GDPR Compliance Checklist 2026: Step-by-Step Guide
Independently fact-checked against primary sources (last audited September 11, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 11, 2026. · 27 primary sources cited on this page. How we verify our legal content

GDPR compliance under Regulation (EU) 2016/679 requires organisations to take documented action across fourteen interlocking areas, from data mapping and lawful basis identification to breach response and ongoing staff training. The accountability principle in Article 5(2) requires controllers to demonstrate compliance at any time, making a systematic, evidence-based approach the baseline obligation.
GDPR compliance is not a one-time project. The General Data Protection Regulation (Regulation (EU) 2016/679) demands documented evidence of compliance, and every change to your processing activities can trigger new obligations. This checklist covers every core compliance area, with references to the relevant GDPR articles, official EDPB guidance, and the most significant recent developments.
Information last verified on 2026-09-10. This article presents general legal information and does not constitute legal advice. Consult a qualified data protection attorney or privacy professional for guidance specific to your organisation.
Jurisdiction scope: This checklist addresses compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679) as it applies in EU and EEA member states. It does not address the UK GDPR (which diverged from EU GDPR after Brexit) or national implementation laws. For a comparison, see GDPR vs UK GDPR. For a foundational overview of the regulation, see What Is GDPR.
The GDPR compliance checklist: an overview
GDPR compliance requires action across fourteen interlocking areas. The sections below address each in turn. Start with data mapping, because every other step depends on knowing what data you hold and why.
| Step | Compliance area | Key articles | Priority |
|---|---|---|---|
| 1 | Data mapping and records of processing | Art. 30 | Foundation |
| 2 | Lawful basis identification | Art. 6 | Critical |
| 3 | Privacy notices and transparency | Art. 12, 13, 14 | Critical |
| 4 | Consent management | Art. 7, 8 | Where consent is the lawful basis |
| 5 | Data subject rights procedures | Art. 15-22 | Critical |
| 6 | DPO appointment | Art. 37-39 | Where required |
| 7 | Data Protection Impact Assessments | Art. 35 | Before high-risk processing |
| 8 | Processor contracts (DPAs) | Art. 28 | Critical |
| 9 | Security measures | Art. 32 | Critical |
| 10 | Breach response plan | Art. 33, 34 | Critical |
| 11 | International transfer safeguards | Chapter V | If data leaves EU/EEA |
| 12 | Data protection by design and default | Art. 25 | Ongoing |
| 13 | Staff training and accountability | Art. 39(1)(b) | Ongoing |
| 14 | Vendor management and ongoing review | Art. 24, 28 | Ongoing |
Step 1: Data mapping and records of processing activities (Article 30)
Before your organisation can comply with the GDPR, it must know what personal data it collects, where that data comes from, where it goes, and why it is processed. Data mapping is the foundation of every other compliance activity. Article 30 then requires this knowledge to be formalised in written records of processing activities (RoPA).
What to document in your data inventory
For each processing activity, record:
- Categories of personal data (names, email addresses, IP addresses, health data, financial records, biometric data)
- Categories of data subjects (customers, employees, website visitors, job applicants)
- Purpose of each processing activity
- Legal basis for processing (see Step 2)
- Storage locations and systems
- Who has access (internal roles and external recipients)
- Retention periods or the criteria for determining them
- Whether data leaves the EU/EEA, and if so, by what transfer mechanism
What controllers must record under Article 30(1)
Article 30(1) requires controllers to maintain written records containing:
- The name and contact details of the controller and, where applicable, the joint controller, the controller's EU representative and the data protection officer
- Purposes of processing
- Categories of data subjects and personal data
- Categories of recipients, including third countries
- Details of international transfers and the legal mechanism
- Envisaged retention periods
- A general description of technical and organisational security measures
Processors have a parallel obligation under Article 30(2): they must record the categories of processing carried out on behalf of each controller.
Controllers and processors outside the EU: the Article 27 representative
Where Article 3(2) catches a controller or processor that is not established in the Union, Article 27 requires it to designate a representative in the Union in writing, established in a member state where the affected data subjects are. The exemptions are narrow: occasional processing that does not include large-scale Article 9(1) or Article 10 data and is unlikely to result in a risk, and public authorities.
The representative is mandated to be addressed by supervisory authorities and data subjects on all issues relating to the processing. Its contact details belong in the Article 30 record and in the privacy notices required by Articles 13(1)(a) and 14(1)(a).
The Article 30(5) derogation and the proposed SME simplification
Article 30(5) disapplies the Article 30(1) and (2) record obligations for an enterprise or organisation employing fewer than 250 persons, unless the processing is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data under Article 9(1) or personal data relating to criminal convictions and offences under Article 10. A small employer that runs criminal-record background checks therefore keeps the record. In practice, most organisations process data regularly enough that this derogation rarely applies in full.
The proposed 250-to-750 change belongs to a different legislative file from the Digital Omnibus. It sits in the Commission's fourth simplification proposal for SMEs and small mid-caps, COM(2025) 501 of 21 May 2025, which would raise the Article 30(5) figure to fewer than 750 persons and replace the three current conditions with a single test: records would be required only where the processing is likely to result in a high risk within the meaning of Article 35.
