GDPR Compliance Checklist 2026: Step-by-Step Guide

Independently fact-checked against primary sources (last audited September 11, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 11, 2026. · 27 primary sources cited on this page. How we verify our legal content

GDPR Compliance Checklist 2026: Step-by-Step Guide

Frequently Asked Questions

What is the first step in GDPR compliance?

The first step is conducting a data mapping exercise and building your records of processing activities under Article 30. You need to identify every category of personal data your organisation collects, where it comes from, how it is processed, who has access, and where it is stored. Without a complete picture of your data flows, you cannot properly identify lawful bases, write accurate privacy notices, or implement appropriate security measures.

Do all organisations need a Data Protection Officer?

No. A DPO is mandatory only for public authorities, organisations whose core activities require large-scale regular and systematic monitoring of individuals, and organisations that process Article 9 special category data, or Article 10 data on criminal convictions and offences, on a large scale (Article 37 GDPR). Many organisations appoint a DPO voluntarily. If you designate a DPO, whether required or voluntary, the full GDPR rules on independence, resources, and protection from dismissal apply.

How often should GDPR compliance be reviewed?

GDPR compliance requires continuous maintenance. Records of processing should be updated whenever processing changes. DPIAs must be reviewed when the nature, scope, or purpose of processing changes significantly. Privacy notices should be updated when new processing is introduced. Staff training should be refreshed at least annually. Most organisations conduct a comprehensive compliance audit once a year and trigger interim reviews on material operational changes.

When is a Data Protection Impact Assessment required?

A DPIA is required before any processing likely to result in high risk to individuals rights and freedoms (Article 35 GDPR). It is always required for systematic profiling with significant effects, large-scale processing of special category data, and large-scale systematic monitoring of public areas. National supervisory authorities publish additional lists of operations requiring DPIAs. The CNIL considers a DPIA in principle necessary for developing high-risk AI systems covered by the EU AI Act that involve personal data, and Article 26(9) of the AI Act requires deployers of high-risk systems to use the provider's information where they owe an Article 35 DPIA.

What must be included in a GDPR privacy notice?

A privacy notice must include the controller identity and contact details, the EU representative's contact details where Article 27 applies, DPO contact details where applicable, purposes and lawful basis for processing, categories of data collected, recipients, retention periods, international transfer details, all eight data subject rights, the right to complain to a supervisory authority, and information about automated decision-making. The notice must use clear, plain language (Article 12 GDPR). The EDPB CEF 2026 enforcement action, launched on 19 March 2026 with 25 participating data protection authorities, focuses specifically on privacy notices under Articles 12, 13 and 14.

What are the GDPR penalties for non-compliance?

GDPR fines reach up to EUR 20 million or 4% of global annual turnover (whichever is higher) for violations of core principles, data subject rights, and international transfer rules. Lower-tier fines of up to EUR 10 million or 2% of turnover apply to administrative violations including failure to maintain Article 30 records or appoint a required DPO. Supervisory authorities can also issue warnings, reprimands, and processing bans. See GDPR fines and penalties for enforcement data and case examples.

What must processor contracts include under Article 28?

Article 28 DPAs must specify: subject matter, duration, nature, and purpose of processing; types of personal data and categories of data subjects; obligations for the processor to act only on documented controller instructions; staff confidentiality obligations; security measures; assistance with data subject rights and breach notification; deletion or return of data at contract end; audit rights; and sub-processing conditions requiring the controller's prior specific or general written authorisation, with notice and an opportunity to object where that authorisation is general.

How does the EU AI Act affect GDPR compliance?

The EU AI Act (Regulation (EU) 2024/1689) applies alongside the GDPR wherever AI systems process personal data. Article 2(7) of the AI Act expressly preserves GDPR obligations in full. Where a deployer of a high-risk AI system owes a DPIA under Article 35 GDPR, Article 26(9) of the AI Act requires it to use the information the provider supplies under Article 13. The November 2025 Digital Omnibus proposal includes a clarification that processing for AI development can constitute a legitimate interest, but that proposal is not yet law.

What does the November 2025 Digital Omnibus proposal change for GDPR?

The Digital Omnibus, COM(2025) 837 of 19 November 2025, proposes to require breach notification only where a breach is likely to result in a high risk and to extend the deadline from 72 to 96 hours through the NIS2 single-entry point; clarify that AI training can constitute a legitimate interest under Article 6(1)(f); narrow the definition of personal data for entities that cannot identify the individual; and adjust online tracking consent rules. It does not amend Article 30. The record-keeping change from 250 to 750 persons sits in the separate Omnibus IV proposal, COM(2025) 501 of 21 May 2025 (raised to fewer than 1,000 persons in the 9 June 2026 provisional agreement, which awaits the plenary vote). Both files are still under negotiation and neither is in force.

