GDPR Compliance Checklist

Review Date

Example Text

Company Name

John Doe

Dpo Name

John Doe

Data Mapping

Data mapping covers all processing activities across business units:
• CRM (Salesforce): Customer contact data — Lawful basis: Contract.
• Marketing Platform (HubSpot): Email lists, behavioral data — Lawful basis: Consent.
• HR System (Workday): Employee records, payroll — Lawful basis: Contract/Legal obligation.
• Analytics (Google Analytics 4): Usage data, device info — Lawful basis: Consent.
• Payment Processor (Stripe): Card data — Lawful basis: Contract. All records maintained in the Article 30 Register.

Consent Mechanisms

Our consent mechanisms include:
• Granular cookie consent banner on first website visit.
• Separate opt-in checkboxes for marketing emails and SMS communications.
• Double opt-in for newsletter subscriptions.
• Withdrawal mechanism: Users can withdraw consent at any time via Account Settings → Privacy → Manage Consent.
• Consent records are stored with timestamp, IP address, and consent text version for audit purposes.

Security Measures

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures include:
• AES-256 encryption for all data at rest.
• TLS 1.3 encryption for all data in transit.
• Role-based access control (RBAC) and least-privilege principles.
• Regular penetration testing and security audits.
• ISO 27001-compliant information security management system.

Breach Protocol

In the event of a personal data breach, we will:
1. Contain the breach and assess its scope and impact within 24 hours.
2. Notify the relevant supervisory authority within 72 hours of becoming aware (where required by GDPR).
3. Notify affected individuals without undue delay if the breach is likely to result in high risk to their rights and freedoms.
4. Document all breaches in our internal breach register regardless of notification obligations.
5. Conduct a post-incident review and implement remediation measures to prevent recurrence.
Verified & Approved By