The EDPB and EDPS reviewed that proposal in Joint Opinion 01/2025 of 9 July 2025, recommending that the exemption be tied to the statutory SME and small mid-cap definitions for clarity. Parliament and the Council reached a provisional agreement on the package on 9 June 2026 that raises the small mid-cap threshold to fewer than 1,000 employees, so the final figure may end up above 750. Parliament's first-reading vote is indicatively scheduled for 23 November 2026, and none of this is in force.

Step 2: Identify the lawful basis for each processing activity (Article 6)
Article 6 of the GDPR requires every processing activity to rest on one of six lawful bases. The basis must be identified before processing begins; switching bases after the fact is not permitted.
The six lawful bases
| Lawful basis | When it applies | Key conditions |
|---|---|---|
| Consent (Art. 6(1)(a)) | Individual opts in voluntarily | Freely given, specific, informed, unambiguous; withdrawable at any time |
| Contract (Art. 6(1)(b)) | Processing is necessary to perform a contract with the individual | Must be necessary, not merely convenient |
| Legal obligation (Art. 6(1)(c)) | Processing is required by EU or member-state law | The specific legal requirement must be identified |
| Vital interests (Art. 6(1)(d)) | Processing is necessary to protect someone's life | Narrow; cannot be used routinely |
| Public task (Art. 6(1)(e)) | Processing is necessary for a task in the public interest | Typically public authorities |
| Legitimate interests (Art. 6(1)(f)) | Processing is necessary for the controller's or a third party's legitimate interests | A documented balancing test is required |
The Article 9(1) special categories are personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, plus genetic data, biometric data used to identify a person uniquely, data concerning health, and data concerning a person's sex life or sexual orientation. Processing them requires both an Article 6 lawful basis and a separate Article 9(2) condition.
Criminal convictions are not an Article 9 category. Personal data relating to criminal convictions and offences is governed by Article 10, a different and stricter gate: processing based on Article 6(1) may be carried out only under the control of official authority, or where Union or member-state law authorises it with appropriate safeguards. Explicit consent under Article 9(2)(a) does not unlock Article 10 data.
Many organisations default to consent when legitimate interests or contractual necessity would be more appropriate. Consent creates ongoing management obligations, including tracking, withdrawal mechanisms, and potentially re-consent. For detailed guidance, see GDPR consent requirements.
Step 3: Write clear privacy notices (Articles 12, 13, 14)
Articles 13 and 14 require organisations to provide transparent information to data subjects. The EDPB CEF 2026 enforcement action, launched on 19 March 2026, focuses specifically on transparency and information obligations under Articles 12, 13 and 14, and 25 data protection authorities across Europe are auditing privacy notices this year.
Required content of a GDPR privacy notice
A compliant privacy notice must include:
- The controller identity and contact details, the EU representative's contact details where Article 27 applies, and the DPO contact details where applicable
- The purposes and lawful basis for each processing activity
- Categories of personal data collected
- Recipients or categories of recipients
- Details of any international data transfers and the safeguards in place
- Retention periods, or the criteria used to determine them
- All eight data subject rights
- The right to lodge a complaint with a supervisory authority
- Whether providing data is a statutory or contractual requirement
- Information about automated decision-making, including profiling, and the logic involved
Where data is collected directly from the individual (Article 13), the notice must be provided at the time of collection. Where data is obtained from a third party (Article 14), notice must be provided within one month. Article 12 requires clear, plain language that is concise, transparent, and easily accessible; a layered approach (short summary with links to detailed sections) works well.
Step 4: Establish a consent management process (Articles 7, 8)
Where consent is the chosen lawful basis, Article 7 imposes specific requirements. Consent that does not meet these requirements is invalid and the processing lacks a lawful basis.
Requirements for valid GDPR consent
"Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data." (GDPR, Article 7(1))
Valid consent under Article 7 must be:
- Freely given: no conditioning of a service on consent to unnecessary processing; no power imbalance preventing genuine choice
- Specific: separate consent for each distinct processing purpose; bundled consent is not valid
- Informed: the individual must know who collects the data, for what purpose, and that they can withdraw
- Unambiguous: a clear affirmative act is required; pre-ticked boxes, silence, and inactivity do not constitute consent
- Withdrawable: withdrawal must be as easy as giving consent; continued processing after withdrawal is not permitted
Article 8 applies where consent is the lawful basis for an information society service offered directly to a child. In that case the processing is lawful only if the child is at least 16, or if consent is given or authorised by the holder of parental responsibility. Member states may set a lower age by law provided it is not below 13, so the applicable age varies by country. Children's data processed on another lawful basis, such as contract or legal obligation, sits outside Article 8.
Consent management infrastructure requirements
- Record the time, mechanism, and text shown at the point of consent for each individual
- Enable withdrawal of consent and trigger downstream suppression in all systems
- Flag when consent was obtained and whether it remains current
- Support re-consent workflows where processing purposes change
- Store consent records in a format accessible to the supervisory authority on request
Step 5: Build data subject rights procedures (Articles 13-22)
The GDPR grants individuals eight rights over their personal data. For a detailed breakdown of each right, see GDPR data subject rights.
