GDPR Compliance Checklist

Work through each category to audit your data protection practices. Your progress is saved automatically in your browser.

This checklist is a practical guide, not legal advice. Consult a qualified data protection professional for your specific situation.

0%
0 of 25 items complete
Start checking items to track your GDPR compliance.
Lawful Basis & Consent
0/5
Privacy Notice
0/5
Data Subject Rights
0/5
Data Security
0/5
Records & Accountability
0/5
Advertisement
About this GDPR compliance checklist

This interactive GDPR compliance checklist walks you through the most common data protection obligations across five key areas — lawful basis and consent, privacy notices, data subject rights, data security, and records and accountability — so you can audit your website or business and see exactly where the gaps are.

The General Data Protection Regulation sets a high bar for how organisations collect, store, and use personal data belonging to people in the EU and EEA. Working through a structured checklist is one of the simplest ways to turn that broad obligation into concrete, reviewable actions: each item is a plain-language statement you can confidently tick once it is genuinely in place. As you check items off, the tool tracks your progress with a live score for every category and an overall completion percentage, giving you an at-a-glance picture of your data protection posture and a clear list of what still needs attention. People use it to:

Everything runs locally in your browser — nothing you tick is ever uploaded to a server, and your progress is saved automatically so you can return and pick up where you left off. Please treat this checklist as an educational guide to help you spot common obligations, not as legal advice. GDPR applies differently depending on what data you handle, where, and why, so for your specific circumstances you should always confirm your obligations with a qualified data protection professional or solicitor.

How to use
  1. Read the disclaimer at the top — this is a practical guide, not legal advice.
  2. Click any category header to expand its checklist of GDPR obligations.
  3. Tick off each item once it is genuinely in place — your score and category bars update live.
  4. Progress saves automatically in your browser, so you can close the tab and return later.
  5. Use Export as Text to download a plain-text summary for your team or DPO.
FAQ

GDPR (General Data Protection Regulation) is the EU's data privacy law. It applies to any organisation — regardless of where it is based — that processes personal data of people in the EU or EEA, including websites that use analytics, cookies, or collect email addresses from EU visitors.

No. It's a practical overview of common GDPR obligations to help you identify gaps. For your specific situation always consult a qualified data protection professional or solicitor.

Your checked items are saved in your browser's localStorage under the key hub-gdpr-v1. Nothing is uploaded to any server. Use Reset all to clear progress.

Quite possibly. GDPR has no business-size exemption — it applies whenever you process personal data of people in the EU or EEA. A small online shop, blog, or app that collects emails, runs analytics, or sets cookies for EU visitors falls within scope, though some lighter record-keeping rules apply to organisations under 250 staff.

A Data Protection Officer is a person responsible for overseeing an organisation's data protection strategy and GDPR compliance. A DPO is mandatory for public authorities and for organisations whose core activities involve large-scale or systematic monitoring or special-category data. Other organisations may appoint one voluntarily as good practice.

Under GDPR you need a lawful basis before processing personal data. There are six: consent, contract, legal obligation, vital interests, public task, and legitimate interests. You should identify and document which basis applies to each processing activity, as it affects which data subject rights apply and what you must tell people.

Individuals have rights including the right to be informed, access their data, rectify inaccuracies, request erasure (the right to be forgotten), restrict or object to processing, and data portability. You generally must respond to a valid request within one month, and your processes should make it straightforward for people to exercise these rights.