Compliance

GDPR Compliance Checklist: A Practical Guide

The GDPR is principles-based, which makes it easy to nod along to and hard to operationalise. Here's a concrete checklist of what to put in place.

The Pelta Team8 min readUpdated Part of GDPR

The EU General Data Protection Regulation governs how organisations handle the personal data of individuals in the EU. It is principles-based rather than a control checklist, which makes it deceptively easy to agree with and genuinely hard to operationalise. This checklist turns the principles into concrete things to put in place.

This is a general guide, not legal advice. Confirm your obligations — and whether you act as controller or processor — with qualified counsel.

Know your data and your role

  • Maintain a Record of Processing Activities (RoPA): what personal data you process, why, and where it goes.
  • Determine whether you are a controller (you decide purpose and means) or a processor for each activity.
  • Map data flows, including transfers outside the EU and the safeguards that cover them.

Establish a lawful basis

Every processing activity needs a lawful basis — consent, contract, legal obligation, vital interests, public task or legitimate interests. Where you rely on consent, it must be freely given, specific and as easy to withdraw as to give. Where you rely on legitimate interests, you should be able to show the balancing test.

Honour data-subject rights

Handling a data-subject request

Receive

Any channel

Verify

Confirm identity

Locate

Find the data

Action

Access, erase, correct

Respond

Within the deadline

Individuals have rights including access, rectification, erasure, restriction, portability and objection. You need a process to receive a request through any channel, verify identity, find the data across your systems, and respond within the statutory timeframe.

Secure the data and plan for breaches

  • Apply appropriate technical and organisational security measures — the same ground ISO 27001 covers.
  • Be able to detect, assess and, where required, notify a personal data breach within 72 hours.
  • Bind processors with contracts and oversee how they handle data on your behalf.
  • Run Data Protection Impact Assessments for high-risk processing.

Demonstrate accountability

GDPR's accountability principle means it is not enough to comply — you must be able to show you comply. That is where a connected evidence approach earns its keep: policies, RoPA, consent records, DPIAs and request logs kept linked and current. Because GDPR's security expectations overlap heavily with ISO 27001 and with India's DPDPA, much of this can be reused rather than rebuilt — which is how Pelta handles overlapping privacy frameworks.

Comply once, reuse everywhere — in PeltaSee how the crosswalk works
Compliant

GDPR

  • Controls mapped
  • Evidence collected
  • Policies & procedures in place

Adding DPDPA

~70% carried over
Carried over from GDPR New work for your team

Auto-completed from your existing program

Consent recordsData inventorySecurity safeguardsBreach notificationData-subject rightsProcessor oversight

Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.

Frequently asked questions

Who must comply with the GDPR?+

Organisations that process the personal data of individuals in the EU, regardless of where the organisation is based. Your obligations depend on whether you act as a controller or a processor for each activity.

What is a lawful basis under GDPR?+

One of six grounds that justify processing: consent, contract, legal obligation, vital interests, public task or legitimate interests. Every processing activity needs one, documented.

What is the GDPR breach notification deadline?+

Where a personal data breach is notifiable, controllers are generally required to notify the relevant supervisory authority within 72 hours of becoming aware of it. Confirm the specifics for your situation.

What is a RoPA?+

A Record of Processing Activities — an inventory of what personal data you process, for what purpose, and where it flows. It is both a requirement for many organisations and the practical foundation of a GDPR programme.

How does GDPR relate to India's DPDPA?+

Both protect personal data and share core principles, so much groundwork transfers. But they are distinct laws with different definitions, consent mechanics and enforcement, so map obligations across both rather than assuming equivalence.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.