The eight rights at a glance
| Right | Article | Core obligation |
|---|---|---|
| Being informed | 13, 14 | Provide the required privacy information at the point of collection, or within one month where the data came from a third party |
| Access | 15 | Provide a copy of the data and specified information within one month |
| Rectification | 16 | Correct inaccurate or complete incomplete data without undue delay |
| Erasure | 17 | Delete data when no longer necessary, consent is withdrawn, or objection succeeds |
| Restriction | 18 | Pause processing while accuracy or lawfulness is contested |
| Data portability | 20 | Where processing rests on consent or contract and is carried out by automated means, provide the data the person supplied in a structured, commonly used and machine-readable format, and transmit it to another controller where technically feasible |
| Objection | 21 | Stop processing based on public task or legitimate interests unless compelling legitimate grounds are demonstrated; an absolute right to stop direct marketing; also available against Article 89(1) research and statistics |
| Automated decision-making | 22 | Not be subject to solely automated decisions with significant effects without human review |
Operational checklist for rights procedures
- Assign a team or individual to handle data subject access requests
- Create intake channels and acknowledge receipt promptly
- Build identity verification procedures to prevent unauthorised disclosure
- Map all systems containing personal data so data can be located and compiled quickly
- Document how each right type is handled, including partial responses and refusals
- Communicate every rectification, erasure and restriction to each recipient the data was disclosed to, and name those recipients if the individual asks (Article 19)
- Track deadlines: standard period is one calendar month; extension to three months is permitted for complex requests, but the individual must be notified within the first month
- Train customer-facing staff to recognise rights requests even when the individual does not use legal terminology

Step 6: Appoint a Data Protection Officer where required (Article 37)
Article 37 of the GDPR makes DPO appointment mandatory in three circumstances.
When a DPO is mandatory
A DPO must be appointed when:
- The controller or processor is a public authority or body (courts acting in a judicial capacity are excluded)
- The core activities require large-scale, regular, and systematic monitoring of individuals
- The core activities involve large-scale processing of special categories of data (Article 9) or criminal conviction data (Article 10)
"Core activities" means the principal activities of the organisation, not ancillary HR or IT processing common to all employers. "Large-scale" has no fixed numerical threshold; the EDPB's DPO Guidelines consider the number of data subjects, volume of data, geographical extent, and duration of processing.
DPO requirements under Articles 38-39
The DPO must possess expert knowledge of data protection law, report directly to the highest level of management, operate independently without receiving instructions on how to perform tasks, and be provided with adequate resources and access to processing operations. The DPO may not be dismissed or penalised for performing their duties. The DPO's contact details must be published and communicated to the supervisory authority.
The EDPB 2023 Coordinated Enforcement report on DPOs found that many organisations still fail to give DPOs genuine independence and adequate resources, and assign conflicting tasks that create conflicts of interest.
Step 7: Conduct Data Protection Impact Assessments (Article 35)
A DPIA is required before any processing likely to result in high risk to the rights and freedoms of natural persons. The obligation attaches before processing begins; retrospective DPIAs do not fulfil Article 35.
When a DPIA is always required
A DPIA is mandatory for:
- Systematic and extensive profiling with significant effects on individuals
- Large-scale processing of special category data or criminal conviction data
- Systematic monitoring of publicly accessible areas on a large scale
National supervisory authorities publish their own lists of processing operations that require a DPIA. Check the list published by your lead supervisory authority.
AI systems and DPIAs
The EU AI Act (Regulation (EU) 2024/1689), which entered into force on 1 August 2024, applies alongside the GDPR wherever AI systems process personal data. The CNIL considers that, for the development of high-risk systems covered by the AI Act that involve personal data, a DPIA is in principle necessary. Article 26(9) of the AI Act works from the other end: a deployer of a high-risk AI system that owes an Article 35 GDPR DPIA must use the information the provider supplies under Article 13 of the AI Act to meet that duty. The AI Act's technical documentation and data governance requirements under Articles 10 and 11 can feed into the DPIA, provided the DPIA contains all elements required by Article 35(7) GDPR.
What a DPIA must contain under Article 35(7)
- A systematic description of the processing operations and their purposes
- An assessment of the necessity and proportionality of the processing
- An assessment of the risks to data subjects' rights and freedoms
- The measures envisaged to address those risks
Where the DPIA reveals high residual risks that cannot be mitigated, the controller must consult the supervisory authority before proceeding (Article 36 prior consultation). DPIAs must be reviewed whenever there is a significant change to the processing.
Step 8: Put processor contracts in place (Article 28)
Where third-party service providers process personal data on your behalf, Article 28 requires a written data processing agreement before processing begins.
