GDPR Compliance Checklist

A practical checklist for small teams handling personal data.

Checklist steps

  1. Map the data you hold

    What, where, why, who can access and how long.

  2. Record the lawful basis

    One per processing activity, documented.

  3. Publish a clear privacy notice

    Plain language, easy to find, kept current.

  4. Fix consent mechanisms

    Opt-in, granular, withdrawable and logged.

  5. Set up a rights request process

    Identify, verify and respond within one month.

  6. Review processor contracts

    Written terms with every supplier that touches data.

  7. Prepare breach reporting

    72-hour process with a named owner and template.

  8. Train the team annually

    Record attendance and refresh policies.

Frequently asked questions

How long does this take?

Around 555 minutes end to end once the team knows the steps. Times per step are listed above.

Can I edit this checklist?

Yes. Save it to LemPlates and you can add, remove or reorder steps, assign owners and set due dates.

How often should this be run?

Run it every time the process happens and review the steps at least every six months.