Skip to main content

GDPR Checklist

19 requirements mapped to controls.

Requirements

RequirementTitleControlsOwner
Conduct an information auditConduct an information audit to determine what information you process and who has access to itSID-AUDIT-01platform
Have a legal justificationHave a legal justification for your data processing activitiesSID-ORG-05operator
Provide clear information about your data processingProvide clear information about your data processing and legal justification in your privacy policySID-ORG-07operator
Take data protection into account at all timesTake data protection into account at all times, from the moment you begin developing a product to each time you process dataSID-PRIV-01, SID-DATA-01, SID-DATA-02, SID-CRYPTO-03, SID-CRYPTO-02platform
Encrypt, pseudonymize, or anonymizeEncrypt, pseudonymize, or anonymize personal data wherever possibleSID-CRYPTO-01, SID-CRYPTO-03, SID-CRYPTO-02, SID-DATA-01, SID-DATA-06platform
Create an internal security policyCreate an internal security policy for your team members, and build awareness about data protectionSID-ORG-01, SID-PPL-02operator
Know when to conduct a data protection impactKnow when to conduct a data protection impact assessment, and have a process in place to carry it outSID-ARCH-02operator
Have a process in place to notify the authoritiesHave a process in place to notify the authorities and your data subjects in the event of a data breachSID-OPS-01, SID-AUDIT-01platform
Designate someone responsible for ensuring GDPRDesignate someone responsible for ensuring GDPR compliance across your organizationSID-ORG-02operator
Sign a data processing agreementSign a data processing agreement between your organization and any third parties that process personal data on your behalfSID-ORG-04operator
organization is outside the EUIf your organization is outside the EU, appoint a representative within one of the EU member statesSID-ARCH-02operator
Appoint a Data Protection OfficerAppoint a Data Protection Officer (if necessary)SID-ARCH-02operator
request and receive all the informationIt's easy for your customers to request and receive all the information you have about themSID-ARCH-02operator
correct or update inaccurateIt's easy for your customers to correct or update inaccurate or incomplete informationSID-ARCH-02operator
request to have their personal data deletedIt's easy for your customers to request to have their personal data deletedSID-PRIV-03platform
ask you to stop processingIt's easy for your customers to ask you to stop processing their dataSID-ARCH-02operator
receive a copy of their personal dataIt's easy for your customers to receive a copy of their personal data in a format that can be easily transferred to another companySID-ARCH-02operator
object to you processingIt's easy for your customers to object to you processing their dataSID-PRIV-01, SID-PRIV-03platform
automated processesIf you make decisions about people based on automated processes, you have a procedure to protect their rightsSID-ARCH-02operator