Mandatory provisions in an Article 28 DPA
Every processor contract must specify that the processor:
- Processes personal data only on documented instructions from the controller
- Ensures all authorised personnel are bound by confidentiality obligations
- Implements appropriate technical and organisational security measures (Article 32)
- Assists the controller in responding to data subject rights requests
- Assists with DPIAs, prior consultation, breach notification, and security obligations
- Deletes or returns all personal data at the end of the contract, at the controller's choice
- Makes available all information necessary to demonstrate Article 28 compliance and allows audits
- Engages sub-processors only with the controller's prior specific or general written authorisation; under a general authorisation the processor must inform the controller of any intended addition or replacement of sub-processors and give it the opportunity to object
Vendor assessment checklist
- Audit all existing contracts with vendors that handle personal data
- Confirm DPAs are in place and include all Article 28 mandatory provisions
- Assess vendors' security measures through questionnaires, certifications (ISO 27001, SOC 2 Type II), or audit rights
- Verify whether the vendor transfers data outside the EU/EEA and confirm the legal transfer mechanism
- Review sub-processor lists and procedures for sub-processor changes
- Establish a regular vendor review cycle (at minimum annually, or on any material change)
Step 9: Implement technical and organisational security measures (Article 32)
Article 32 requires appropriate technical and organisational measures to ensure security appropriate to the risk. The measures must be calibrated to the state of the art, implementation costs, and the nature, scope, context, and purposes of the processing, as well as the varying likelihood and severity of risks to individuals.
Article 32 specifically mentions
- Pseudonymisation and encryption of personal data
- The ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems
- The ability to restore availability and access to personal data in a timely manner following an incident
- A process for regularly testing, assessing, and evaluating the effectiveness of security measures
Beyond these statutory examples, organisations commonly implement: role-based access controls and the principle of least privilege; multi-factor authentication; network segmentation; vulnerability management and patching schedules; endpoint protection; data loss prevention controls; physical security; and supplier security assessments.
Organisational measures include a documented information security policy, data classification scheme, clear roles and responsibilities, security incident management, and third-party risk management procedures.
Step 10: Build and test a breach response plan (Articles 33, 34)
The GDPR imposes strict timelines for breach notification. Failing to report on time can result in significant fines independent of any fine for the underlying security failure. For a detailed treatment of the notification requirements, see GDPR breach notification 72-hour rule.
The 72-hour notification obligation under Article 33
Under Article 33(1), a controller must notify the competent supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware" of a personal data breach, "unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons". That risk test is the notification threshold: a breach that clears it is reportable, and a breach below it is documented internally instead. Where notification is not made within 72 hours, Article 33(1) requires it to be accompanied by reasons for the delay.
The EDPB has interpreted "aware" as when the controller has a reasonable degree of certainty that a security incident has occurred affecting personal data.
Notifications under Article 33(3) must describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned; give the name and contact details of the data protection officer or other contact point where more information can be obtained; describe the likely consequences; and describe the measures taken or proposed, including any measures to mitigate the effects.
The Article 34 obligation to notify affected individuals
Where a breach is likely to result in high risk to affected individuals, the controller must notify those individuals without undue delay. Article 34(3) provides limited exceptions where the data was encrypted or rendered unintelligible, subsequent measures have made high risk unlikely, or individual notification would require disproportionate effort (in which case a public communication may substitute).
Processors must notify the controller without undue delay after becoming aware of a breach (Article 33(2)). Processor contracts should specify a contractual timeframe, typically 24 to 48 hours.
Watch this step for change. The Digital Omnibus proposal, COM(2025) 837, would require notification only where a breach is likely to result in a high risk, extend the deadline to 96 hours, and route notifications through the single-entry point created by the NIS2 Directive. The EDPB and EDPS supported the longer deadline in Joint Opinion 2/2026. It remains a proposal, so the 72-hour rule above is the law today.
Breach response operational checklist
- Implement technical detection controls: intrusion detection, log monitoring, and anomaly alerting
- Establish a breach response team with defined roles, an escalation path, and a clear definition of organisational "awareness"
- Create a breach assessment template to evaluate risk to data subjects
- Prepare notification templates for the supervisory authority and affected individuals
- Maintain a breach register documenting all incidents, including those that fall below the Article 33(1) risk threshold; Article 33(5) requires this documentation in any event
- Test the breach response procedure through tabletop exercises at least annually
Step 11: Put international data transfer safeguards in place (Chapter V)
Transfers of personal data to countries outside the EU/EEA are only permitted where one of the Chapter V mechanisms is in place.
Transfer mechanisms
| Mechanism | When to use |
|---|---|
| Adequacy decision (Art. 45) | Transferring to a country the Commission has found adequate (examples: Japan, Republic of Korea, UK, US under the EU-US Data Privacy Framework) |
| Standard Contractual Clauses (Art. 46(2)(c)) | Most common mechanism for countries without adequacy; Commission adopted revised SCCs in June 2021 |
| Binding Corporate Rules (Art. 47) | Approved intra-group mechanism for multinational organisations |
| Specific derogations (Art. 49) | Narrow exceptions for occasional transfers where no other mechanism is available |
Transfer impact assessments
When relying on SCCs or BCRs, EDPB Recommendations 01/2020 require a transfer impact assessment to evaluate whether the recipient country's laws provide essentially equivalent protection to EU law. The assessment must consider surveillance laws, government access rights, available legal remedies, and the track record of public authorities in the destination country. Adequacy decisions should be monitored: the Court of Justice has previously invalidated adequacy decisions, and the EU-US Data Privacy Framework remains subject to ongoing legal challenges.
