Downloads

GDPR Compliance Checklist

This file is a yes/no workplan for Regulation (EU) 2016/679. It has 86 items in 15 sections. Each line names the article, recital, EDPB guideline, Commission decision or Court of Justice case it comes from. The list follows the same ground as the long guide: who is in scope, records of processing, the Article 5 principles, lawful basis, consent, special-category data, notices, data-subject rights, processors, security and breaches, DPIAs, the data protection officer, transfers out of the EEA, cookies under the ePrivacy Directive, and oversight. It is current as of 17 August 2026. The Digital Omnibus proposal is marked as a proposal. Regulation (EU) 2025/2518 is noted as applying from 2 April 2027. Start with section 1 (scope and roles). Later sections only hold if you already know what personal data you process, for which purposes, with whom, and where. Tick what is done. Write “N/A” only where the cited rule does not apply, and say why. Keep the finished copy with your Article 30 records. This is a workplan. It is not a certificate of compliance and not legal advice. Member State law can add duties the Union text does not list.

gdpr-compliance-checklist.pdf · 128.9 KB · application/pdf

Sign in to download this file to your account.

Sign in to download