The first year of GDPR enforcement revealed a harsh truth: most organizations weren't prepared, and many still aren't. Helen Dixon, the Irish Data Protection Commissioner, described that period as "a washing machine stuck on the spin cycle," while legal experts called it "unprecedented." The chaos stemmed not from the regulation itself, but from the gap between what teams thought they'd implemented and what supervisory authorities expected.
This checklist distills those hard-learned lessons into clear checkpoints. If you're still catching up or preparing for your next supervisory authority inquiry, use this as your baseline.
What This Checklist Covers
This is your operational readiness assessment for core GDPR obligations. It focuses on the foundational elements that supervisory authorities scrutinized most heavily during year one: lawful basis documentation, transparency obligations, data subject rights infrastructure, and breach response capability. Each item reflects expectations that emerged from real enforcement patterns, not theoretical compliance.
Prerequisites
Before you start:
- Identify your processing activities. You need a current register that maps personal data types, purposes, lawful bases, and retention periods. If you don't have this, stop here and build it first.
- Know your role. Confirm whether you're operating as controller, processor, or joint controller for each activity. Ambiguity here invalidates everything downstream.
- Assign ownership. Someone must be accountable for each checklist item. If you're a DPO, you're coordinating, not doing it all yourself.
Checklist Items
1. Lawful basis is documented and defensible for each processing purpose
Review every entry in your processing register. For each one, you should have a written justification explaining which Article 6 lawful basis applies and why. If you're relying on legitimate interests, you must have a completed legitimate interests assessment on file.
Good looks like: A product manager can't launch a new feature that processes personal data without first documenting its lawful basis and getting it reviewed. You have assessments dated before processing began, not retrofitted after a supervisory authority inquiry.
2. Consent mechanisms meet Article 7 requirements
If you're using consent as your lawful basis, verify it's freely given, specific, informed, and unambiguous. Check that consent requests are separated from other terms, use clear language, and allow granular choices where you process data for multiple purposes.
Good looks like: Your consent record includes what the person agreed to, when they agreed, and how you presented the choice. You can demonstrate withdrawal is as easy as giving consent. Pre-ticked boxes don't exist in your systems.
3. Transparency obligations are met at collection
At the point you collect personal data, you must provide specific information under Articles 13 or 14. Review your privacy notices. Do they state your identity, processing purposes, lawful bases, retention periods, data subject rights, and whether you share data with third parties?
Good looks like: Your privacy notice isn't a legal document dump. It's layered, with key information up front and details available on click-through. You've tested it with actual users, not just lawyers. You update it when processing changes, not annually by default.
4. Data subject rights infrastructure is operational
You need documented procedures and response workflows for DSARs, erasure requests, objections, rectification requests, and portability requests. Your team should know where data lives, how to retrieve it, and what exemptions might apply.
Good looks like: You've processed at least one test request through your entire workflow. Response templates exist for each right. Your one-month deadline (Article 12(3)) includes time for identity verification, data gathering, legal review, and delivery. You track requests in a system, not email threads.
5. Processor agreements contain Article 28 requirements
Every processor you use must have a written contract covering the nine mandatory elements in Article 28(3): subject matter, duration, processing nature and purpose, personal data types, data subject categories, controller obligations, processor obligations, and what happens at contract end.
Good looks like: You maintain a processor register with contract status. New vendors can't access personal data until the Article 28 agreement is signed. You've verified processors have appropriate technical and organizational measures in place, not just taken their word for it.
6. Personal data breach response plan exists and has been tested
You need a documented process for detecting, investigating, and reporting breaches. This includes knowing when the 72-hour notification window (Article 33) starts, who makes the reporting decision, and how you'll communicate with affected individuals if required (Article 34).
Good looks like: You've run a tabletop exercise. Your incident response team knows the difference between a security incident and a personal data breach. You have templates ready for both supervisory authority notifications and data subject communications. You're not figuring out your DPC contact details at 2am.
7. Cross-border transfer mechanisms are documented and current
If you transfer personal data outside the EEA, you need a valid transfer mechanism under Chapter V. Review every transfer. Are you using Standard Contractual Clauses? Adequacy decisions? Binding corporate rules? Have you completed transfer impact assessments where required?
Good looks like: You know which cloud regions your data sits in. Your SCCs are the current versions, not the old ones. If you're relying on adequacy, you're monitoring for changes (remember Privacy Shield). You've documented why each transfer is necessary.
8. Records of processing activities are maintained
Article 30 requires you to maintain records describing your processing activities. This isn't your privacy notice; it's your internal register showing what data you process, why, who you share it with, and how long you keep it.
Good looks like: Your Article 30 records are in a structured format (spreadsheet or system), not scattered across documents. They're reviewed quarterly, not when someone asks for them. New processing activities trigger an update before launch, not after.
Common Mistakes
Treating compliance as a one-time project. Organizations that stopped after May 2018 fell behind immediately. GDPR compliance is operational, not a launch milestone.
Assuming silence means approval. Many teams interpreted lack of enforcement action as validation of their approach. Supervisory authorities were building capability and prioritizing cases. Your turn may still be coming.
Copying someone else's documentation. Your legitimate interests assessment or privacy notice must reflect your actual processing. Templates are starting points, not solutions.
Next Steps
Run through this checklist with your team. For any item you can't confidently mark done, schedule the work now. The second year of GDPR brought more sophisticated enforcement. The third year brought cross-border cooperation between supervisory authorities. You're not preparing for year one anymore; you're preparing for mature, coordinated oversight.
If multiple items need work, prioritize based on your risk profile: high-volume processing, sensitive data categories, or previous supervisory authority contact should move to the front of the queue. Don't try to fix everything simultaneously. Pick three items, get them to "good," then move to the next three.
The washing machine is still spinning. The question is whether you're ready for the cycle you're in.



