Checklist

GDPR compliance checklist

This checklist covers the operational GDPR obligations most SaaS companies need to demonstrate. It is not legal advice; confirm applicability with your adviser or DPO.

Reviewed by Compliancy compliance team

Know what you process

  • Maintain records of processing activities under Article 30.
  • Record the lawful basis for each processing activity.
  • Record retention periods and deletion behaviour per data category.
  • Identify international transfers and the mechanism relied on.

Respect individual rights

  • Provide a route for access, rectification, erasure, portability and objection requests.
  • Track requests with owners and deadlines; the default response window is one month.
  • Be able to show how a request was handled after the fact.

Manage processors

  • Keep an inventory of processors and sub-processors.
  • Hold data processing terms with each processor.
  • Review processors on a defined cycle rather than only at onboarding.

Secure and prove

  • Implement and document Article 32 technical and organisational measures.
  • Run DPIAs where processing is likely to be high risk.
  • Be able to detect, assess and report a personal data breach within 72 hours where required.

Most of these obligations are ongoing records, not one-off documents. Keeping them in a system rather than a folder is what makes them defensible.

See this in the product

Compliancy holds the controls, evidence and records described above in one platform.