The EU General Data Protection Regulation governs how organisations handle the personal data of individuals in the EU. It is principles-based rather than a control checklist, which makes it deceptively easy to agree with and genuinely hard to operationalise. This checklist turns the principles into concrete things to put in place.
Know your data and your role
- Maintain a Record of Processing Activities (RoPA): what personal data you process, why, and where it goes.
- Determine whether you are a controller (you decide purpose and means) or a processor for each activity.
- Map data flows, including transfers outside the EU and the safeguards that cover them.
Establish a lawful basis
Every processing activity needs a lawful basis — consent, contract, legal obligation, vital interests, public task or legitimate interests. Where you rely on consent, it must be freely given, specific and as easy to withdraw as to give. Where you rely on legitimate interests, you should be able to show the balancing test.
Honour data-subject rights
Receive
Any channel
Verify
Confirm identity
Locate
Find the data
Action
Access, erase, correct
Respond
Within the deadline
Individuals have rights including access, rectification, erasure, restriction, portability and objection. You need a process to receive a request through any channel, verify identity, find the data across your systems, and respond within the statutory timeframe.
Secure the data and plan for breaches
- Apply appropriate technical and organisational security measures — the same ground ISO 27001 covers.
- Be able to detect, assess and, where required, notify a personal data breach within 72 hours.
- Bind processors with contracts and oversee how they handle data on your behalf.
- Run Data Protection Impact Assessments for high-risk processing.
Demonstrate accountability
GDPR's accountability principle means it is not enough to comply — you must be able to show you comply. That is where a connected evidence approach earns its keep: policies, RoPA, consent records, DPIAs and request logs kept linked and current. Because GDPR's security expectations overlap heavily with ISO 27001 and with India's DPDPA, much of this can be reused rather than rebuilt — which is how Pelta handles overlapping privacy frameworks.
GDPR
- Controls mapped
- Evidence collected
- Policies & procedures in place
Adding DPDPA
~70% carried overAuto-completed from your existing program
Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.
Frequently asked questions
Who must comply with the GDPR?+
Organisations that process the personal data of individuals in the EU, regardless of where the organisation is based. Your obligations depend on whether you act as a controller or a processor for each activity.
What is a lawful basis under GDPR?+
One of six grounds that justify processing: consent, contract, legal obligation, vital interests, public task or legitimate interests. Every processing activity needs one, documented.
What is the GDPR breach notification deadline?+
Where a personal data breach is notifiable, controllers are generally required to notify the relevant supervisory authority within 72 hours of becoming aware of it. Confirm the specifics for your situation.
What is a RoPA?+
A Record of Processing Activities — an inventory of what personal data you process, for what purpose, and where it flows. It is both a requirement for many organisations and the practical foundation of a GDPR programme.
How does GDPR relate to India's DPDPA?+
Both protect personal data and share core principles, so much groundwork transfers. But they are distinct laws with different definitions, consent mechanics and enforcement, so map obligations across both rather than assuming equivalence.