All Blog Posts

GDPR Compliance Checklist: Everything Your Organization Needs to Do

Close
Read time
10 mins
Updated
Jul 1, 2026
Share
  • GDPR applies to companies with EU/EEA visitors in any location, including the USA.
  • GDPR fines can come up to EUR 20 million per infraction or four percent of global annual turnover, as of May 2026.
  • The GDPR compliance checklist covers ten key areas, including data mapping, consent mechanism implementation, and conducting Data Protection Impact Assessments (DPIAs).
  • Obtaining cookie consent is one of the key GDPR compliance mechanisms for collecting non-essential information from website users.
  • US companies that transfer EU personal data to the United States must comply with GDPR and use a recognized mechanism: EU–US Data Privacy Framework certification, Standard Contractual Clauses, or both.

The General Data Protection Regulation (GDPR) applies to any organization (regardless of its B2B/B2C focus, size, and location) that processes the data of individuals who are physically present in the EU/EEA (regardless of their nationality). If you are a US business with customers and/or website visitors from the EU, GDPR compliance is relevant for you. 

Yet, the compliance with GDPR is not a one-time project, and it feels like a maze with no starting point. This guide offers a ten-step GDPR compliance checklist with clear processes your organization should launch and maintain.

Does GDPR Apply to Your Organization?

Art. 3 GDPR for EU and UK GDPR (“Territorial scope”) states that the regulation applies to the processing of personal data in the Union, including the cases when this processing happens in another jurisdiction. The territorial scope requirement covers offering goods and services to EU/EEA residents and monitoring their behavior and applies to both controllers and processors. 

Here is what you can do to prepare your company for the GDPR requirements checklist:

  • Confirm whether GDPR applies to your organization: Review Art. 3 and common GDPR exemptions.
  • Address GDPR requirements: Appoint an EU Representative under Art. 27 GDPR and implement six data processing principles into your business operations (Art. 5 GDPR).
  • Set legal data transfer mechanism: Get DPF certification or sign the SCC contract and confirm the correct model with a Transfer Impact Assessment (TIA).

GDPR Compliance Checklist

 GDPR Compliance Checklist
1

Map Your Data with ROPA

2

Determine lawful bases for your processing activities

3

Publish a Compliant Privacy Notice

4

Implement a Cookie Consent Mechanism

5

Honor Data Subject Rights

6

Review Third-Party Processors

7

Appoint a Data Protection Officer (If Required)

8

Conduct Data Protection Impact Assessments (DPIAs) for High-Risk Processing

9

Have a Data Breach Response Plan

10

Maintain Ongoing Compliance

1. Map Your Data with ROPA

Action items:

  • Introduce ROPA documenting for all processing activities (required for companies with over 250 employees globally)
  • Check all third-party data flows and include the relevant ones in ROPA
  • Limit your data collection to the data minimisation principle under Art. 5.1 (c) GDPR
  • Review ROPA accuracy and scope at least once a year

Art. 30 GDPR requires a controller or their representative to keep a Record of Processing Activities (ROPA) under its responsibility, including:

  • Name and contact details of the controller (and DPO if applicable)
  • Purposes of processing
  • Categories of data subjects and personal data
  • Categories of recipients (including third-country transfers)
  • Retention periods
  • Security measures (where possible)

As of Art. 30(5) GDPR, organizations with less than 250 employees are not obligated to comply with the ROPA requirement, unless their activity poses a risk to individuals' rights.

2. Determine Lawful Bases for Your Processing Activities

Action items:

  • Add a lawful basis to each processing activity in your ROPA
  • Where legitimate interests apply: complete and document a Legitimate Interests Assessment (LIA)
  • Where consent applies: introduce an opt-in mechanism for collecting consent
  • Review lawful bases with ROPA annually

Art. 6 GDPR introduces six lawful bases as possible justifications for personal data collection, meaning:

  • Consent: Introducing a GDPR-compliant mechanism where users give their permission for data processing
  • Contract: Signing a contract with a user to process their data
  • Legal obligation: The data processing activity is connected with a binding law, regulation, or court order 
  • Vital interests: Specific “life or death scenarios” like sharing a missing person's health records with emergency rescue teams. 
  • Public task: The processing is conducted by public universities, utility companies, or public health agencies. 
  • Legitimate interests: The data processing is necessary for the interests of an organization and doesn’t contradict the fundamental rights of users (requires LIA).

