GDPR compliance requires a clear understanding of how personal data is collected, used, shared, and protected. Privacy notices, cookie preferences, customer records, employee data, and agreements with service providers all form part of that review.
This checklist covers the main obligations in 10 steps. Use it to review your current practices, identify gaps, and assign responsibility for the work needed.
What Is GDPR Compliance?
GDPR compliance means processing personal data in accordance with the European Union’s General Data Protection Regulation and being able to demonstrate that compliance. This includes having a lawful basis for processing, informing individuals, respecting their rights, and applying appropriate security measures.
Article 5 sets out the principles for processing personal data. Article 24 requires controllers to implement appropriate measures and update them when necessary. Compliance therefore covers both published policies and day-to-day practices, along with the records that document them.
For an introduction to the main concepts, see our What Is GDPR? guide. For the legal requirements, refer to the official GDPR text.
Who Does the GDPR Apply To?
The GDPR applies to personal data processing carried out in the context of an organisation’s establishment in the EU/EEA. Organisations outside the region may also fall within its scope when they offer goods or services to people there or monitor their behaviour.
Article 3 sets out the main situations in which the GDPR applies:
Controllers and processors established in the EU/EEA: Processing carried out in the context of that establishment’s activities falls within scope. Processing the data in another country does not, by itself, change this.
Organisations outside the EU/EEA that offer goods or services to people in the region: Processing related to those goods or services may fall within scope. The service does not have to involve payment.
Organisations outside the EU/EEA that monitor people’s behaviour in the region: Processing related to monitoring behaviour that takes place within the EU/EEA may fall within scope.
These organisations may be businesses, public bodies, associations, or other entities. Whether the GDPR applies is not determined solely by an individual’s nationality.
Under Article 2, the GDPR covers automated processing as well as manual records that form part of a filing system or are intended to do so. Exceptions, such as purely personal or household activities, must be considered separately.
Does the GDPR Apply to Your Business?
To determine whether the GDPR applies to your business, review where you operate, which markets you target, and how you use personal data.
Start with these questions:
Do you have a branch, office, or other establishment in the EU/EEA?
Do you target people in the region with sales, deliveries, memberships, or services?
Do you track their online behaviour to create profiles or analyse their activities?
For example, a business in Türkiye that targets customers in Germany and delivers products to them may fall within the GDPR’s scope for processing related to those sales. A website simply being accessible from Europe is not enough on its own. Advertising aimed at the market, delivery options, and other indicators must be considered together.
Being a small business does not create a general exemption. Obligations depend on the nature and risks of processing as well as, for some requirements, the number of employees.
Who Is Responsible for GDPR Compliance?
Controllers and processors are responsible for GDPR compliance within their respective roles and obligations. A data protection officer advises the organisation and monitors compliance. Supervisory authorities oversee enforcement.
Data controller: Determines why and how personal data is processed. Under Article 24, the controller must implement appropriate measures and be able to demonstrate compliance.
Data processor: Processes personal data on the controller’s behalf. Under Article 28, the processor must follow documented instructions, comply with the contract, and meet the GDPR obligations that apply directly to it.
Data protection officer (DPO): Must be appointed where required under Articles 37–39. The DPO provides advice, monitors compliance, advises on impact assessments, and acts as a contact point for the supervisory authority.
National supervisory authorities: Handle complaints, conduct investigations, and take enforcement action where necessary under Article 51 and Articles 57–58.
When working with service providers, establish the difference between a data controller and a data processor in each relationship. Outsourcing work or appointing a DPO does not remove the organisation’s own responsibilities.
A 10-Step GDPR Compliance Checklist
1. Identify Your Personal Data and Map Its Flow
Identify the personal data you collect, why you use it, and who you share it with. Include customer records, employee information, website forms, and the software you use in your data inventory.
Answer these questions:
What data do you collect, who does it relate to, and where does it come from?
Do you process health information, children’s data, or other data requiring additional protection?
Which systems and countries is the data stored in?
Who within your organisation can access it?
Which service providers receive it?
How long is it kept, and how is it deleted?
Use this information to map your data flows. Prepare the records of processing activities (ROPA) required under Article 30. Having fewer than 250 employees does not automatically exempt an organisation. Regular processing, processing that poses risks, and certain sensitive data categories can trigger record-keeping obligations.
