GDPR Compliance Checklist
Score your organisation's GDPR compliance across {total} items in {sections} categories. Free. Takes 10 minutes.
Identify a Lawful Basis for Each Processing Activity
Map every category of personal data your firm processes (client files, HR records, marketing) to one of the six lawful bases. Document the rationale in your Records of Processing Activities.
Conduct Legitimate Interest Assessments
For processing that relies on legitimate interests (e.g., conflict checks, business development), complete a three-part balancing test documenting the purpose, necessity, and impact on individuals.
Obtain Valid Consent Where Required
When consent is the lawful basis (e.g., marketing emails, optional profiling), ensure it is freely given, specific, informed, and unambiguous. Use clear opt-in mechanisms — never pre-ticked boxes.
Maintain Auditable Consent Records
Store timestamped evidence of each consent action including the version of the notice shown, the channel used, and the specific purposes consented to. Enable retrieval for audit or DSAR response.
Enable Easy Consent Withdrawal
Provide a simple mechanism for individuals to withdraw consent at any time. Withdrawal must be as easy as giving consent and must take effect without undue delay.
Publish a Client-Facing Privacy Notice
Provide clients with a clear, concise privacy notice at the start of each engagement explaining what personal data you collect, why, how long you keep it, and their rights.
Maintain a Website Privacy Policy
Publish a comprehensive privacy policy on your firm's website covering all data processing activities — website analytics, contact forms, cookie usage, and recruitment.
Include Engagement Letter Disclosures
Integrate data protection clauses into client engagement letters specifying the controller identity, purposes of processing, data sharing with third parties, and retention periods.
Provide Employee Privacy Notices
Give staff and job applicants a dedicated privacy notice covering HR data processing — payroll, performance monitoring, background checks, and internal communications.
Disclose Third-Party Data Sharing
Clearly inform data subjects about any sharing of their personal data with barristers, experts, courts, regulators, or other third parties. Name categories of recipients.
Encrypt Personal Data at Rest and in Transit
Apply encryption to client files, databases, email communications, and portable devices. Enforce TLS 1.2+ for all data in transit and AES-256 or equivalent for data at rest.
Implement Role-Based Access Controls
Restrict access to personal data based on job function using the principle of least privilege. Maintain access logs and review permissions quarterly.
Establish a Data Breach Response Plan
Document a clear incident response procedure. Notify the supervisory authority within 72 hours of becoming aware of a qualifying breach. Inform affected individuals without undue delay when there is a high risk.
Conduct Regular Security Testing
Perform periodic vulnerability assessments and penetration tests on systems that process personal data. Address findings promptly and document remediation.
Secure Physical and Remote Access
Protect physical premises with appropriate access controls. For remote work, enforce VPN usage, multi-factor authentication, and endpoint security on all devices accessing client data.
Implement a DSAR Handling Process
Establish a documented procedure to receive, verify, and respond to data subject access requests within one calendar month. Train staff to recognise and escalate requests promptly.
Support Rectification and Erasure Requests
Enable individuals to correct inaccurate data and request deletion. Document lawful grounds for refusal (e.g., legal obligation to retain) and communicate these clearly.
Facilitate Data Portability
Where processing is based on consent or contract, provide personal data in a structured, commonly used, machine-readable format (CSV, JSON) upon request.
Honour the Right to Object
Stop processing personal data for direct marketing immediately upon objection. For other objections based on legitimate interests, assess whether compelling grounds override the individual's interests.
Review Automated Decision-Making
If your firm uses automated profiling or decision-making that significantly affects individuals, provide meaningful information about the logic involved and offer the right to human review.
Maintain Records of Processing Activities
Keep a comprehensive ROPA documenting every processing activity — purpose, categories of data, recipients, retention periods, and technical and organisational security measures.
Appoint or Assess the Need for a DPO
Determine whether your firm is required to appoint a Data Protection Officer. If appointed, ensure they have sufficient resources, independence, and direct reporting to senior management.
Conduct Data Protection Impact Assessments
Perform a DPIA before any processing likely to result in high risk to individuals — large-scale profiling, systematic monitoring, or processing of special category data.
Manage Third-Party Processors
Execute Data Processing Agreements with all processors (IT providers, cloud services, external counsel). Audit processor compliance regularly and maintain a register of all sub-processors.
Implement Staff Training and Policies
Deliver mandatory data protection training to all staff at induction and annually. Maintain written policies for data handling, clean desk, acceptable use, and incident reporting.
Map All International Data Flows
Identify every transfer of personal data outside the EEA — cloud hosting, cross-border litigation support, international co-counsel. Document the destination country and legal basis for each transfer.
Implement Appropriate Transfer Safeguards
For transfers to countries without an adequacy decision, put Standard Contractual Clauses or Binding Corporate Rules in place. Conduct Transfer Impact Assessments where required.
Identify and Protect Special Category Data
Recognise when you process special category data (health records, criminal offence data, racial or ethnic origin) in litigation or advisory work. Apply enhanced safeguards and document the Art. 9 condition relied upon.
Define and Enforce Data Retention Schedules
Set clear retention periods for each data category — client files, financial records, HR data. Implement automated deletion or anonymisation when retention periods expire.
Apply Data Minimisation Principles
Collect only the personal data strictly necessary for each purpose. Review intake forms, data collection practices, and legacy databases. Purge unnecessary data regularly.
Save your results
Get your {score}% compliance score and a personalised report emailed to you, plus weekly GDPR insights to help you improve.
No spam. Unsubscribe anytime. We respect your privacy.
Want to automate these checks?
PrivacyForge handles consent management, data mapping, DSAR workflows, and audit-ready reports — so you can stop checking boxes manually.
Start Free Trial — No Card RequiredThis checklist is for informational purposes only and does not constitute legal advice. Consult a qualified data-protection professional to ensure full compliance.