The GDPR checklist for websites mostly recommends introducing consent for marketing purposes and analytics and relying on legitimate interests (after passing a LIA) for fraud prevention, security, and internal administration services. Signing a contract and relying on a legal obligation are optional legal bases for other types of processing activities.

3. Publish a Compliant Privacy Notice

Action items:

  • Include all the GDPR checklist requirements for a privacy notice
  • Write the notice in plain, accessible language
  • Place the privacy notice on the website footer, cookie banner, and sign-up forms
  • Keep a version history of your privacy notice for accountability

Art. 13 and Art. 14 GDPR obligate organizations to notify users at the moment of data collection with a privacy notice that includes:

  • Identity and contact details of the controller
  • Contact details of the Data Protection Officer (DPO) (if applicable)
  • Purposes and lawful basis for processing
  • Legitimate interests, contractual rules, or statutory requirements relied upon (if applicable)
  • Any third-party recipients or categories of recipients
  • International transfers and safeguards used
  • Data retention periods
  • Data subject rights and how to exercise them
  • Right to withdraw consent (where consent is the basis, along with the cookie policy)
  • Right to lodge a complaint with a supervisory authority
  • Existence of automated decision-making (including profiling)

Art. 12 GDPR requires transparent information, communication, and modalities for the privacy notice, meaning being written in plain language and easily visible for website visitors or while visiting the physical office.

Action items:

  • Audit essential and non-essential cookies your website collects
  • Implement a GDPR-compliant cookie banner for non-essential cookies
  • Log and store consent records
  • Enable users to withdraw or change consent at any time

Art. 7 GDPR requires consent as a freely given, specific, and informed decision to share personal data for processing that is easy to withdraw. More specifically, the ePrivacy Directive is transposed into national law by each EU member state and regulates prior consent before collecting non-essential cookies.

Cookiebot CMP automates cookie scanning, creates a GDPR-compliant cookie banner (available in over 47 languages), and logs each consent event to an audit trail.

5. Honor Data Subject Rights

Action items:

  • Check eight data subject rights under GDPR
  • Create a documented process for each scenario of honoring
  • Keep logs of all requests and responses for accountability
  • Conduct training for employees who act as a dedicated contact point in your organization to respond accordingly

Chapter 3 GDPR determines eight key data subject rights, with the requirements to document and stick to the designated timeframe for each scenario.

Data subject rightLegal basisGDPR compliance requirements 
Withdraw consentArt. 7The right should be given at any time and be easy. Withdrawal shall not affect the lawfulness of processing.
Subject right access (SAR)Art. 15 Should be easy to know and obtain the copy and an explanation regarding the purposes of processing within one month (or three months for more complex requests, as of May 2026).
RectificationArt. 16Provide the right to correct inaccurate data without undue delay.
ErasureArt. 17Provide the ‘right to be forgotten’ without undue delay where no overriding legal basis applies
Restriction of processingArt. 18Suspend processing (but retain data) where requested before obtaining consent
Data portabilityArt. 20Provide data in a machine-readable format to the individual or another controller
ObjectArt. 21Should be possible at any time to stop processing for direct marketing immediately
Automated individual decision makingArt. 22Provide the right to exclude oneself from automated processing, including profiling

6. Review Third-Party Processors

Action items:

  • Conduct an inventory of all the third-party tools, including analytics, marketing platforms, CDNs, and CMS plugins
  • Check you’ve signed a Data Processing Agreement (DPA) with each
  • Implement DPAs with all the existing and new third-party contractors
  • For US companies: confirm the transfer mechanism (DPF certification or SCCs) is documented in or alongside the DPA

Art. 28 GDPR requires a binding contract between a controller and a processor that regulates the terms of personal data processing, commonly referred to as a Data Processing Agreement (DPA). The absence of this document is a GDPR violation, even if the analytics tool, cloud storage, or marketing platform you use is GDPR-compliant.