Step 12: Embed data protection by design and by default (Article 25)
Article 25 requires controllers to implement data protection principles from the earliest stages of any new processing activity or system (by design) and to ensure that only the minimum necessary data is processed for each purpose (by default).
Data protection by design in practice
- Include a data protection review as a mandatory gate in your project management or product development process
- Build access controls, encryption, and pseudonymisation into system architecture from the start
- Select technologies that minimise data exposure
- Document design decisions and the privacy trade-offs considered
Data protection by default in practice
Default settings must be the most privacy-protective available. Practical measures include: minimum-fields data collection forms; opt-in rather than opt-out defaults for non-essential processing; automatic deletion after the retention period; role-based access controls; and privacy-preserving defaults in analytics and tracking configurations.
Step 13: Staff training and accountability (Article 39(1)(b))
Article 39(1)(b) lists staff awareness training as one of the DPO's mandatory tasks. The accountability principle under Article 5(2) requires organisations without a mandatory DPO to demonstrate training as well. Enforcement decisions frequently cite inadequate staff training as an aggravating factor.
Training programme requirements
- Provide baseline GDPR training to all staff who handle personal data, before they begin processing and refreshed at least annually
- Deliver role-specific training for high-risk functions: HR, marketing, IT and development, customer service
- Train staff on your organisation's specific privacy notices, lawful bases, retention policies, and breach reporting procedures
- Document all training: who attended, date, format, and content
- Assess competency, not just attendance
Organisations that perform consistently well in regulatory audits embed data protection into their culture through visible leadership commitment, privacy champions in each department, clear escalation paths for privacy concerns, and regular internal communications reinforcing privacy expectations.
Step 14: Vendor management and ongoing review (Articles 24, 28)
Article 24 requires controllers to implement appropriate measures and to be able to demonstrate compliance on an ongoing basis. Compliance programmes need regular review cycles, not just initial implementation.
Ongoing compliance review framework
- Annual compliance audit: review your RoPA, privacy notices, consent records, DPAs, and security measures at least once per year, or when any material change in processing occurs
- DPIA reviews: revisit DPIAs whenever the nature, scope, context, or purpose of the processing changes significantly
- Vendor reviews: reassess processors at regular intervals; review sub-processor lists, certifications, and transfer mechanisms; monitor for vendor security incidents
- Legislative monitoring: track EDPB guidelines, national DPA guidance, CJEU judgments, and developments including the Digital Omnibus legislative process
- Incident reviews: after any security incident, conduct a post-incident review and update procedures, controls, and training accordingly
Accountability documentation
Maintain a compliance file containing: your RoPA; DPIAs and their review history; DPA contracts; consent records and withdrawal logs; staff training records; security assessments; breach register; and DPO appointment documentation. These records form the evidence base if a supervisory authority initiates an investigation.
Recent developments: the EU AI Act and the November 2025 Digital Omnibus
The EU AI Act and GDPR compliance
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in phases. Prohibitions on unacceptable-risk AI systems applied from 2 February 2025. Obligations for general-purpose AI model providers applied from 2 August 2025. The Article 50 transparency duties apply from 2 August 2026. The high-risk obligations were moved by the July 2026 Digital Omnibus, Regulation (EU) 2026/1744: they apply from 2 December 2027 for stand-alone Annex III systems and from 2 August 2028 for high-risk AI embedded in the regulated products listed in Annex I.
Article 2(7) of the AI Act expressly confirms that EU data protection law remains fully applicable to all processing of personal data in the lifecycle of AI systems. The EDPB, in Statement 3/2024, confirmed that data protection authorities retain their full supervisory role under the GDPR even where the AI Act creates parallel obligations.
For organisations developing or deploying AI systems that process personal data:
- Processing personal data to train AI models requires a lawful basis under Article 6 GDPR (and Article 9 for special category data)
- Where a deployer of a high-risk AI system owes an Article 35 GDPR DPIA, Article 26(9) of the AI Act requires it to use the provider's Article 13 information to comply; the CNIL treats a DPIA as in principle necessary for developing high-risk AI systems involving personal data, and the AI Act's technical documentation can feed into the DPIA provided all Article 35(7) elements are present
- AI Act Article 10 data governance requirements for high-risk AI systems, which address data quality and bias examination, are complementary to the GDPR's data minimisation and accuracy principles
The CNIL has published detailed recommendations on GDPR compliance for AI system development, covering lawful bases for training data, data minimisation in model development, data subject rights for individuals whose data is used in training, and privacy by design in model architecture.
The November 2025 Digital Omnibus proposal
On 19 November 2025, the European Commission published the Digital Omnibus package, proposing amendments to the GDPR, ePrivacy Directive, NIS2 Directive, Data Act, and EU AI Act. The AI Act amendments were adopted separately as Regulation (EU) 2026/1744 and have applied since 27 July 2026. The proposed GDPR amendments are still in the EU legislative process and are not yet in force.
