A checklist is only useful if you know what "done" looks like for each line. This annotated GDPR checklist for companies goes item by item - what you need, and how you'd evidence it in an audit - then breaks it down by department, because the gaps usually sit where data is handled day to day, not in a central policy folder. For the bigger picture and a scored self-assessment, start with the GDPR compliance checklist pillar; use this page to work the detail.
- Each checklist item needs a document you can produce - "done" means evidenced, not intended.
- Gaps cluster by department: marketing, HR, sales and IT each carry typical ones.
- Use this alongside the scored self-check on the pillar page.
Company-Wide Checklist (Annotated)
What do I need, and how do I prove each item?
| Item | What to have | How to evidence it |
|---|---|---|
| Lawful basis | A basis per processing activity (Art. 6) | The basis recorded in your ROPA |
| Privacy notice | Current notice covering every processing purpose and its legal basis | Published URL + version date |
| ROPA | Complete processing register | The ROPA file, reviewed within 12 months |
| DPAs | Signed agreement per processor | Countersigned DPAs on file |
| TOM | Specific security measures | A current TOM document |
| Breach process | 72-hour notification routine | Written process + breach log |
| Data subject requests | Defined response workflow | Request log with response times |
By Department
Marketing
The usual gaps: a newsletter running on consent that was never properly captured, tracking without a valid basis, and tools (CRM, email, analytics) missing from the ROPA and the privacy notice. Evidence to hold: consent records, the legal basis per campaign, and a DPA with each platform.
HR
Applicant and employee data is sensitive and long-lived. Gaps: retention of rejected applications beyond what's justified, no basis documented for background checks, and AI-assisted screening with no DPIA. Evidence: a retention schedule, the basis per HR process, and a DPIA where AI influences decisions about people.
Sales
CRM data, call recordings and enrichment tools. Gaps: contacts added without a basis, recordings without notice, and enrichment vendors with no DPA. Evidence: the basis for prospect data, a disclosure for recordings, and signed DPAs.
IT / Operations
Owns the TOM and the breach process. Gaps: vague security measures, untested backups, and no defined 72-hour breach routine. Evidence: a specific TOM document, backup test logs, and a written incident plan.
Annotated GDPR Checklist (Excel)
How to Use This Checklist
What order do I work in?
Run the scored self-assessment first to see where you stand, then use this annotated list to close gaps in priority order - highest-risk processing first. Assign each department its own rows and a named owner; compliance decays fastest where no one owns it.
instead of a static spreadsheet, ETHYX turns this checklist into a live status across the company - which items are evidenced, which are stale, and who owns each - with a certified DPO to review the result.