 Each DPA must include:

  • Subject matter, duration, nature, and purpose of processing
  • Type of personal data and categories of data subjects involved
  • Processor's obligations and rights
  • Obligation to assist the controller with data subject rights requests 
  • Technical and organizational measures for security
  • Sub-processing restrictions and requirements
  • Data breach notification terms
  • Data return or deletion
  • Compliance verification

7. Appoint a Data Protection Officer (If Required)

Action items:

  • Check if your organization requires a Data Protection Officer (DPO) under GDPR
  • If yes: appoint a DPO, register their contact in DPA, and publish their details in a privacy notice
  • In no: designate an internal privacy lead as a single point of contact

Under Art. 37 GDPR, a DPO appointment is required for: 

  1. Public authorities and bodies (except courts acting in judicial capacity)
  2. Organizations involved in regular, systematic, and large-scale monitoring of individuals
  3. Organizations processing special category data (health, biometric, criminal) on a large scale

A DPO is an independent expert in data protection law who reports to the highest management level (Art. 38 GDPR requirement as of May 2026). Organizations that are not required to appoint a DPO can consider appointing an internal privacy lead to fulfill the DPO duties.

8. Conduct Data Protection Impact Assessments (DPIAs) for High-Risk Processing

Action items:

  • Determine high-risk processing activities in your organization eligible for DPIAs
  • Contact a supervisory authority for consultation on high-risk processing
  • Complete a DPIA for all processing activities required by GDPR

Data Protection Impact Assessment (DPIA) is a tool to address the potential high risk to the rights and freedoms caused by personal data processing using new technologies (Art. 35 GDPR). As of May 2026, this document should include a systematic description, assessment of the necessity and proportionality of the processing operations, assessment of risks and freedoms, and measures to address them.

The DPIA is required for:

  • Automated processing (including profiling)
  • Processing of large data sets of special categories (health, biometric, genetic, criminal)
  • Systematic monitoring of individuals in a publicly accessible area

9. Have a Data Breach Response Plan

Action items: 

  • Establish and document a data breach response procedure covering detection, containment, assessment, notification, and review
  • Identify who is responsible for breach notification decisions (DPO, legal counsel, or designated privacy lead)
  • Know your national supervisory authority's breach reporting portal to contact within 72 hours

Art. 4(12) GDPR determines a personal data breach as accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. As of May 2026, Art. 33 GDPR gives a controller 72 hours to notify a supervisory authority after having become aware of a data breach or, if delayed, accompanied by reasons for the delay.

10. Maintain Ongoing Compliance

Action items:

  • Maintain all required documentation and store it in a manner accessible to your supervisory authority on request
  • Establish an annual process for a full compliance check, with ad hoc review after any significant change to processing activities
  • Conduct regular training for all staff who handle personal data

Art. 5.2 GDPR sets accountability as its key principle, meaning that organizations must be able to demonstrate GDPR compliance on request. In the CNIL sanctions issued overview, failure to meet data retention and security requirements is the most common issue by May 2026.

To protect your company from costly penalties, it’s recommended to keep all the documentation in a consolidated and accessible manner, including:

  • ROPA files with legal bases documented
  • LIA documentation (for legitimate interests processing)
  • Privacy notice version history
  • Consent logs
  • DPA agreements with third parties
  • DPIA records for high-risk processing activities
  • Breach register with all incidents documented
  • Staff data protection training records

GDPR Compliance for US Companies: What You Need to Know

The three key triggers for compliance with GDPR for US companies are: having an EU office (branch or subsidiary), offering goods and services to EU/EEA residents, or monitoring the behavior of EU/EEA residents.

For companies that need to comply with GDPR, it imposes stricter rules on consent, legal bases, and mandatory roles compared to most US laws. Still, there are GDPR exemptions, or specific cases when GDPR doesn’t apply. The quick decision table below helps to make an informed decision in your situation.