Key proposed GDPR changes in the Digital Omnibus include:
- Recast breach notification (Article 33): notification would be required only where a breach is likely to result in a high risk to people's rights and freedoms, the deadline would move from 72 to 96 hours, and notifications would run through the single-entry point created by the NIS2 Directive, with a common template to be adopted by the Commission
- AI training as legitimate interest: a clarification that processing personal data for the development and deployment of AI systems can constitute a legitimate interest under Article 6(1)(f), subject to necessity, proportionality, and appropriate safeguards
- Revised definition of personal data: information would not constitute personal data for an entity that does not have means reasonably likely to be used to identify the individual, or where identification is legally prohibited or would require disproportionate effort
- Cookie and tracking rule changes: amendments to ePrivacy rules to reduce consent-fatigue from cookie banners
The Digital Omnibus does not amend Article 30. The record-keeping threshold change sits in the separate Omnibus IV proposal, COM(2025) 501, described in Step 1.
The EDPB and EDPS issued Joint Opinion 2/2026 on the Digital Omnibus. They supported extending the breach-notification deadline from 72 to 96 hours, while raising concerns about the personal data redefinition and its compatibility with the EU Charter of Fundamental Rights. Privacy advocacy organisations have criticised several provisions.
The file is moving slowly. The Council did not agree a negotiating mandate in June 2026, and in Parliament the ITRE and LIBE committees are still working through more than 1,700 tabled amendments. Organisations should monitor the process but not adjust compliance programmes on the basis of the proposal until it is enacted.
Disclaimer
This article presents general legal information about the General Data Protection Regulation (Regulation (EU) 2016/679) and related EU legislation as it stood on 2026-09-10. It does not constitute legal advice and does not create a lawyer-client relationship. Compliance requirements depend on your specific processing activities, sector, size, and the member states in which you operate. Consult a qualified data protection lawyer or certified privacy professional licensed in the relevant jurisdiction before making compliance decisions. The Digital Omnibus (COM(2025) 837) and Omnibus IV (COM(2025) 501) measures referenced in this article are legislative proposals and have not entered into force.
About the author
[PLACEHOLDER: author roster pending]
Authorities cited
- General Data Protection Regulation, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. https://eur-lex.europa.eu/eli/reg/2016/679/oj
- European Data Protection Board (EDPB). https://edpb.europa.eu/edpb_en
- European Commission, Data Protection in the EU. https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu_en
- EDPB, Data Protection Impact Assessment (DPIA). https://www.edpb.europa.eu/topics/accountability-and-compliance-tools/data-protection-impact-assessment_en
- EDPB, Data Protection Officer. https://www.edpb.europa.eu/topics/accountability-and-compliance-tools/data-protection-officer_en
- EDPB, Guidelines on DPIAs and High-Risk Processing. https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/data-protection-impact-assessments-high-risk-processing_en
- GDPR Article 30, Records of Processing Activities (EUR-Lex consolidated text). https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504#art_30
- GDPR Article 33, Notification of a Personal Data Breach to the Supervisory Authority (EUR-Lex consolidated text). https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504#art_33
- EDPB, Coordinated Enforcement Report: DPOs (January 2024). https://www.edpb.europa.eu/system/files/2024-01/edpb_report_20240116_cef_dpo_en.pdf
- EDPB, Personal Data Breaches. https://www.edpb.europa.eu/topics/security-data-breaches/personal-data-breaches_en
- ICO, When Do We Need to Do a DPIA? https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/when-do-we-need-to-do-a-dpia/
- ICO, How Do We Document Our Processing Activities? https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/documentation/how-do-we-document-our-processing-activities/
- European Commission, Principles of the GDPR. https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/principles-gdpr_en
- EU AI Act, Regulation (EU) 2024/1689. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- European Commission, AI Act Enters Into Force (1 August 2024). https://commission.europa.eu/news-and-media/news/ai-act-enters-force-2024-08-01_en
- EDPB Statement 3/2024 on DPA Role in AI Act Framework. https://www.edpb.europa.eu/news/news/2024/edpb-adopts-statement-dpas-role-ai-act-framework-eu-us-data-privacy-framework-faq_en
- European Commission, Digital Omnibus Regulation Proposal (19 November 2025). https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal
- EDPB and EDPS, Joint Opinion 2/2026 on the Digital Omnibus. https://www.edpb.europa.eu/news/news/2026/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while_en
- EDPB and EDPS, Targeted Modifications of the GDPR: Record-Keeping Simplification. https://www.edpb.europa.eu/news/news/2025/targeted-modifications-gdpr-edpb-edps-welcome-simplification-record-keeping_en
- EDPB, CEF 2026: Coordinated Enforcement on Transparency and Information Obligations. https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en
- CNIL, AI System Development: Recommendations to Comply with the GDPR. https://www.cnil.fr/en/ai-system-development-cnils-recommendations-to-comply-gdpr
- EDPB, Guidelines on the Interplay Between the DSA and the GDPR. https://www.edpb.europa.eu/news/news/2025/interplay-between-dsa-and-gdpr-edpb-adopts-guidelines_en
- European Commission, Proposal COM(2025) 501 of 21 May 2025 (Omnibus IV, SMEs and small mid-caps), amending Article 30(5) GDPR. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0501
- EDPB and EDPS, Joint Opinion 01/2025 of 9 July 2025 on the SME and SMC simplification proposal and Article 30(5) GDPR. https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-012025-on-the-proposal-for-a-regulation-on_en
- GDPR Article 10, Processing of Personal Data Relating to Criminal Convictions and Offences (EUR-Lex consolidated text). https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504#art_10
Related articles
- What Is GDPR: a comprehensive overview of the regulation
- GDPR Data Subject Rights: detailed guidance on all eight individual rights
- GDPR Consent Requirements: valid consent standards and management obligations
- GDPR Breach Notification 72-Hour Rule: breach reporting requirements in full
- GDPR for Small Businesses: SME-specific guidance including the proposed record-keeping simplification
- EU Data Privacy Laws: the complete EU data protection hub
Last updated: 2026-09-10. Statutes and guidance cited reflect their in-force version as of 2026-09-10. The Digital Omnibus GDPR proposals (COM(2025) 837) and the Omnibus IV record-keeping change (COM(2025) 501) are legislative proposals and have not entered into force; the AI Act half of the Digital Omnibus package was enacted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026.
