GDPR compliance checklist - GDPR.eu (2024)

Lawful basis and transparency
  • Conduct an information audit to determine what information you process and who has access to it.
  • Have a legal justification for your data processing activities.
  • Provide clear information about your data processing and legal justification in your privacy policy.
Conduct an information audit to determine what information you process and who has access to it.

Organizations that have at least 250 employees or conduct higher-risk data processing are required to keep an up-to-date and detailed list of their processing activities and be prepared to show that list to regulators upon request. The best way to demonstrate GDPR compliance is using a data protection impact assessment Organizations with fewer than 250 employees should also conduct an assessment because it will make complying with the GDPR's other requirements easier. In your list, you should include: the purposes of the processing, what kind of data you process, who has access to it in your organization, any third parties (and where they are located) that have access, what you're doing to protect the data (e.g. encryption), and when you plan to erase it (if possible).

Have a legal justification for your data processing activities.

Processing of data is illegal under the GDPR unless you can justify it according to one of six conditions listed in Article 6. There are other provisions related to children and special categories of personal data in Articles 7-11. Review these provisions, choose a lawful basis for processing, and document your rationale. Note that if you choose "consent" as your lawful basis, there are extra obligations, including giving data subjects the ongoing opportunity to revoke consent. If "legitimate interests" is your lawful basis, you must be able to demonstrate you have conducted a privacy impact assessment.

Provide clear information about your data processing and legal justification in your privacy policy.

You need to tell people that you're collecting their data and why (Article 12). You should explain how the data is processed, who has access to it, and how you're keeping it safe. This information should be included in your privacy policy and provided to data subjects at the time you collect their data. It must be presented "in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child."

GDPR compliance checklist - GDPR.eu (2024)

FAQs

What is the GDPR compliance checklist? ›

In your list, you should include: the purposes of the processing, what kind of data you process, who has access to it in your organization, any third parties (and where they are located) that have access, what you're doing to protect the data (e.g. encryption), and when you plan to erase it (if possible).

Who does the GDPR apply to quiz answers? ›

To whom does the GDPR apply? Any organisation which processes and holds the personal data of EU citizens is obliged to abide by the laws set out by GDPR.

How to answer GDPR interview questions? ›

If you've worked with the GDPR in previous roles, offer an explanation of the type of work you carried out and how the GDPR related to it. You may also wish to mention any strategies you've used to ensure compliance with the GDPR in your previous work.

What are the 7 GDPR requirements? ›

Lawfulness, fairness, and transparency; ▪ Purpose limitation; ▪ Data minimisation; ▪ Accuracy; ▪ Storage limitation; ▪ Integrity and confidentiality; and ▪ Accountability. These principles are found right at the outset of the GDPR, and inform and permeate all other provisions of that legislation.

What are the 10 key requirements of GDPR? ›

The 10 Key Requirements of the GDPR
  • Recordkeeping: ...
  • Data Protection Officers. ...
  • Data Protection Impact Assessments. ...
  • Privacy by Design and Default. ...
  • Transparency and GDPR. ...
  • Informed Consent or another Basis for Processing. ...
  • Third Party Processing. ...
  • Data Subject Access Requests.

What is the compliance checklist? ›

It is a tool that helps businesses to ensure that they are meeting all the necessary legal requirements and avoiding potential legal and financial penalties. This checklist covers a wide range of areas, including data privacy, security, accounting and financial reporting, employment laws, and environmental regulations.

Does the GDPR apply to EU citizens in the US? ›

No, the GDPR does not apply to EU citizens in the US. The location of the data subject, rather than their citizenship, determines whether GDPR applies. EU citizens traveling to or living in the US are not protected by the GDPR.

Is GDPR EU only? ›

The GDPR does apply outside Europe

The whole point of the GDPR is to protect data belonging to EU citizens and residents. The law, therefore, applies to organizations that handle such data whether they are EU-based organizations or not, known as “extra-territorial effect.”

Who checks GDPR compliance? ›

Tasks of the DPO

☐ Our DPO is tasked with monitoring compliance with the UK GDPR and other data protection laws, our data protection policies, awareness-raising, training, and audits. ☐ We will take account of our DPO's advice and the information they provide on our data protection obligations.

What are the 4 important principles of GDPR? ›

These principles include the lawful, fair, and transparent processing of personal data; the purpose limitation principle, which emphasizes the need to collect data for specified and legitimate purposes; the minimization principle, which requires organizations to only collect and retain the data necessary for the ...

How do I prepare for GDPR compliance? ›

10-Step GDPR Compliance Checklist
  1. #1 Know the data you hold. ...
  2. #2 Secure your website. ...
  3. #3 Update privacy policy. ...
  4. #4 Get consent for emails. ...
  5. #5 Add a cookie banner. ...
  6. #6 Check forms on your website. ...
  7. #7 Review data processors or third-party services. ...
  8. #8 Review international data transfer.

What is the GDPR for dummies? ›

The GDPR takes the stance that a data subject must be informed of the processes which will be used to store their personal data. Subsequently, it will then be the data controller's responsibility to make the processing of personal data available to the data subject.

What are the golden rules of GDPR? ›

Necessary, proportionate, relevant, accurate, timely and secure: Ensure that the information you share is necessary for the purpose for which you are sharing it, is shared only with those people who need to have it, is accurate and up-to-date, is shared in a timely fashion, and is shared securely.

What are the three rules of GDPR? ›

Lawfulness, fairness and transparency.

What is the GDPR compliance? ›

At its core, GDPR Compliance means an organization that falls within the scope of the General Data Protection Regulation (GDPR) meets the requirements for properly handling personal data as defined in the law. The GDPR outlines certain obligations organizations must follow which limit how personal data can be used.

What is the GDPR in simple terms? ›

GDPR stands for General Data Protection Legislation. It is a European Union (EU) law that came into effect on 25th May 2018. GDPR governs the way in which we can use, process, and store personal data (information about an identifiable, living person).

What is the GDPR compliance verification? ›

GDPR Validation. The EU's General Data Protection Regulation (GDPR) is one of the leading privacy regulations that business partners, customers, and regulators look at for compliance. Get validated by an independent third party that attests your privacy and data protection practices.

What is needed to be GDPR compliant? ›

What are the basic requirements of GDPR? The basic requirement is to collect and process the personal data of users fairly, securely and lawfully for a lawful purpose and disclose details about how you handle the data to users.

Top Articles
Latest Posts
Article information

Author: Kareem Mueller DO

Last Updated:

Views: 5926

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Kareem Mueller DO

Birthday: 1997-01-04

Address: Apt. 156 12935 Runolfsdottir Mission, Greenfort, MN 74384-6749

Phone: +16704982844747

Job: Corporate Administration Planner

Hobby: Mountain biking, Jewelry making, Stone skipping, Lacemaking, Knife making, Scrapbooking, Letterboxing

Introduction: My name is Kareem Mueller DO, I am a vivacious, super, thoughtful, excited, handsome, beautiful, combative person who loves writing and wants to share my knowledge and understanding with you.