Your situationDoes GDPR applyExtra notes
Having an EU establishment (office, branch, representative)YesTerritorial scope applies under Art. 3 GDPR
Offering goods/services or monitoring the behavior of EU/EEA residentsYesAppoint an EU representative (Art. 27)
Ensure DPF/SCC for data transfers
Regularly review vendor contracts
US-only or anonymous data operationsNoUS state laws may apply
Pseudoanonymized data remains in scope
Processing for personal activity only or acting upon law enforcementNoGDPR exemptions

As of 2025-2026, compliance with GDPR for US companies is part of broader EU digital legislation, including:

  • The EU–U.S. Data Privacy Framework (DPF) that regulates data transfers between regions (upheld by the European General Court in September 2025)
  • Standard Contractual Clauses (SCC) as an alternative data transfer mechanism between a contractor and processor under Art. 46 GDPR.
  • EU AI Act (effective August 2024, enforcement of the majority of provisions beginning on August 2, 2026) that affects GDPR privacy impact assessment, privacy notice messaging, and compliance checklist composition. 

For US companies, complying with GDPR and introducing a legitimate data transfer mechanism are equally important to avoid costly GDPR penalties that can reach up to EUR 20 million per violation or four percent of global annual turnover (as of May 2026).

Putting Your GDPR Checklist Into Action

The GDPR compliance checklist is the set of measures that organizations should take to avoid GDPR penalties and establish secure personal data processing operations. The scope of actions includes proper data categorization and documentation, introducing GDPR-compliant mechanisms, agreements, and responsible roles, and designing a data breach mechanism. 

Cookiebot CMP helps to simplify data audit, cookie banner design, and keep GDPR-compliant consent logs. It automatically scans the website to detect cookies and third-party scripts, creates opt-in consent banners (with geo-targeting available), and maintains audit records ready for check by a supervisory authority.

Simplify and automate GDPR compliance steps and keep them up to date.

This article was last verified in May 2026. GDPR enforcement and related legislation are subject to ongoing change — check EDPB guidance and your national supervisory authority for the latest requirements. 

Frequently asked questions

GDPR compliance requirements include ten core areas: (1) data mapping and audit with ROPA, (2) assigning lawful bases for each data processing case, (3) publishing a privacy notice, (4) introducing cookie consent mechanism, (5) reviewing operations to honor data subject rights per GDPR, (6) signing DPAs with third-party processors, (7) appointing DPO or another responsible person for GDPR compliance, (8) conducting DPIAs for high-risk processing, (9) preparing a data breach plan, and (10) proactively documenting all these activities for accountability.

GDPR applies to all US companies that have an EU establishment, offer goods or services to EU residents, or monitor EU resident behavior, according to Art. 3 GDPR. For all the companies outside the EU, the first steps on how to be GDPR compliant are assigning an EU Representative and aligning with the GDPR opt-in consent model (which is different from the opt-out model under CCPA).

As of May 2026, the GDPR fine can reach up to EUR 20 million or four percent of global annual turnover, with the largest EUR 1.2 billion penalty imposed on Meta in 2023 for the systematic non-compliance. US companies should also have a DPF/SCC data transfer mechanism in place: in 2024, the Dutch Supervising Authority imposed a EUR 290 million fine on Uber for the lack of proper data transfer tools.

GDPR requirements checklist is a structured list of actionable tasks covering each of the key legal requirements to address the accountability principle required by Art. 5.2 GDPR. The scope of GDPR compliance steps covers data mapping, introducing consent mechanisms and LIAs, assigning responsible roles, and keeping accurate documentation.

Yes. GDPR does not include a minimum threshold for the number of EU individuals whose data is processed. Even businesses with a small number of EU customers may need to comply if they collect or process EU personal data.

If your website uses cookies and third-party trackers (e.g. by using social media links, analytics tools or marketing plugins), you are required to ask for and obtain the prior and explicit consent of your user.

Learn more about GDPR and cookie consent

Art. 4 GDPR defines a data controller as the entity that determines the purposes and means of personal data processing, while a data processor is the entity that executes it. Data controllers possess the full scope of GDPR compliance obligations, and data processors should act only on controller instructions and maintain their obligations determined in Art. 28 GDPR.