GDPR Compliance Checklist
Use this interactive checklist to ensure your website or application is compliant with the General Data Protection Regulation (GDPR).
0% complete
1. Lawful Basis for Processing
Determine if you process data based on consent, contract, legal obligation, vital interests, public task, or legitimate interests.
Keep internal records showing which lawful basis applies to each type of processing.
If relying on consent, ensure it's freely given, specific, informed, and unambiguous.
2. Privacy Policy
Your policy should explain what data you collect, why, how you use it, and who you share it with.
Link to your privacy policy in your website footer and during account registration.
Avoid legal jargon. Users should understand their rights and how their data is used.
3. Data Subject Rights
Users can request a copy of their personal data in a machine-readable format.
Users can request corrections to inaccurate or incomplete data.
Users can request deletion of their personal data under certain conditions.
Users can limit how you process their data in certain situations.
Users can object to processing based on legitimate interests or direct marketing.
4. Data Security
Implement HTTPS/TLS for data transmission and encrypt sensitive data in storage.
Limit data access to authorized personnel only using role-based permissions.
Plan for detecting, reporting, and investigating data breaches within 72 hours.
Periodically review and test your security measures and update them as needed.
5. Third-Party Data Processors
Ensure written contracts with vendors who process data on your behalf.
Check that third-party services you use are also GDPR compliant.
Use Standard Contractual Clauses (SCCs) or adequacy decisions for data transfers outside the EU.
6. Documentation & Records
Document what data you process, purposes, categories of data subjects, and retention periods.
Required for high-risk processing activities that could impact users' rights and freedoms.
Track when and how users gave consent, and what they consented to.
7. Data Retention & Deletion
Determine how long you need to keep different types of data and document this.
Set up processes to automatically delete data after retention periods expire.
Periodically audit stored data and remove what's no longer needed.
Next Steps
Generate Your Privacy Policy
Use our free generator to create a GDPR-compliant privacy policy.
Go to Privacy Policy Generator →Learn More About GDPR
Visit our legal resources page for guides and best practices.
Browse Legal Resources →Download This Checklist
Save your progress as a PDF for your records.
Disclaimer: This checklist is for informational purposes only and does not constitute legal advice. GDPR compliance requirements may vary based on your specific situation. We recommend consulting with a qualified data protection officer or attorney for personalized guidance.