GDPR checklist

The GDPR obligations EU supervisory authorities expect.

The lawful-basis register, the data-subject rights walk-through, and the SCCs + transfer-impact assessment the EU supervisory authority expects when US mid-market teams process EU data. The full Article-30 record-of-processing format and the 72-hour breach-notification clock are written up in the long-form checklist.

Article 30 · lawful basis · 72-hour breach clock

What “GDPR-ready” looks like

A working GDPR program at the Tier 2 / Tier 3 stack covers the Article 30 record-of-processing activities (RoPA), the lawful-basis register per processing purpose, the data-subject rights response workflow (access, erasure, portability), and the 72-hour breach-notification clock that drives most of the operational risk when a US team processes EU personal data.

The full checklist — the RoPA template, the standard-contractual-clauses (SCC) addendum stack, and the transfer-impact-assessment (TIA) format — is being written up against the founder’s first reviewer round. For now, the hub at /resources indexes all four framework checklists; GDPR ships as an add-on at the $8K and $20K tier.

See pricing →

More frameworks

See all checklists →

HIPAA, SOC 2, PCI DSS, GDPR — pick by the framework your auditor opens on first.