- Supports risk-based security checks for confidentiality, integrity, availability, and technical and organisational measures.
"confidentiality, integrity and availability"
Check whether a product, service, vendor, dataset, or workflow has the GDPR basics covered: scope, role, lawful basis, transparency, rights, DPIA, RoPA, contracts, transfers, breach response, retention, security, and accountability evidence.
Built from official EU text and regulator guidance; designed for privacy, legal, product, security, procurement, support, HR, marketing, and data governance teams.
Structured answer sets in this page tree.
Cited legal and guidance references.
Review this checklist before launching or materially changing processing of . It connects each purpose and lawful basis to the operational records that prove the decision, including rights handling, the RoPA, any required DPIA, processor and transfer files, breach decisions, retention rules, and security evidence. It does not replace case-specific legal analysis.
Start by proving that the activity is or is not GDPR processing. Record the , data subjects, processing operations, controller or processor role, establishment or EU-targeting facts, and whether any special category or criminal-offence data is involved.
For each purpose, assign one Article 6 lawful basis before collection or use. If consent is used, keep the consent wording, capture event, withdrawal route, and evidence that consent was freely given, specific, informed, and unambiguous. If legitimate interests is used, keep the interest, necessity analysis, balancing outcome, safeguards, and objection route. Article 9 special-category processing needs both an Article 6 basis and a separate Article 9(2) condition; Article 10 criminal-offence processing has its own authority and safeguard requirements.
Create a rights workflow that can receive, authenticate, triage, fulfil, refuse, or extend requests without relying on ad hoc inbox searches. Ask for additional identity information only when there are reasonable doubts about identity, and keep the request open across the channels the organisation has designated. The access workflow should cover confirmation of processing, the itself, required processing information, transfer safeguards, and a copy of the data where required.
Keep the RoPA close to the actual processing inventory. A useful controller RoPA is not a policy pointer; it lists processing purposes, data subject categories, categories, recipient categories, transfers, envisaged erasure time limits where possible, and a general description of security measures where possible. Processor records need their separate Article 30(2) fields.
Treat DPIA, vendor, transfer, and incident checks as launch gates. They should be complete before high-risk processing begins, before a processor receives data, before a third-country transfer starts, and before incident teams need to make 72-hour notification decisions.
Do not treat SCCs as a signature-only exercise. First identify whether is transmitted or otherwise made available by an exporter subject to the GDPR to a different controller or processor in a third country or international organisation. The transfer record should then identify the exporter, importer, countries, data, transfer tool, SCC module and annexes, assessment, supplementary measures, and review trigger for legal or technical changes that could affect the transfer.
Close the checklist only when the evidence shows both compliance design and operating reality. For each processing activity, keep the source citation, control owner, reviewer, decision date, implementation proof, open exception, and reopening trigger together. A policy or contract proves design only; sample records, configured controls, logs, deletion results, response files, or test results show whether the process operates.
Security evidence should be risk-based. Article 32 points to measures such as pseudonymisation, encryption, confidentiality, integrity, availability, resilience, restoration capability, and regular testing, but the selected controls must fit the nature, scope, context, purposes, and risk of the processing.
Sorena can turn the GDPR checks on this page into cited tasks, owner assignments, evidence requests, and reusable review records for privacy, product, security, vendor, and support teams.
Ask questions tied to cited sources about GDPR scope, lawful basis, DSARs, DPIAs, RoPA, processors, transfers, breach handling, and evidence using the cited sources on this page.
Review your GDPR checklist owners, source support, transfer records, processor contracts, and evidence gaps with Sorena.
"confidentiality, integrity and availability"
"Standard Contractual Clauses"
"high risk processing projects"
"living and dynamic document"
"able to demonstrate compliance"