GDPR compliance rests on being able to show what personal data you hold, why you are allowed to hold it, and how you honour people's rights over it. The regulation applies to any organisation processing the personal data of people in the EU or UK, regardless of where the organisation itself is based.
1. Know your data
- Maintain a Record of Processing Activities (ROPA) - required under Article 30 and the first thing a regulator asks for.
- Map what personal data you collect, why, where it is stored, who can access it, and who you share it with.
- Identify any special category data (health, biometrics, beliefs) - it carries stricter conditions.
- Define and enforce retention periods. Keeping data indefinitely is a breach of the storage limitation principle.
2. Establish a lawful basis
- Assign one of the six lawful bases to every processing activity: consent, contract, legal obligation, vital interests, public task, or legitimate interests.
- Where you rely on consent, ensure it is freely given, specific, informed, unambiguous - and as easy to withdraw as to give.
- Where you rely on legitimate interests, document a Legitimate Interests Assessment.
3. Be transparent
- Publish a privacy notice in clear language covering identity, purposes, lawful basis, recipients, retention, rights and complaint routes.
- Provide the notice at the point of collection, not buried three clicks away.
4. Honour data subject rights
You must be able to action all eight rights, generally within one month:
- Access, rectification and erasure
- Restriction of processing and data portability
- Objection, and rights relating to automated decision-making and profiling
- The right to be informed
Have a documented, rehearsed process. Ad-hoc handling is where organisations miss the deadline.
Turn the checklist into a tracked programme
GRC Copilot maps your privacy controls, stores the evidence behind each obligation, and shows where your GDPR programme has gaps before a regulator or customer finds them.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
5. Security, breaches and accountability
- Apply appropriate technical and organisational measures - encryption, access control, logging, testing.
- Maintain a breach response process capable of notifying the supervisory authority within 72 hours of becoming aware of a notifiable breach.
- Keep an internal breach register, including incidents you decided not to report and why.
- Run a Data Protection Impact Assessment (DPIA) for high-risk processing such as large-scale profiling, systematic monitoring or special category data at scale.
- Appoint a Data Protection Officer where required, and document the reasoning if you conclude one is not.
6. Third parties and transfers
- Put Article 28 processor contracts in place with every vendor processing personal data on your behalf.
- Conduct due diligence on processors and keep the evidence.
- For transfers outside the EU or UK, apply an appropriate safeguard - adequacy decision, Standard Contractual Clauses, or binding corporate rules - and complete a transfer risk assessment.
Frequently asked questions
Does GDPR apply to organisations outside Europe?
Yes. It applies extraterritorially where you offer goods or services to people in the EU or UK, or monitor their behaviour, regardless of where your company is established.
How long do we have to respond to a data subject access request?
One month from receipt, extendable by two further months for complex or numerous requests - provided you inform the individual within the first month.
When is a DPIA mandatory?
When processing is likely to result in a high risk to individuals, including large-scale systematic monitoring, large-scale special category processing, or automated decisions with legal or similarly significant effects.
Do we have to report every breach?
No. Report to the supervisory authority within 72 hours only where the breach is likely to result in a risk to individuals' rights and freedoms, and to the individuals themselves where the risk is high. Document your decision either way.
Key takeaways
- Your ROPA is the foundation - regulators ask for it first.
- Every processing activity needs a documented lawful basis.
- Rights requests carry a one-month clock; breach notification carries 72 hours.
- Processor contracts and transfer safeguards are commonly missed.