Frequently Asked Questions
What is the first step in GDPR compliance?
The first step is conducting a data mapping exercise and building your records of processing activities under Article 30. You need to identify every category of personal data your organisation collects, where it comes from, how it is processed, who has access, and where it is stored. Without a complete picture of your data flows, you cannot properly identify lawful bases, write accurate privacy notices, or implement appropriate security measures.
Do all organisations need a Data Protection Officer?
No. A DPO is mandatory only for public authorities, organisations whose core activities require large-scale regular and systematic monitoring of individuals, and organisations that process Article 9 special category data, or Article 10 data on criminal convictions and offences, on a large scale (Article 37 GDPR). Many organisations appoint a DPO voluntarily. If you designate a DPO, whether required or voluntary, the full GDPR rules on independence, resources, and protection from dismissal apply.
How often should GDPR compliance be reviewed?
GDPR compliance requires continuous maintenance. Records of processing should be updated whenever processing changes. DPIAs must be reviewed when the nature, scope, or purpose of processing changes significantly. Privacy notices should be updated when new processing is introduced. Staff training should be refreshed at least annually. Most organisations conduct a comprehensive compliance audit once a year and trigger interim reviews on material operational changes.
When is a Data Protection Impact Assessment required?
A DPIA is required before any processing likely to result in high risk to individuals rights and freedoms (Article 35 GDPR). It is always required for systematic profiling with significant effects, large-scale processing of special category data, and large-scale systematic monitoring of public areas. National supervisory authorities publish additional lists of operations requiring DPIAs. The CNIL considers a DPIA in principle necessary for developing high-risk AI systems covered by the EU AI Act that involve personal data, and Article 26(9) of the AI Act requires deployers of high-risk systems to use the provider's information where they owe an Article 35 DPIA.
What must be included in a GDPR privacy notice?
A privacy notice must include the controller identity and contact details, the EU representative's contact details where Article 27 applies, DPO contact details where applicable, purposes and lawful basis for processing, categories of data collected, recipients, retention periods, international transfer details, all eight data subject rights, the right to complain to a supervisory authority, and information about automated decision-making. The notice must use clear, plain language (Article 12 GDPR). The EDPB CEF 2026 enforcement action, launched on 19 March 2026 with 25 participating data protection authorities, focuses specifically on privacy notices under Articles 12, 13 and 14.
What are the GDPR penalties for non-compliance?
GDPR fines reach up to EUR 20 million or 4% of global annual turnover (whichever is higher) for violations of core principles, data subject rights, and international transfer rules. Lower-tier fines of up to EUR 10 million or 2% of turnover apply to administrative violations including failure to maintain Article 30 records or appoint a required DPO. Supervisory authorities can also issue warnings, reprimands, and processing bans. See GDPR fines and penalties for enforcement data and case examples.
What must processor contracts include under Article 28?
Article 28 DPAs must specify: subject matter, duration, nature, and purpose of processing; types of personal data and categories of data subjects; obligations for the processor to act only on documented controller instructions; staff confidentiality obligations; security measures; assistance with data subject rights and breach notification; deletion or return of data at contract end; audit rights; and sub-processing conditions requiring the controller's prior specific or general written authorisation, with notice and an opportunity to object where that authorisation is general.
How does the EU AI Act affect GDPR compliance?
The EU AI Act (Regulation (EU) 2024/1689) applies alongside the GDPR wherever AI systems process personal data. Article 2(7) of the AI Act expressly preserves GDPR obligations in full. Where a deployer of a high-risk AI system owes a DPIA under Article 35 GDPR, Article 26(9) of the AI Act requires it to use the information the provider supplies under Article 13. The November 2025 Digital Omnibus proposal includes a clarification that processing for AI development can constitute a legitimate interest, but that proposal is not yet law.
What does the November 2025 Digital Omnibus proposal change for GDPR?
