Checklist · 17 items · Updated July 2026

GDPR Compliance Checklist

Privacy that survives procurement.

For SaaS companies, GDPR shows up as procurement friction long before regulators do — a customer's counsel reviewing your DPA, sub-processor list, and transfer mechanism. This checklist is ordered for that reality.

01 Map the data

  • Build the record of processing activities (RoPA): what personal data, whose, why, where
  • Classify your role per product flow: processor for customer data, controller for your own marketing and HR
  • Assign a lawful basis to every controller-side processing activity
  • Determine whether you need a DPO or an EU representative, and appoint if so

02 Paper the processing chain

  • Publish a standard DPA and incorporate it into your terms
  • Maintain a public sub-processor list with a change-notification mechanism
  • Flow down GDPR obligations to every sub-processor via their DPAs
  • Implement a transfer mechanism for EU data reaching the US (SCCs and a transfer impact assessment)
  • Align your privacy policy with what your systems actually do

03 Operationalize rights and consent

  • Build a data-subject request process: access, deletion, export, rectification — with a 30-day clock
  • Test deletion end-to-end, including backups policy and vendor propagation
  • Implement consent management for marketing and non-essential cookies
  • Apply data minimization and retention schedules — delete what you no longer need

04 Secure and prepare for breach

  • Implement Article 32 security measures: encryption, access control, resilience, testing
  • Write the personal-data breach procedure with the 72-hour supervisory notification clock
  • Run DPIAs for high-risk processing (new AI features frequently trigger this)
  • Train staff who touch personal data, with records

The pattern we see in security reviews: companies fail GDPR questions not on security but on operations — a deletion request that can’t actually propagate, a sub-processor list that’s two acquisitions stale, an SCC package nobody can produce. The paperwork items on this list are cheap until the moment they’re urgent.

Don't Want to Run This Yourself?

Security Questionnaire Support

We answer your enterprise security questionnaires — SIG, CAIQ, and custom 200-question reviews — accurately, fast, and backed by real evidence from your platform.

Book a Call
Frequently Asked
Does GDPR apply to us if we have no EU entity?

If you offer services to people in the EU or monitor their behavior, yes — establishment isn't the test. For B2B SaaS the practical trigger is simpler: your first EU customer's procurement team will require GDPR terms regardless.

GDPR certification — is that a thing?

There's no general GDPR certificate. Approved certification schemes exist in a few member states but are rare in practice. Buyers rely on your DPA, sub-processor transparency, and evidence of the items on this list.

How does GDPR relate to SOC 2 or ISO 27001?

Article 32's security requirements overlap heavily with both — an ISO 27001 ISMS is strong evidence of 'appropriate technical and organisational measures.' The privacy-specific machinery (lawful bases, rights, transfers) has no SOC 2/ISO equivalent and needs its own checklist — this one.