitor : compliance is never static. Actions must be tracked over time, assigned to a person in charge, and regularly reassessed.

This is precisely the stage where Excel files quickly reach their limits.

The most common GDPR compliance errors

Throughout our audits, several gaps appear repeatedly. Here are the most frequent ones:

  • ❌ a record of processing activities that has not been updated for several years
  • ❌ missing or inconsistent retention periods
  • ❌ incomplete data processing agreements
  • ❌ no procedure in place for managing data subject rights
  • ❌ untracked requests for the exercise of rights
  • ❌ overlooked impact assessments
  • ❌ a privacy policy that no longer reflects actual processing activities
  • ❌ compliance relying exclusively on the DPO

In most cases, these gaps are not due to a lack of intent, but a lack of oversight.

Why an Excel-based GDPR checklist quickly reaches its limits

For a small organization, an Excel checklist may be enough to get started. But as processing activities multiply, multiple departments get involved, or the organization grows to include several subsidiaries, difficulties quickly arise.

The main limitations are well known:

  • multiple versions circulating simultaneously
  • it becomes difficult to identify the master version
  • no audit trail is available
  • responsibilities are not clearly defined
  • action plans are rarely followed up on
  • there are no links between processing activities, risks, subcontractors, and DPIAs
  • evidence is scattered across various folders

Conversely, a dedicated platform allows you to centralize all compliance elements, track actions over time, document changes to processing activities, and prepare for an audit or inspection with greater peace of mind.

This approach provides a much more operational view of compliance and facilitates collaboration between legal, business, security, and IT teams. It also serves as a solid foundation for organizations looking to structure their compliance around a comprehensive approach that integrates, where relevant, the requirements for managing the AI Act.

Your GDPR compliance checklist: 30 key checks

Use this checklist as a basis for your internal audits or your annual compliance review.

No. Area Check
1GovernanceDPO appointed where required
2GovernanceRoles and responsibilities defined
3GovernanceGDPR policy in place
4GovernanceEmployee awareness training delivered
5RecordsRecord of processing activities up to date
6RecordsPurposes documented
7RecordsData categories identified
8RecordsRecipients listed
9RecordsSecurity measures documented
10Lawful basisEvery processing activity rests on an identified lawful basis
11TransparencyPrivacy notices compliant
12TransparencyPrivacy policy up to date
13TransparencyCookie banner compliant
14Data subject rightsRights request procedure documented
15Data subject rightsResponse deadlines tracked
16ProcessorsData processing agreements (DPA) signed
17ProcessorsVendors listed
18ProcessorsInternational transfers identified
19SecurityAccess rights management
20SecurityBackups tested
21SecurityStrong authentication where relevant
22SecurityAccess logging
23BreachesIncident management procedure
24BreachesBreach register kept up to date
25RetentionRetention periods defined
26RetentionData deletion scheduled
27DPIAHigh-risk processing identified
28DPIAImpact assessments carried out where required
29OversightAction plan tracked
30DocumentationDocuments readily available in the event of an inspection
Governance
Check 1DPO appointed where required
Check 2Roles and responsibilities defined
Check 3GDPR policy in place
Check 4Employee awareness training delivered
Records
Check 5Record of processing activities up to date
Check 6Purposes documented
Check 7Data categories identified
Check 8Recipients listed
Check 9Security measures documented
Lawful basis
Check 10Every processing activity rests on an identified lawful basis
Transparency
Check 11Privacy notices compliant
Check 12Privacy policy up to date
Check 13Cookie banner compliant
Data subject rights
Check 14Rights request procedure documented
Check 15Response deadlines tracked
Processors
Check 16Data processing agreements (DPA) signed
Check 17Vendors listed
Check 18International transfers identified
Security
Check 19Access rights management
Check 20Backups tested
Check 21Strong authentication where relevant
Check 22Access logging
Breaches
Check 23Incident management procedure
Check 24Breach register kept up to date
Retention
Check 25Retention periods defined
Check 26Data deletion scheduled
DPIA
Check 27High-risk processing identified
Check 28Impact assessments carried out where required
Oversight
Check 29Action plan tracked
Documentation
Check 30Documents readily available in the event of an inspection

This checklist can serve as a foundation for an annual review, an internal audit, or preparation for a data protection authority inspection.

Conclusion: from checklist to continuous compliance management

Implementing a GDPR compliance checklist is one of the best ways to structure your personal data protection strategy. It allows you to methodically verify that the main pillars of compliance are covered: governance, records of processing activities, legal bases, informing individuals, security, vendor management, impact assessments, and documentation.

However, a checklist should not be viewed as a simple to-do list to be completed once a year. Compliance is a living process that evolves in line with new processing activities, business projects, regulatory changes, and organizational shifts. Its value depends primarily on how well it is updated and its ability to reflect the reality of the processing activities carried out within the organization.

As a company grows, maintaining this documentation in scattered files quickly becomes complex. Centralizing processing activities, evidence of compliance, action plans, and impact assessments within a single platform not only saves time but also provides a clear view of your compliance level at any given moment, transforming compliance into a continuous process rather than a one-off exercise.

It is with this in mind that specialized solutions like Adequacy support DPOs, legal departments, CISOs, and compliance officers in the daily management of their GDPR obligations, while preparing organizations for new regulatory requirements such as the AI Act.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

FAQ - GDPR compliance checklist

What is a GDPR compliance checklist?

A GDPR compliance checklist is a tool used to verify, point by point, that an organization meets the main obligations of the General Data Protection Regulation. It generally covers governance, records of processing activities, legal bases, data subject rights, security, subcontractors, and documentation.

Is there an official GDPR checklist?

There is no single official checklist that applies to every organization. However, the CNIL provides numerous practical guides and frameworks to help you build a compliance approach tailored to your specific context.

What documents can the CNIL request during an audit?

Depending on the organization being audited, the CNIL may request items such as the record of processing activities, data processing agreements, impact assessments, internal procedures, privacy policies, evidence of data breach management, or documentation regarding the exercise of data subject rights.

What are the mandatory GDPR documents?

The required documents depend on the processing activities carried out by the organization. Common examples include the record of processing activities, data processing agreements, privacy notices, internal procedures, impact assessments where necessary, and documentation of security measures.

How do you prepare for a GDPR audit?

A GDPR audit involves comparing an organization's practices against the regulation's requirements. A checklist helps identify gaps, prioritize corrective actions, and track their implementation over time.

How often should you update your GDPR checklist?

It is recommended to review your checklist at least once a year, as well as whenever there is a significant change, such as a new processing activity, a new tool, organizational restructuring, regulatory updates, or a security incident.

Should an SME use the same checklist as a large corporation?

The principles of the GDPR apply to all relevant organizations, but the level of formalization varies based on size, the nature of processing activities, and the associated risks. An SME will generally not have the same volume of documentation as an international group, even though both must adhere to the same fundamental principles.

Can you manage GDPR compliance using Excel?

For a small organization, an Excel spreadsheet can be a good starting point. However, as the number of processing activities, users, or subsidiaries grows, it becomes difficult to track actions, maintain an audit trail of changes, and centralize evidence of compliance.

How can you automate your GDPR compliance tracking?

Specialized platforms allow you to centralize processing activities, records, impact assessments, action plans, and related documentation. They also facilitate team collaboration and provide a comprehensive overview of your organization's compliance status.

Why should you link GDPR compliance with the AI Act?

Many organizations are now deploying artificial intelligence systems that process personal data. Structuring your governance now around a platform capable of supporting both GDPR and AI Act requirements helps avoid tool sprawl and fosters a consistent approach to compliance.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

The latest news

They have trusted us for years

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.