Compliance

GDPR Compliance Checklist: A Practical Guide

The GDPR is principles-based, which makes it easy to nod along to and hard to operationalise. Here's a concrete, item-by-item checklist of what to actually put in place, and how to prove it.

Vishal Shinde · GRC Product Specialist, Pelta Technologies11 min readUpdated Part of GDPR

The EU General Data Protection Regulation governs how organisations handle the personal data of individuals in the EU. It is principles-based rather than a control checklist, which makes it deceptively easy to agree with and genuinely hard to operationalise. This guide turns the principles into a concrete, item-by-item checklist of what to put in place, and, just as importantly, how to prove it. For the wider picture, see the GDPR framework overview.

This is a general guide, not legal advice. Confirm your obligations (including whether you act as controller or processor, and whether you need an EU representative) with qualified counsel.

Does GDPR apply to you?

The first thing to settle is scope, because GDPR reaches well beyond the EU. It applies if you are established in the EU, or if you offer goods or services to, or monitor the behaviour of, individuals in the EU, wherever your organisation sits. That is why an Indian or US company with EU customers is often in scope. If you are caught by this extraterritorial reach and have no EU establishment, you may also need to appoint an EU representative.

Know your data and your role

You cannot protect or justify data you have not mapped, so the programme starts with knowing what you hold and in what capacity.

  • Maintain a Record of Processing Activities (RoPA): what personal data you process, why, and where it goes.
  • Determine whether you are a controller (you decide purpose and means) or a processor for each activity, your obligations differ.
  • Map data flows, including transfers outside the EU and the safeguards that cover them.

Establish a lawful basis

Every processing activity needs a lawful basis: consent, contract, legal obligation, vital interests, public task or legitimate interests. Consent is only one of the six, and often not the most robust, pick the basis that genuinely fits the activity and document it. Where you rely on consent, it must be freely given, specific, informed and as easy to withdraw as to give. Where you rely on legitimate interests, be ready to show the balancing test that weighed your interest against the individual's rights.

Honour data-subject rights

Handling a data-subject request

Receive

Any channel

Verify

Confirm identity

Locate

Find the data

Action

Access, erase, correct

Respond

Within the deadline

Individuals have rights including access, rectification, erasure, restriction, portability and objection. You need a process to receive a request through any channel, verify identity, find the data across all your systems, and respond within the statutory timeframe (generally one month). The hard part is rarely the decision, it is locating every copy of a person's data quickly enough to meet the deadline.

Secure the data and plan for breaches

  • Apply appropriate technical and organisational security measures, the same ground ISO 27001 covers.
  • Be able to detect, assess and, where required, notify a personal data breach to the supervisory authority within 72 hours, and affected individuals without undue delay where the risk is high.
  • Bind processors with GDPR-compliant contracts and oversee how they handle data on your behalf.
  • Run Data Protection Impact Assessments (DPIAs) for high-risk processing before you start it.

International data transfers

Sending EU personal data outside the EU needs a valid transfer mechanism: an adequacy decision for the destination country, or safeguards such as Standard Contractual Clauses (SCCs), often paired with a transfer impact assessment. For organisations in India, the US and other non-adequacy countries, SCCs are the common route, and they are exactly the kind of control an auditor will ask you to evidence.

Do you need a Data Protection Officer?

A DPO is mandatory if your core activities involve large-scale, regular and systematic monitoring of individuals, or large-scale processing of special-category data, or you are a public authority. Many organisations that are not strictly required to appoint one still designate a responsible privacy owner, because the accountability duties below need a clear owner regardless.

Demonstrate accountability

GDPR's accountability principle means it is not enough to comply, you must be able to show you comply. That is where a connected evidence approach earns its keep: policies, RoPA, consent records, DPIAs, transfer safeguards and data-subject-request logs, all kept linked and current so you can produce them on demand. Because GDPR's security expectations overlap heavily with ISO 27001 and with India's DPDPA, much of this can be reused rather than rebuilt, which is how Pelta handles overlapping privacy frameworks.

Comply once, reuse everywhere, in PeltaSee how the crosswalk works
Compliant

GDPR

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding DPDPA

~70% carried over
Carried over from GDPR New work for your team

Auto-completed from your existing program

Consent recordsData inventorySecurity safeguardsBreach notificationData-subject rightsProcessor oversight

Overlap shown is illustrative, the actual carry-over depends on the maturity of your existing program.

If you operate in India as well as the EU, that overlap is a real shortcut: see the DPDPA compliance checklist, and note how much of the same evidence base serves both. The security layer also reuses your ISO 27001 work.

Putting it together

GDPR compliance comes down to knowing your data and role, having a lawful basis for every activity, honouring rights on time, securing the data and being ready to report a breach within 72 hours, covering international transfers, and above all being able to demonstrate all of it with linked evidence. Build it once, reuse it across ISO 27001 and DPDPA, and GDPR becomes an operating rhythm rather than a scramble before a regulator or a customer audit.

Frequently asked questions

Does GDPR apply to companies outside the EU?+

Yes, it can. GDPR applies if you are established in the EU, or if you offer goods or services to, or monitor the behaviour of, individuals in the EU, regardless of where your organisation is based. Many Indian and US companies are in scope through this extraterritorial reach, and some must appoint an EU representative.

Who must comply with the GDPR?+

Any organisation processing the personal data of individuals in the EU within the scope above. Your specific obligations depend on whether you act as a controller (you decide purpose and means) or a processor for each activity.

What is a lawful basis under GDPR?+

One of six grounds that justify processing: consent, contract, legal obligation, vital interests, public task or legitimate interests. Every processing activity needs one, chosen to fit the activity and documented.

What is the GDPR breach notification deadline?+

Where a personal data breach is notifiable, controllers are generally required to notify the relevant supervisory authority within 72 hours of becoming aware of it, and to inform affected individuals without undue delay where the risk to them is high. Confirm the specifics for your situation.

Do I need a Data Protection Officer under GDPR?+

A DPO is mandatory if your core activities involve large-scale regular and systematic monitoring, or large-scale processing of special-category data, or you are a public authority. Even when not required, many organisations designate a privacy owner to carry the accountability duties.

What is a RoPA?+

A Record of Processing Activities, an inventory of what personal data you process, for what purpose, and where it flows. It is both a requirement for many organisations and the practical foundation of a GDPR programme.

How does GDPR relate to India's DPDPA?+

Both protect personal data and share core principles, so much groundwork transfers. But they are distinct laws with different definitions, consent mechanics and enforcement, so map obligations across both rather than assuming equivalence.

About the author

V

Vishal Shinde

GRC Product Specialist, Pelta Technologies

GRC · Privacy & Information Security

Vishal Shinde is a GRC Product Specialist at Pelta Technologies, focused on governance, risk and compliance, privacy and information security. He works hands-on with regulated organisations to turn framework requirements into managed controls with linked evidence.

Connect on LinkedIn →

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.