General Data Protection Regulation (GDPR) Checks

This GDPR compliance checklist can be used to conduct an information audit to determine what information is processed, who has access to it, a legal justification for the data processing activities, etc.

General Data Protection Regulation (GDPR) Checks



GDPR Inspection

1. Is the manager aware of his/her responsibilities as a data controller under GDPR?


Photo Comment

2. Is the requested information about an individual really needed?


Photo Comment

3. Is the purpose behind the data collection known?


Photo Comment

4. Are the people whose information is held aware that their data is collected and recorded?


Photo Comment

5. Are the people whose information is collected aware of the purpose their data is likely to be used for?


Photo Comment

6. Are people aware of their data protection rights?


Photo Comment

7. Is the information being held securely, whether it is on paper or electronically?


Photo Comment

8. Is the website secure?


Photo Comment

9. Is the personal information collected accurate and up-to-date?


Photo Comment

10. Is personal information deleted as soon as there is no need for it?


Photo Comment

11. Is access to personal information limited only to those with a strict need-to-know?


Photo Comment

12. When putting staff details on the company website, are staff first consulted and consent taken?


Photo Comment

13. If staff are monitored for example checking their use of email, have they been informed about this and reasons for monitoring explained to staff?


Photo Comment

14. Are staff trained in their duties and responsibilities under GDPR?


Photo Comment

15. Are staff putting GDPR responsibilities into practice?


Photo Comment

16. If asked to pass on personal information, are staff clear as to when GDPR allows it?


Photo Comment

17. Are clear protocols established in case service users or employees asks for a copy of information held about them?


Photo Comment

18. Is a policy in place for dealing with data protection issues?


Photo Comment

19. Does the Information Commissioner need to be notified?


Photo Comment

20. If the Information Commissioner is already notified, is the notification up to date, or does it need removing or amending?


Photo Comment

Is this sample what you are looking for?
Sign up to use & customise this template, or create your own custom checklist:

Checklist by GoAudits.com – Please note that this checklist is intended as an example. We do not guarantee compliance with the laws applicable to your territory or industry. You should seek professional advice to determine how this checklist should be adapted to your workplace or jurisdiction.

Seeing is Believing

Get a live demo customized to your unique needs, or get started with a 14-day FREE trial.