Skip to content
Case studiesPricingSecurityCompareBlog

Europe

Americas

Oceania

Resources

GDPR Document Compliance Checklist

Complete list of documents and processes to implement for GDPR-compliant document processing, covering consent, storage, data subject rights, and impact assessments.

19 itemsโ€ข17 required

Consent Management

Up-to-date privacy policyRequired

Accessible document describing purposes, legal bases, retention periods, and data subject rights.

Reference: GDPR Art. 13-14
Consent collection formsRequired

Explicit, granular, and documented consent mechanisms for each processing purpose.

Reference: GDPR Art. 7
Cookie policyRequired

Cookie banner and detailed policy with opt-in management compliant with ePrivacy regulations.

Reference: ePrivacy Directive / ICO
Consent proof registryRequired

Traceability system recording who consented, when, to what, and through which mechanism.

Reference: GDPR Art. 7(1)

Data Storage and Retention

Data encryption policyRequired

Encryption at rest (AES-256) and in transit (TLS 1.2+) for all documents containing personal data.

Reference: GDPR Art. 32
Retention scheduleRequired

Table defining retention periods by document type and purpose, with automated purge procedures.

Reference: GDPR Art. 5(1)(e)
Data processing map (ROPA)Required

Comprehensive inventory of personal data flows, systems involved, and third-party processors.

Reference: GDPR Art. 30
Data localisation documentationRequired

Records of server locations and verification of compliance for cross-border data transfers.

Reference: GDPR Art. 44-49

Data Subject Rights

DSAR handling procedureRequired

Formalised process for responding to data subject access requests within the one-month deadline.

Reference: GDPR Art. 15
Data portability mechanismRequired

Capability to export personal data in a structured, commonly used, machine-readable format.

Reference: GDPR Art. 20
Erasure procedure (right to be forgotten)Required

Documented process for deleting data on request, including copies and backups.

Reference: GDPR Art. 17
Request tracking register

Timestamped log of all data subject rights requests with status and response timelines.

Reference: GDPR Art. 12

DPO and Governance

DPO appointmentRequired

Formal designation of a Data Protection Officer, registered with the supervisory authority.

Reference: GDPR Art. 37
Published DPO contact detailsRequired

DPO contact information accessible on the website and within the privacy policy.

Reference: GDPR Art. 37(7)
DPO and staff training plan

Ongoing training programme for the DPO and regular awareness sessions for all staff.

Reference: GDPR Art. 39(1)(b)

Data Protection Impact Assessment (DPIA)

DPIA for high-risk processingRequired

Impact assessment for processing activities that pose a high risk to individuals' rights and freedoms.

Reference: GDPR Art. 35
Risk mitigation planRequired

Technical and organisational measures identified to reduce risks to an acceptable level.

Reference: GDPR Art. 35(7)(d)
DPIA documentation and reviewRequired

Archived assessment with periodic review triggered by significant changes to the processing.

Reference: GDPR Art. 35(11)
Breach notification procedureRequired

Action plan for data breaches: notify the supervisory authority within 72 hours and inform affected individuals.

Reference: GDPR Art. 33-34

Automate this checklist

CheckFile automatically verifies every document on the list.