The Digital Omnibus, COM(2025) 837 of 19 November 2025, proposes to require breach notification only where a breach is likely to result in a high risk and to extend the deadline from 72 to 96 hours through the NIS2 single-entry point; clarify that AI training can constitute a legitimate interest under Article 6(1)(f); narrow the definition of personal data for entities that cannot identify the individual; and adjust online tracking consent rules. It does not amend Article 30. The record-keeping change from 250 to 750 persons sits in the separate Omnibus IV proposal, COM(2025) 501 of 21 May 2025 (raised to fewer than 1,000 persons in the 9 June 2026 provisional agreement, which awaits the plenary vote). Both files are still under negotiation and neither is in force.
What is a transfer impact assessment and when is it required?
A transfer impact assessment (TIA) is an analysis of whether the legal framework in a third country provides essentially equivalent protection to EU law, required when relying on Standard Contractual Clauses or Binding Corporate Rules for international data transfers under Chapter V GDPR. EDPB Recommendations 01/2020 provide the methodology. The TIA must examine surveillance laws, government access rights, available legal remedies, and the track record of public authorities in the destination country.
Updates
Corrected the breach-notification rule to state the Article 33(1) risk threshold and the duty to give reasons for a late notification; moved criminal-conviction data from Article 9 to Article 10 where it belongs; re-attributed the proposed 250-to-750 record-keeping change from the Digital Omnibus to the separate Omnibus IV proposal COM(2025) 501 and noted the June 2026 provisional agreement on a higher figure; added the proposed 96-hour breach rule, the missing eighth data subject right, the Article 27 EU representative duty and several fuller statutory conditions; and replaced five citations that had gone dead.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
AI Act dates updated for the July 2026 Digital Omnibus: high-risk obligations now apply 2 December 2027 (Annex III) and 2 August 2028 (Annex I), while the 2 August 2026 transparency date is unchanged.
Expanded with dedicated sections on consent management, data protection by design and default, staff training and accountability, vendor management, and ongoing review. Added coverage of the EU AI Act (Regulation (EU) 2024/1689) obligations for AI processing, the November 2025 Digital Omnibus proposal, the EDPB CEF 2026 transparency enforcement action, and the proposed Article 30 record-keeping threshold change. Citations updated throughout.
Reviewed and approved by an editor
Initial publication of the [GDPR](/world-laws/world-data-privacy-laws) compliance checklist.
Sources and References
- GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council(eur-lex.europa.eu).gov
- European Data Protection Board (EDPB)(edpb.europa.eu).gov
- European Commission — Data Protection in the EU(commission.europa.eu).gov
- EDPB — Data Protection Impact Assessment (DPIA)(edpb.europa.eu).gov
- EDPB — Data Protection Officer(edpb.europa.eu).gov
- EDPB — Guidelines on DPIAs and High-Risk Processing(edpb.europa.eu).gov
- GDPR Article 30 — Records of Processing Activities (EUR-Lex consolidated text)(eur-lex.europa.eu).gov
- GDPR Article 33 — Notification of a Personal Data Breach to the Supervisory Authority (EUR-Lex consolidated text)(eur-lex.europa.eu).gov
- EDPB — 2023 Coordinated Enforcement Report on DPOs(edpb.europa.eu).gov
- EDPB — Personal Data Breaches(edpb.europa.eu).gov
- ICO — When Do We Need a DPIA?(ico.org.uk).gov
- ICO — Documenting Processing Activities(ico.org.uk).gov
- European Commission — Principles of the GDPR(commission.europa.eu).gov
- EU AI Act — Regulation (EU) 2024/1689(eur-lex.europa.eu).gov
- European Commission — AI Act Enters Into Force (August 2024)(commission.europa.eu).gov
- EDPB Statement 3/2024 — DPA Role in AI Act Framework(edpb.europa.eu).gov
- European Commission — Digital Omnibus Regulation Proposal (November 2025)(digital-strategy.ec.europa.eu).gov
- EDPB and EDPS Joint Opinion 2/2026 on the Digital Omnibus(edpb.europa.eu).gov
- EDPB — Targeted Modifications of the GDPR: Record-Keeping Simplification(edpb.europa.eu).gov
- EDPB — CEF 2026: Coordinated Enforcement on Transparency and Information Obligations(edpb.europa.eu).gov
- CNIL — AI System Development: Recommendations to Comply with the GDPR(cnil.fr).gov
- EDPB — Guidelines on the Interplay Between the DSA and the GDPR(edpb.europa.eu).gov
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
- European Commission — Proposal COM(2025) 501 of 21 May 2025 (Omnibus IV, SMEs and small mid-caps), amending Article 30(5) GDPR(eur-lex.europa.eu).gov
- EDPB and EDPS — Joint Opinion 01/2025 of 9 July 2025 on the SME and SMC simplification proposal and the Article 30(5) GDPR record-keeping obligation(edpb.europa.eu).gov
- GDPR Article 10 — Processing of Personal Data Relating to Criminal Convictions and Offences (EUR-Lex consolidated text)(eur-lex.europa.eu).gov
- European Parliament Legislative Train — Omnibus IV: simplifying measures for SMEs and small mid-caps (state of play, 2025/0130(COD))(europarl.europa.eu).gov