2. Establish Lawful Bases and Retention Periods
Before processing personal data, identify a valid lawful basis for each purpose. Article 6 provides six bases: consent, performance of a contract, legal obligation, vital interests, public task or official authority, and legitimate interests.
Match each purpose to a lawful basis: Assess order fulfilment and advertising separately. The lawful bases for processing personal data must be appropriate to each purpose.
Document legitimate interests: Assess whether the processing is necessary and how it affects individuals’ rights.
Review sensitive data separately: Check the conditions in Article 9 for special category data and Article 10 for data relating to criminal convictions and offences.
Remove unnecessary data: Do not request information you do not need for the purpose. Correct inaccurate records.
Set retention periods: Decide when data will be deleted or anonymised, taking legal requirements into account.
Your data retention and deletion policy should cover archives, backups, and copies held by service providers as well as active records.
3. Update Your Privacy Notice
Your privacy notice should explain clearly how you use personal data. It must reflect your actual practices and meet the relevant requirements of Articles 12–14.
When writing a GDPR privacy notice, check that it includes:
Organisation details: The controller’s identity and contact information, along with representative and DPO details where applicable.
Data use: The purposes of processing, lawful bases, and any legitimate interests relied on.
Sharing and transfers: Recipients or categories of recipients, international transfers, and relevant safeguards.
Retention: How long data is kept or how the retention period is determined.
Individual rights: How to make a request, withdraw consent, and complain to a supervisory authority.
Additional information: Where relevant, the source of the data, the consequences of not providing it, and information about automated decision-making.
If you collect data directly from individuals, provide the information when you collect it. For data obtained from other sources, assess the conditions and deadlines in Article 14. Make the notice accessible from the relevant forms.
4. Review Forms and Marketing Permissions
Ask only for the information you need and explain how it will be used. Completing a contact form or making a purchase does not, by itself, mean that someone has agreed to receive marketing messages.
Remove unnecessary fields: Distinguish between required and optional information. When creating GDPR-compliant forms, assess every field against the form’s purpose.
Keep consent separate: Where processing relies on consent, offer a clear, optional choice that meets the consent requirements in GDPR Article 7. Do not bundle marketing consent with service terms.
Do not use pre-ticked boxes: Users must take an affirmative action to give consent.
Keep consent records: Record when and how consent was given and which information the person was shown.
Make opting out easy: Keep consent withdrawal and unsubscribe options easy to find and use.
GDPR rules for email marketing must be considered alongside ePrivacy requirements and the relevant national laws. Check where your mailing list came from and whether any existing-customer exception applies. Stop processing data for direct marketing when someone objects.
If you rely on consent for online services offered directly to children, assess the age and parental authorisation requirements in Article 8 separately.
5. Audit Cookies and Tracking Tools
Your cookie banner must translate users’ choices into how the website actually behaves. If someone rejects advertising cookies, the associated tracking must not continue.
Start with a cookie audit to identify cookies, analytics tools, advertising pixels, and embedded content. Then apply the following checks:
Block before consent: Do not activate cookies or tracking that require consent until the user agrees.
Present clear choices: Make accepting and rejecting straightforward. Avoid misleading buttons.
Offer choices by purpose: Separate purposes such as analytics and advertising. Do not preselect optional choices.
Record preferences: Document consent and the version of the information shown to the user.
Allow withdrawal: Add a visible “Cookie preferences” link.
Test the implementation: Check which tools run after acceptance, rejection, and withdrawal.
Cookie consent requirements depend on the GDPR’s consent rules and national implementation of ePrivacy rules. Assess strictly necessary uses and any other applicable exemptions separately. Explain purposes, providers, durations, and preference management in your cookie policy.
6. Assess Data Security and High-Risk Processing
Under Article 32, protect personal data against unauthorised access, loss, alteration, and other security risks. Choose measures based on the nature of the data and the potential harm.
Restrict access: Give employees only the permissions they need for their work.
Protect accounts: Use strong authentication and multi-factor authentication where appropriate.
Keep systems up to date: Monitor vulnerabilities and apply updates.
Assess encryption needs: Identify appropriate protection for data in transit and at rest.