What is a transfer impact assessment and when is it required?

A transfer impact assessment (TIA) is an analysis of whether the legal framework in a third country provides essentially equivalent protection to EU law, required when relying on Standard Contractual Clauses or Binding Corporate Rules for international data transfers under Chapter V GDPR. EDPB Recommendations 01/2020 provide the methodology. The TIA must examine surveillance laws, government access rights, available legal remedies, and the track record of public authorities in the destination country.

Updates

Corrected the breach-notification rule to state the Article 33(1) risk threshold and the duty to give reasons for a late notification; moved criminal-conviction data from Article 9 to Article 10 where it belongs; re-attributed the proposed 250-to-750 record-keeping change from the Digital Omnibus to the separate Omnibus IV proposal COM(2025) 501 and noted the June 2026 provisional agreement on a higher figure; added the proposed 96-hour breach rule, the missing eighth data subject right, the Article 27 EU representative duty and several fuller statutory conditions; and replaced five citations that had gone dead.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

AI Act dates updated for the July 2026 Digital Omnibus: high-risk obligations now apply 2 December 2027 (Annex III) and 2 August 2028 (Annex I), while the 2 August 2026 transparency date is unchanged.

Expanded with dedicated sections on consent management, data protection by design and default, staff training and accountability, vendor management, and ongoing review. Added coverage of the EU AI Act (Regulation (EU) 2024/1689) obligations for AI processing, the November 2025 Digital Omnibus proposal, the EDPB CEF 2026 transparency enforcement action, and the proposed Article 30 record-keeping threshold change. Citations updated throughout.

Reviewed and approved by an editor

Initial publication of the [GDPR](/world-laws/world-data-privacy-laws) compliance checklist.

Sources and References

  1. GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council(eur-lex.europa.eu).gov
  2. European Data Protection Board (EDPB)(edpb.europa.eu).gov
  3. European Commission — Data Protection in the EU(commission.europa.eu).gov
  4. EDPB — Data Protection Impact Assessment (DPIA)(edpb.europa.eu).gov
  5. EDPB — Data Protection Officer(edpb.europa.eu).gov
  6. EDPB — Guidelines on DPIAs and High-Risk Processing(edpb.europa.eu).gov
  7. GDPR Article 30 — Records of Processing Activities (EUR-Lex consolidated text)(eur-lex.europa.eu).gov
  8. GDPR Article 33 — Notification of a Personal Data Breach to the Supervisory Authority (EUR-Lex consolidated text)(eur-lex.europa.eu).gov
  9. EDPB — 2023 Coordinated Enforcement Report on DPOs(edpb.europa.eu).gov
  10. EDPB — Personal Data Breaches(edpb.europa.eu).gov
  11. ICO — When Do We Need a DPIA?(ico.org.uk).gov
  12. ICO — Documenting Processing Activities(ico.org.uk).gov
  13. European Commission — Principles of the GDPR(commission.europa.eu).gov
  14. EU AI Act — Regulation (EU) 2024/1689(eur-lex.europa.eu).gov
  15. European Commission — AI Act Enters Into Force (August 2024)(commission.europa.eu).gov
  16. EDPB Statement 3/2024 — DPA Role in AI Act Framework(edpb.europa.eu).gov
  17. European Commission — Digital Omnibus Regulation Proposal (November 2025)(digital-strategy.ec.europa.eu).gov
  18. EDPB and EDPS Joint Opinion 2/2026 on the Digital Omnibus(edpb.europa.eu).gov
  19. EDPB — Targeted Modifications of the GDPR: Record-Keeping Simplification(edpb.europa.eu).gov
  20. EDPB — CEF 2026: Coordinated Enforcement on Transparency and Information Obligations(edpb.europa.eu).gov
  21. CNIL — AI System Development: Recommendations to Comply with the GDPR(cnil.fr).gov
  22. EDPB — Guidelines on the Interplay Between the DSA and the GDPR(edpb.europa.eu).gov
  23. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  24. European Commission — Proposal COM(2025) 501 of 21 May 2025 (Omnibus IV, SMEs and small mid-caps), amending Article 30(5) GDPR(eur-lex.europa.eu).gov
  25. EDPB and EDPS — Joint Opinion 01/2025 of 9 July 2025 on the SME and SMC simplification proposal and the Article 30(5) GDPR record-keeping obligation(edpb.europa.eu).gov
  26. GDPR Article 10 — Processing of Personal Data Relating to Criminal Convictions and Offences (EUR-Lex consolidated text)(eur-lex.europa.eu).gov
  27. European Parliament Legislative Train — Omnibus IV: simplifying measures for SMEs and small mid-caps (state of play, 2025/0130(COD))(europarl.europa.eu).gov
Share: