Skip the reading? Connect your stack and get a readiness score today. Plans from $79 a month, prices published.
A GDPR compliance checklist for a small or mid-size company covers twelve things: data mapping, lawful basis, Article 30 records, privacy notices, DPAs with vendors, a DSAR process, a 72-hour breach plan, security measures, the DPO question, international transfers, retention, and training. Work them in this order and each step feeds the next.
Who this applies to
The GDPR applies if you are established in the EU, or if you offer goods or services to people in the EU or monitor their behavior, regardless of where your company sits. A 40-person US SaaS company with EU users is in scope. Fines scale to the higher of 20 million EUR or 4% of global annual revenue for the most serious infringements, but for small companies the more immediate pressure is usually enterprise customers refusing to sign without evidence of compliance.
The 12-step GDPR compliance checklist
- Map your personal data. List every category of personal data you hold (customers, users, employees, prospects), where it lives, where it flows, and who touches it. Every later step depends on this inventory being honest.
- Assign a lawful basis to every processing activity. Article 6 gives six: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Most SaaS processing rests on contract or legitimate interests; marketing email usually needs consent. Document the basis per activity, and run a legitimate interests assessment where you rely on that basis.
- Create your Article 30 records of processing activities (RoPA). A structured register of what you process, why, the categories of data and recipients, transfers, retention, and security measures. Companies under 250 employees get a partial exemption, but it falls away for non-occasional processing, which describes nearly every software company, so build the RoPA anyway.
- Publish accurate privacy notices. Articles 13-14 require you to tell people what you collect, why, the lawful basis, recipients, retention, and their rights, at the point of collection, in plain language. Regenerate the notice whenever the RoPA changes.
- Put DPAs in place with every processor. Article 28 requires a data processing agreement with each vendor that processes personal data for you: hosting, analytics, email, support tooling, payroll. Most established vendors offer one; your job is to track that each is signed and current, which is a straightforward job for an obligation tracker.
- Build a DSAR process. People can ask for access, correction, deletion, portability, restriction, and objection. You generally have one month to respond, extendable by two for complex requests. Define intake, identity verification, where to search (your data map again), and who approves the response.
- Write and rehearse a breach response plan. Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a notifiable breach; Article 34 adds notifying affected individuals when the risk is high. Seventy-two hours is brutally short without a decided-in-advance plan: who declares, who drafts, who notifies. Run a tabletop exercise once a year and keep the internal breach register even for incidents you decide are not notifiable.
- Implement Article 32 security measures. Security "appropriate to the risk": encryption at rest and in transit, access control, testing, backups, resilience. If you are also pursuing SOC 2 or ISO 27001, that control work largely satisfies Article 32; cross-mapping stops you doing it twice.
- Answer the DPO question deliberately. Article 37 requires a data protection officer only if you are a public authority, or your core activities involve large-scale regular monitoring or large-scale special-category data. Most small B2B SaaS companies do not need one, but must document that reasoning. If you are outside the EU and in scope, check whether you need an EU representative under Article 27 as well.
- Handle international transfers. Transfers out of the EU need a mechanism: an adequacy decision (including the EU-US Data Privacy Framework for certified US companies), standard contractual clauses, or binding corporate rules. Record the mechanism per vendor in your RoPA.
- Set and enforce retention periods. Storage limitation means data goes away when the purpose ends. Define retention per data category and actually delete; "we keep everything forever" is the most commonly self-reported gap.
- Train the team and assign owners. Everyone who touches personal data should know how to spot a DSAR and a breach. Each checklist item above needs a named owner and a review date, because GDPR compliance decays without maintenance.
GDPR compliance checklist for US companies
US companies fall under GDPR when they offer goods or services to people in the EU or monitor the behavior of people in the EU, regardless of where the company is based. A US SaaS company with EU users, an ecommerce store that ships to Europe, or an analytics tool that tracks EU visitors is in scope. The 12 steps above still apply, but three of them carry extra weight for a US business:
- Article 27 EU representative. If you have no EU establishment but process EU personal data on more than an occasional basis, you generally must appoint a representative located in an EU member state and name them in your privacy notice. Confirm whether the limited exemptions apply before you decide to skip it.
- International transfer mechanism. Moving EU personal data to US servers is a restricted transfer. Certify under the EU-US Data Privacy Framework, or sign standard contractual clauses and run a transfer impact assessment. Record the mechanism you rely on for each vendor and each data flow.
- Reconcile GDPR with US state privacy laws. Most US companies in GDPR scope also fall under state laws like the CCPA and CPRA in California, plus similar statutes in Virginia, Colorado, and Connecticut. Build one data map and one rights process that satisfy both, rather than running parallel programs, because the underlying obligations overlap heavily.
The practical order for a US company is: confirm scope honestly, map your data, fix the lawful basis and transfer mechanism, then work the rest of the checklist. Do not assume being outside the EU puts you outside the regulation.
GDPR compliance checklist for suppliers and vendors
If you are a supplier that processes personal data on behalf of business customers, you are a processor under GDPR, and your customers will push their obligations down to you in contracts and security questionnaires. Expect to sign a data processing agreement under Article 28, document your sub-processors, prove Article 32 security measures, support your customer's data subject requests, and notify them without undue delay after a breach. The fastest way to clear a customer's supplier review is to have your DPA template, sub-processor list, and a current SOC 2 or ISO 27001 report ready before they ask, which is the same preparation that makes security questionnaires a lookup instead of a fire drill. Managing that flows naturally out of a vendor risk management program, applied to your own upstream vendors, and out of the evidence you already collect for security frameworks.