Test backups: Verify that data can be restored securely when needed.
Review your measures: Regularly check whether the controls are effective.
Build data protection into system design as required by Article 25. Configure default settings so that only necessary personal data is processed. Before starting processing that is likely to pose a high risk, carry out a data protection impact assessment (DPIA). If a high risk remains despite the measures planned, consult the supervisory authority in advance under Article 36.
7. Review Service Providers and International Transfers
Check how your cloud, CRM, email, analytics, and payment providers use personal data. Establish whether each provider acts on your behalf or also determines its own purposes. If you jointly determine the purposes and means of processing with another organisation, allocate responsibilities under Article 26 and make the essence of that arrangement available to individuals.
Check agreements: Providers processing data on your behalf must be covered by a data processing agreement (DPA) or another binding arrangement that meets Article 28.
Define obligations: Cover data types, purpose, duration, instructions, confidentiality, security, assistance with rights requests, and breach notification.
Review subprocessors: Arrange the required written authorisation and notifications of changes.
Assess security: Review the provider’s access controls, encryption, and incident response practices.
Plan for the end of the service: Define requirements for returning or deleting data and verifying compliance.
For international data transfers under the GDPR, consider remote access by separate organisations abroad as well as the countries where data is stored. Under Articles 44–49, assess the scope of any adequacy decision or appropriate safeguards such as standard contractual clauses (SCCs) and binding corporate rules (BCRs). Complete the risk assessments and supplementary measures required by the chosen mechanism.
8. Establish a Process for Data Rights Requests
People may ask to access their data, correct inaccuracies, or have it deleted in certain circumstances. Create an accessible process for exercising GDPR data subject rights and tracking response deadlines.
Provide a contact channel: Include an address or request form in your privacy notice.
Assign responsibility: Decide who will receive, assess, and respond to requests.
Verify identity proportionately: Ask for necessary additional information where there is reasonable doubt. Do not automatically demand identity documents for every request.
Check all relevant records: Locate the data in your own systems and with service providers.
Track deadlines: Under Article 12, respond without undue delay and within one month at the latest.
Explain your decision: If you refuse a request, explain why and tell the person about their right to complain and seek a judicial remedy.
The deadline may be extended by two months because of the complexity or number of requests. If so, inform the person within the first month and explain the reason. Assess the conditions for erasure, portability, restriction, and objection separately. Record the request and the action taken.
For decisions based solely on automated processing that have legal or similarly significant effects, assess the restrictions in Article 22. Where applicable, put safeguards in place so individuals can request human intervention, express their views, and challenge the decision.
9. Prepare a Data Breach Response Plan
A file sent to the wrong person, a lost device, or unauthorised access may constitute a personal data breach. Decide in advance how incidents will be investigated and who will handle notifications.
Contain the incident: Take action on affected accounts or systems. Preserve records and evidence.
Establish the impact: Investigate which data is involved and approximately how many people and records are affected.
Assess the risk: Consider the potential consequences for individuals’ rights and freedoms.
Notify the controller: If you are acting as a processor, notify the controller without undue delay.
Check whether the authority must be notified: Notification under GDPR Article 33 must take place without undue delay and, where feasible, within 72 hours of becoming aware of the breach. An exception applies where the breach is unlikely to result in a risk to individuals’ rights and freedoms. If notification takes longer than 72 hours, explain the delay.
Inform individuals where there is a high risk: Notify affected people without undue delay, taking the exceptions in Article 34 into account.
Your GDPR data breach notification should describe the nature of the incident, its likely consequences, a contact point, and the measures taken. Information may be provided in stages where necessary. Document all breaches and decisions, including those that do not require notification.
10. Keep Responsibilities and Compliance Checks Up to Date
New software, service providers, or purposes for using data can change your processing practices. Review your measures and update them where necessary under Article 24.
Assign responsibilities: Identify the people and teams responsible for data protection work.
Assess whether a DPO is required: Review the appointment requirements in Articles 37–39. Where an appointment is required, check independence, resources, and potential conflicts of interest.
Assess EU representative requirements: If you are outside the EU and fall within Article 3(2), review the obligation and exceptions in Article 27.
Train employees: Explain forms, data sharing, security, and breach reporting in ways relevant to their roles.
