Complies
GDPR CHECKLISTS

GDPR Compliance Checklist: 12 Steps for Small and Mid-Size Companies

MAY 2026 · 10 MIN READ · BY THE COMPLIES TEAM

A GDPR compliance checklist for a small or mid-size company covers twelve things: data mapping, lawful basis, Article 30 records, privacy notices, DPAs with vendors, a DSAR process, a 72-hour breach plan, security measures, the DPO question, international transfers, retention, and training. Work them in this order and each step feeds the next.

Who this applies to

The GDPR applies if you are established in the EU, or if you offer goods or services to people in the EU or monitor their behavior, regardless of where your company sits. A 40-person US SaaS company with EU users is in scope. Fines scale to the higher of 20 million EUR or 4% of global annual revenue for the most serious infringements, but for small companies the more immediate pressure is usually enterprise customers refusing to sign without evidence of compliance.

The 12-step GDPR compliance checklist

  1. Map your personal data. List every category of personal data you hold (customers, users, employees, prospects), where it lives, where it flows, and who touches it. Every later step depends on this inventory being honest.
  2. Assign a lawful basis to every processing activity. Article 6 gives six: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Most SaaS processing rests on contract or legitimate interests; marketing email usually needs consent. Document the basis per activity, and run a legitimate interests assessment where you rely on that basis.
  3. Create your Article 30 records of processing activities (RoPA). A structured register of what you process, why, the categories of data and recipients, transfers, retention, and security measures. Companies under 250 employees get a partial exemption, but it falls away for non-occasional processing, which describes nearly every software company, so build the RoPA anyway.
  4. Publish accurate privacy notices. Articles 13-14 require you to tell people what you collect, why, the lawful basis, recipients, retention, and their rights, at the point of collection, in plain language. Regenerate the notice whenever the RoPA changes.
  5. Put DPAs in place with every processor. Article 28 requires a data processing agreement with each vendor that processes personal data for you: hosting, analytics, email, support tooling, payroll. Most established vendors offer one; your job is to track that each is signed and current, which is a straightforward job for an obligation tracker.
  6. Build a DSAR process. People can ask for access, correction, deletion, portability, restriction, and objection. You generally have one month to respond, extendable by two for complex requests. Define intake, identity verification, where to search (your data map again), and who approves the response.
  7. Write and rehearse a breach response plan. Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a notifiable breach; Article 34 adds notifying affected individuals when the risk is high. Seventy-two hours is brutally short without a decided-in-advance plan: who declares, who drafts, who notifies. Run a tabletop exercise once a year and keep the internal breach register even for incidents you decide are not notifiable.
  8. Implement Article 32 security measures. Security "appropriate to the risk": encryption at rest and in transit, access control, testing, backups, resilience. If you are also pursuing SOC 2 or ISO 27001, that control work largely satisfies Article 32; cross-mapping stops you doing it twice.
  9. Answer the DPO question deliberately. Article 37 requires a data protection officer only if you are a public authority, or your core activities involve large-scale regular monitoring or large-scale special-category data. Most small B2B SaaS companies do not need one, but must document that reasoning. If you are outside the EU and in scope, check whether you need an EU representative under Article 27 as well.
  10. Handle international transfers. Transfers out of the EU need a mechanism: an adequacy decision (including the EU-US Data Privacy Framework for certified US companies), standard contractual clauses, or binding corporate rules. Record the mechanism per vendor in your RoPA.
  11. Set and enforce retention periods. Storage limitation means data goes away when the purpose ends. Define retention per data category and actually delete; "we keep everything forever" is the most commonly self-reported gap.
  12. Train the team and assign owners. Everyone who touches personal data should know how to spot a DSAR and a breach. Each checklist item above needs a named owner and a review date, because GDPR compliance decays without maintenance.

GDPR compliance checklist for US companies

US companies fall under GDPR when they offer goods or services to people in the EU or monitor the behavior of people in the EU, regardless of where the company is based. A US SaaS company with EU users, an ecommerce store that ships to Europe, or an analytics tool that tracks EU visitors is in scope. The 12 steps above still apply, but three of them carry extra weight for a US business:

  • Article 27 EU representative. If you have no EU establishment but process EU personal data on more than an occasional basis, you generally must appoint a representative located in an EU member state and name them in your privacy notice. Confirm whether the limited exemptions apply before you decide to skip it.
  • International transfer mechanism. Moving EU personal data to US servers is a restricted transfer. Certify under the EU-US Data Privacy Framework, or sign standard contractual clauses and run a transfer impact assessment. Record the mechanism you rely on for each vendor and each data flow.
  • Reconcile GDPR with US state privacy laws. Most US companies in GDPR scope also fall under state laws like the CCPA and CPRA in California, plus similar statutes in Virginia, Colorado, and Connecticut. Build one data map and one rights process that satisfy both, rather than running parallel programs, because the underlying obligations overlap heavily.

The practical order for a US company is: confirm scope honestly, map your data, fix the lawful basis and transfer mechanism, then work the rest of the checklist. Do not assume being outside the EU puts you outside the regulation.

GDPR compliance checklist for suppliers and vendors

If you are a supplier that processes personal data on behalf of business customers, you are a processor under GDPR, and your customers will push their obligations down to you in contracts and security questionnaires. Expect to sign a data processing agreement under Article 28, document your sub-processors, prove Article 32 security measures, support your customer's data subject requests, and notify them without undue delay after a breach. The fastest way to clear a customer's supplier review is to have your DPA template, sub-processor list, and a current SOC 2 or ISO 27001 report ready before they ask. Managing that flows naturally out of a vendor risk management program, applied to your own upstream vendors, and out of the evidence you already collect for security frameworks.

Keeping it alive after the checklist

GDPR is not a one-time project. New vendors need DPAs, new features change the RoPA, notices drift out of date, and the breach plan needs an annual rehearsal. A quarterly compliance calendar with owners per item is the difference between "we did GDPR in 2025" and being able to answer a customer's security questionnaire this week. Evidence matters too: signed DPAs, DSAR logs, and training records are what you will actually be asked to produce; our guide to audit evidence examples shows what good records look like.

One boundary worth stating plainly: a checklist like this, and any software that operationalizes it, assists with the workflow. It is not legal advice, and edge cases (special-category data, minors, novel transfers) deserve a privacy lawyer's eyes.

Running the checklist in one place

Every item here is an obligation with an owner, a due date, and evidence: exactly the shape Complies is built around. It tracks your GDPR obligations on a compliance calendar, cross-maps Article 32 security work against SOC 2 and ISO 27001 so overlapping controls count once, drafts policies and notices for a human to approve, and shows a live readiness score. Prices are published from $79 per month, self-serve, no sales call. See how GDPR compliance software keeps the twelve steps from decaying, and get started with the data map.

RUN IT, NOT JUST READ IT

Turn this into tracked rows with owners

Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.