Templates
Information Security
GDPR Compliance Checklist for US Companies
🔒

GDPR Compliance Checklist for US Companies

1
Identify the scope of personal data processed by the company
2
Assign a Data Protection Officer
3
Conduct Data Protection Impact Assessment
4
Implement techniques to pseudonymize and encrypt personal data
5
Develop procedures for data subject rights
6
Create a plan for managing data breaches
7
Review third-party service providers for GDPR compliance
8
Establish data retention and deletion policies
9
Legal basis - document justifications for processing personal data
10
Approval: Legal counsel's review of data processing justifications
11
Implement consent mechanisms for data collection
12
Update privacy policies and terms of service
13
Design processes for children's data protection
14
Conduct GDPR training for employees
15
Implement ongoing GDPR compliance auditing
16
Approval: Executive team's review of GDPR compliance status
17
Create records of processing activities
18
Implement data protection 'by design and by default'
19
Prepare process to respond to data subject's requests
20
Approval: Data Protection Officer's review of GDPR implementation