GDPR Compliance Checklist
A practical checklist for small teams handling personal data.
Checklist steps
- Map the data you hold
What, where, why, who can access and how long.
- Record the lawful basis
One per processing activity, documented.
- Publish a clear privacy notice
Plain language, easy to find, kept current.
- Fix consent mechanisms
Opt-in, granular, withdrawable and logged.
- Set up a rights request process
Identify, verify and respond within one month.
- Review processor contracts
Written terms with every supplier that touches data.
- Prepare breach reporting
72-hour process with a named owner and template.
- Train the team annually
Record attendance and refresh policies.
Frequently asked questions
How long does this take?
Around 555 minutes end to end once the team knows the steps. Times per step are listed above.
Can I edit this checklist?
Yes. Save it to LemPlates and you can add, remove or reorder steps, assign owners and set due dates.
How often should this be run?
Run it every time the process happens and review the steps at least every six months.