GDPR implementation feels open-ended until you sequence it. The work doesn't vanish, but a structured quarter turns "we should sort out data protection" into a finished, audit-ready baseline. This roadmap lays out exactly what to do in each phase - map first, evidence the security layer, then close the high-risk items - with a named owner driving it. For the overview and a self-score, start at the GDPR compliance checklist pillar.
- 90 structured days gets a typical SME to a defensible baseline; without a plan it takes three to four times as long.
- Sequence matters: map and build the ROPA first, then security and vendors, then high-risk and ownership.
- One named owner is the difference between a plan that lands and one that stalls.
Days 1-30: Map and Build the ROPA
What's the first month for?
Visibility. You can't protect or document what you can't see. In the first 30 days:
- Build a complete tool inventory - every system that touches personal data, including Shadow IT.
- Create the first ROPA entries for your highest-volume processes (marketing, HR, support).
- Review your privacy notice against that inventory.
Outcome: you know what data lives where, and your central record exists.
Days 31-60: Evidence the Security and Vendor Layer
What does the second month cover?
- Document your TOM - specific encryption, access control, backups, logging.
- Check every external vendor and sign the missing DPAs.
- Define your breach process against the 72-hour window (Art. 33).
Outcome: your security and processor layer is evidenced, not assumed.
Days 61-90: Close High-Risk Items and Assign Ownership
What finishes the baseline?
- Run a DPIA for any high-risk processing, especially AI-assisted decisions about people (Art. 35).
- Close open items from the first two phases.
- Assign a named owner for each area and set the first scheduled review.
Outcome: a maintainable, audit-ready baseline - and a process that keeps it current.
30-60-90-Day GDPR Plan (DOCX)
Keeping It Going After Day 90
Is compliance "done" at day 90?
No - it's maintained. The baseline is the hard part; keeping it current is a rhythm: update on every new tool or vendor, run a quarterly mock check, and do one full review a year. A platform that flags entries for review when they age out removes most of the manual tracking.
ETHYX runs this roadmap as an ongoing system - guided workflows for each phase and automatic review reminders, so the baseline you build in 90 days stays current instead of decaying.