Update records: Maintain policies, agreements, consent records, rights requests, and breach records.
Track outstanding work: Assign an owner and completion date to each corrective action.
During a GDPR compliance audit, review actual practices as well as documentation. Verify that cookie preferences, access controls, and deletion processes work as intended.
Frequently Asked Questions
The GDPR requires personal data to be processed lawfully, transparently, securely, and for appropriate purposes. Businesses must identify a valid lawful basis, limit collection to what is necessary, set retention periods, and enable individuals to exercise their rights. They must also keep records that demonstrate these practices. Depending on the processing, additional obligations may include data processing agreements, international transfer safeguards, a DPO, impact assessments, and breach notifications.
Some cookies contain personal data or lead to personal data being processed. A cookie identifier falls within the GDPR where it makes a person identifiable, either on its own or together with other information. This is not necessarily the case for every cookie. Storing or reading information on a device may also be subject to ePrivacy rules even when no personal data is involved. The relationship between cookies and personal data depends on the cookie’s contents, purpose, and connection to other information.
The GDPR’s seven principles are the processing and accountability rules set out in Article 5:
Lawfulness, fairness, and transparency: Process data on a valid lawful basis and inform individuals clearly.
Purpose limitation: Collect data for specified, legitimate purposes and do not use it for incompatible purposes.
Data minimisation: Process only the data necessary for the purpose.
Accuracy: Keep data accurate and up to date where necessary.
Storage limitation: Do not keep data in an identifiable form for longer than necessary.
Integrity and confidentiality: Protect data against unauthorised processing, loss, and damage.
Accountability: Follow these principles and be able to demonstrate compliance.
If a service provider processes personal data on your behalf, you need a data processing agreement or another binding legal arrangement that meets Article 28. The arrangement can be in electronic form. A general confidentiality agreement is not enough unless it includes the Article 28 requirements. However, not every data-sharing relationship is a controller–processor relationship. Sharing between independent controllers and joint controllership must be assessed separately.
The UK GDPR and EU GDPR share a common foundation but operate as separate legal frameworks. The main differences include:
Scope: One applies in the UK context and the other in the EU/EEA context.
Supervision: The ICO oversees data protection in the UK, while the relevant national supervisory authorities oversee it in the EU/EEA.
Data transfers: Available transfer mechanisms and adequacy decisions must be assessed separately.
Legislative changes: The UK’s Data (Use and Access) Act 2025 has introduced changes to the UK GDPR framework.
Businesses operating in both markets may need to comply with both regimes. Assess the differences between the UK GDPR and EU GDPR in the context of your business activities.
A GDPR compliance checklist turns data protection obligations into practical checks. It helps identify gaps in areas such as data inventories, lawful bases, security, individual rights, and service providers. The GDPR does not prescribe a single 10-step checklist. Completing one does not guarantee compliance. The checks must reflect your organisation’s activities and be supported by how you actually handle data.
The maximum penalty for a GDPR infringement depends on the type of breach. Article 83 sets out two main tiers:
Up to €10 million or 2% of the previous financial year’s total worldwide annual turnover.
Up to €20 million or 4% of the previous financial year’s total worldwide annual turnover.
For businesses, the higher amount in the relevant tier is the upper limit. These amounts are not imposed automatically for every infringement. Authorities consider factors such as severity, duration, and the measures taken. GDPR fines and penalties can also include orders restricting or prohibiting processing.
You must comply with the GDPR if your use of Google Analytics involves personal data processing that falls within its scope. The GDPR is not a certificate you purchase to use Analytics.
You need to block cookies that require consent until consent is given, inform users, set retention periods, and review contractual and international transfer requirements. Google Analytics GDPR compliance depends on your configuration and the features you enable. Consent Mode does not replace these assessments. It communicates users’ consent choices to tags but does not collect consent on its own.
The GDPR does not require you to use or purchase a particular cookie management platform. However, if you use cookies that require consent, you must collect valid consent, apply users’ choices, be able to demonstrate consent, and allow it to be withdrawn.
A consent management platform can help manage these tasks, but installing one is not enough on its own. Check that cookies are classified correctly, tags respond to users’ choices, and the consent withdrawal process works as intended.
Türkçe
English