Do you need a data protection officer?
Most US companies do not. Article 37 makes a DPO mandatory in three cases: you are a public authority, your core activities require regular and systematic monitoring of people on a large scale, or your core activities involve large-scale processing of special-category data such as health, biometric, or criminal-offense data. A 60 person B2B SaaS company processing ordinary business-contact data usually falls outside all three.
Falling outside them does not remove the work, it removes the title. You still need someone accountable for privacy, and appointing a DPO voluntarily has a real consequence: once you designate one publicly, the Article 38 and 39 obligations attach, including independence and a direct reporting line to senior management. The practical middle path most small companies take is naming a privacy owner internally without the formal DPO designation. If you are working through a DPO checklist, the substance is the same list either way: maintain the RoPA, advise on data protection impact assessments, act as the contact point for supervisory authorities and data subjects, and monitor compliance with a documented review cadence.
What a GDPR Article 32 checklist covers
Article 32 is the security-of-processing article, and it is the one your customers' security questionnaires actually test. It asks for measures appropriate to the risk, and names four in particular: pseudonymization and encryption where appropriate, ongoing confidentiality, integrity, availability, and resilience of processing systems, the ability to restore availability after an incident, and a process for regularly testing and evaluating the effectiveness of those measures.
That last one catches people out. Article 32 does not just want controls in place, it wants evidence you test them. In practice an Article 32 checklist means encryption in transit and at rest, access control with least privilege, logging and monitoring, tested backups with a documented restore, vulnerability management, and a security testing cadence you can show records for. If you already run SOC 2 or ISO 27001, you have almost all of this: Article 32 maps closely onto SOC 2 CC6 and the ISO 27001 Annex A technological controls, which is why one control library covering several frameworks saves rebuilding the same evidence per regulation.
What a GDPR Article 28 checklist covers
Article 28 governs the relationship between a controller and its processors, meaning every vendor that touches personal data on your behalf. The contract has to be in writing and must cover a defined list: the subject matter and duration, the nature and purpose of processing, the type of personal data and categories of data subjects, processing only on documented instructions, confidentiality commitments from personnel, Article 32 security measures, rules for engaging sub-processors with your authorization, assistance with data subject requests and breach notification, deletion or return of data at the end of the contract, and the right to audit.
Operationally this is vendor management wearing a legal hat. You need a current list of processors, a signed data processing agreement for each, a record of sub-processors, and a review date. That is the same inventory a security framework asks for under SOC 2 CC9.2 and ISO 27001 A.5.19 to A.5.22, which is why it is worth deciding once whether you need third-party risk management software or whether the vendor register in your compliance platform covers it.
GDPR compliance checklist for small businesses
The obligations do not scale down much, but two things genuinely do. Article 30(5) exempts organizations with fewer than 250 employees from maintaining full records of processing activities, unless the processing is likely to result in a risk to individuals, is not occasional, or involves special-category data. Read the exceptions carefully, because routine customer data processing is rarely occasional, so most small companies end up maintaining a RoPA anyway. The second is proportionality: Article 32 asks for measures appropriate to the risk, so a 15 person company is not held to an enterprise security program.
The realistic small-business sequence is: work out whether GDPR applies to you at all, map what personal data you hold and why, fix your lawful basis and privacy notice, get DPAs signed with your processors, put a DSAR process and a 72 hour breach process in writing, and set a review date. That is a few weeks of focused work, not a year.
If you are weighing tooling rather than doing it by hand, we compare the eight products that get recommended for this in best GDPR compliance software, including which of them publish a price.
Should you run this as a spreadsheet?
A spreadsheet is a reasonable place to start, and plenty of teams do their first pass in one. It stops working for a specific reason: nothing in a spreadsheet chases anyone. DPAs expire, sub-processor lists change when a vendor switches infrastructure, privacy notices go stale after a product launch, and nobody notices until a customer's security review surfaces it. The failure is never the format, it is that the rows have no owners and no due dates.
If you keep a spreadsheet, at minimum give every row a named owner and a next-review date, and put those dates somewhere that actually alerts someone. If GDPR sits alongside SOC 2 or ISO 27001 for you, keeping all three in one control library avoids maintaining the same encryption and access-control evidence three times under three different article numbers. Our walkthrough of tracking compliance in Excel covers where the spreadsheet approach holds up and where it breaks.
Keeping it alive after the checklist
GDPR is not a one-time project. New vendors need DPAs, new features change the RoPA, notices drift out of date, and the breach plan needs an annual rehearsal. A quarterly compliance calendar with owners per item is the difference between "we did GDPR in 2025" and being able to answer a customer's security questionnaire this week. Evidence matters too: signed DPAs, DSAR logs, and training records are what you will actually be asked to produce; our guide to audit evidence examples shows what good records look like.
One boundary worth stating plainly: a checklist like this, and any software that operationalizes it, assists with the workflow. It is not legal advice, and edge cases (special-category data, minors, novel transfers) deserve a privacy lawyer's eyes.
Running the checklist in one place
Every item here is an obligation with an owner, a due date, and evidence: exactly the shape Complies is built around. It tracks your GDPR obligations on a compliance calendar, cross-maps Article 32 security work against SOC 2 and ISO 27001 so overlapping controls count once, drafts policies and notices for a human to approve, and shows a live readiness score. Prices are published from $79 per month, self-serve, no sales call. See how GDPR compliance software keeps the twelve steps from decaying, and get started with the data map.
RUN IT, NOT JUST READ IT
Turn this into tracked rows with owners
Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.