GDPR Compliance Checklist
Every GDPR duty a small business has, with its article — and a plan for what is left.
Checks
Preview
Highlighted hints mark fields you have not filled in; downloads and printouts show a blank line there instead. To print, choose your printer or “Save as PDF” and turn off “Headers and footers”.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the GDPR Compliance Checklist
The GDPR applies to organisations in the EU and to businesses anywhere — including in India — that offer goods or services to people in the EU or monitor their behaviour; the UK GDPR does the same for the UK. Both expect you to show that you comply, and the most common gaps are the same: no record of processing, no documented lawful basis, privacy notices that leave things out, processors without a proper contract, and no plan for a breach.
This checklist goes through the duties a small business has — lawful basis, privacy notices, records of processing, DPIAs, processor contracts, security, breach reporting within 72 hours, international transfers, people’s rights and whether you need a DPO — each with its article reference and fine tier. Answer a few questions and only what applies is shown; the UK items (the ICO fee, the complaints duty and the Data (Use and Access) Act 2025 changes) appear when you choose the UK. Mark what is done, add an owner and a target date for the rest, and export an action plan sorted by fine tier. Nothing you enter leaves your browser.
How to use it
- Choose the law that applies — EU GDPR, UK GDPR or both — and answer the questions about your organisation: size, special category data, processors, transfers, cookies, marketing.
- For each item choose Done, Partly, Not yet or N/A. For open items, add an owner, a target date and what is left to do.
- Use Show: Actions to see only what is open, and the Checks for the higher-tier gaps first.
- Download the action plan as Word, PDF, Markdown or text, or print it.
- Tick Keep a draft in this browser to continue later on the same device.
Examples
EU and UK · outside the EU/UK · processor for clients · transfers · cookies · marketing
13 of 34 done (38%), 11 not yet, 10 in progress. The plan starts with the higher-tier gaps: legitimate interests assessments (art. 6(1)(f)), the retention schedule (art. 5(1)(e)), data portability (art. 20) and the transfer risk assessment (art. 46); the UK fee and the 30-day complaints acknowledgement are listed for the UK.
UK GDPR · fewer than 250 staff · uses processors
Includes the ICO data protection fee, the complaints duty, and a note that being small does not remove the record of processing for regular activities such as payroll (art. 30(5)).
Common uses
- An Indian or other non-EU company selling to customers in the EU or the UK.
- A small business or charity checking its basics before a client’s security questionnaire.
- A SaaS provider that is a processor for its clients and a controller for its own customers.
- Turning a one-off review into a dated action plan with owners.
The two fine tiers
- Higher tier — up to €20 million (UK £17.5 million) or 4% of worldwide annual turnover, whichever is higher: the principles and lawful basis (arts. 5, 6), consent (art. 7), special category data (art. 9), people’s rights (arts. 12–22) and international transfers (arts. 44–49) — art. 83(5).
- Standard tier — up to €10 million (UK £8.7 million) or 2%: children’s consent (art. 8), data protection by design (art. 25), processors (art. 28), records (art. 30), security (art. 32), breaches (arts. 33–34), DPIAs (art. 35) and DPOs (arts. 37–39) — art. 83(4).
Authorities set each fine by the nature, gravity and duration of the infringement, intent or negligence, mitigation and cooperation (art. 83(2)), and can also order you to stop processing.
What changed in the UK
The Data (Use and Access) Act 2025 amends the UK GDPR, the Data Protection Act 2018 and PECR; the ICO confirms that all its data protection provisions are now in force. Among the changes: a list of recognised legitimate interests that needs no balancing test; request time limits that start when you can confirm the person’s identity, with the clock paused while you ask for clarification you reasonably need; only reasonable and proportionate searches for subject access requests; a duty to help people complain to you, acknowledge complaints within 30 days and reply without undue delay; wider use of solely automated decisions with safeguards; and new exceptions to cookie consent for some statistics and functionality cookies.
Do small businesses need records of processing?
Article 30(5) exempts organisations with fewer than 250 employees only when their processing is occasional, unlikely to risk people’s rights, and includes no special category or criminal offence data. Payroll, customer lists and mailing lists are regular, not occasional — so most small businesses need at least a simple record of those activities. The ICO publishes record templates for controllers and processors.
Sources
- GDPR — Regulation (EU) 2016/679 — arts. 3–8, 12–22, 24–39, 44–49, 83
- ICO: advice for small organisations; what to document under Article 30; when to do a DPIA; international transfers
- ICO: the Data (Use and Access) Act 2025 — summary of the changes
- European Commission: adequacy decisions; EDPB data protection guide for small businesses
Limitations
- A self-assessment, not an audit or legal advice; the plan reflects only the answers given.
- It covers the main duties of a small controller or processor. National laws (employment data, age of consent, ePrivacy), sector rules and authorities’ guidance can add more.
- Fine amounts are the legal maximums; actual fines depend on the case.
- Rules change: the European Commission has proposed extending the Article 30(5) exemption to organisations with fewer than 750 employees, who would keep records only of high-risk processing. Until such a change is adopted the 250-employee rule applies — review the checklist when the law changes.
Privacy
Everything happens in your browser. Your answers are not uploaded or stored by MySmartCoPilot. If you tick Keep a draft in this browser, they are saved in this browser’s local storage until you untick it.
Frequently asked questions
Does the GDPR apply to my company in India?
Yes if you offer goods or services to people in the EU — for example a website that takes orders in euros or ships to the EU — or monitor their behaviour, such as tracking EU visitors for advertising (art. 3(2)). You then usually also need an EU representative (art. 27). The UK GDPR has the same rule for the UK.
How quickly must a data breach be reported?
To the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people (art. 33). Tell the affected people too when the risk to them is high (art. 34). Log every breach either way.
Do I need a Data Protection Officer?
Only if you are a public authority, or your core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special category or criminal offence data (art. 37). Most small businesses do not — but record that decision.
How long do we have to answer a subject access request?
One month from receipt, extendable by two further months for complex or numerous requests if you tell the person within the first month (art. 12(3)). It is free unless the request is manifestly unfounded or excessive. In the UK the month starts once you have what you need to confirm identity, and may pause while you ask for clarification.
Can we transfer EU personal data to India?
India has no EU adequacy decision, so you need a transfer tool — usually the European Commission’s standard contractual clauses — with an assessment of whether they can be complied with in practice, and supplementary measures where needed (arts. 44–46).