GDPR Checklist
Free web tool: GDPR Checklist
Compliance Progress
0%
0 / 28 items completed
합법적 처리 근거
0/6데이터 주체 권리
0/8기술적 조치
0/6조직적 조치
0/5국제 이전
0/3About GDPR Checklist
The GDPR Compliance Checklist is a free, interactive browser tool that helps organizations systematically verify their compliance with the EU General Data Protection Regulation. It organizes 28 compliance requirements across five key sections: Lawful Basis for Processing (6 items covering consent, contract necessity, legal obligation, vital interests, public task, and legitimate interest), Data Subject Rights (8 items including access, rectification, erasure, restriction, portability, objection, automated decision-making rights, and consent withdrawal), Technical Measures (6 items for encryption, access control, security testing, backup procedures, pseudonymization, and incident detection), Organizational Measures (5 items for DPO appointment, staff training, breach response planning, DPIA, and processing activity records), and International Transfers (3 items for EEA transfer safeguards, Standard Contractual Clauses, and Adequacy Decisions).
Data protection officers, compliance managers, legal counsel, startup founders, and IT security teams use this checklist during GDPR readiness assessments, internal audits, vendor due diligence reviews, and new-product compliance checks. The tool lets you check off individual items as you verify them, with per-section counters (e.g., "3/6 completed") and an overall progress bar showing the total completion percentage across all 28 items.
All checkbox state is managed entirely within the browser session using React's useState hook. No compliance data, checkmarks, or organizational information is ever transmitted to a server or stored beyond your current browser session. The tool is designed to be a starting-point reference and structured guide — it is not a substitute for legal advice or a formal compliance certification process.
Key Features
- 28 GDPR compliance items organized across 5 categories: Lawful Basis, Data Subject Rights, Technical Measures, Organizational Measures, and International Transfers
- Lawful Basis section covers all 6 legal grounds: consent, contract, legal obligation, vital interests, public task, and legitimate interest
- Data Subject Rights section covers all 8 GDPR rights: access, rectification, erasure, restriction, portability, objection, automated decision-making, and consent withdrawal
- Technical Measures section covers encryption, access control, security testing, backup, pseudonymization, and incident detection
- Organizational Measures section covers DPO designation, staff training, breach response plan, DPIA, and processing activity records
- International Transfers section covers EEA transfer safeguards, Standard Contractual Clauses (SCC), and Adequacy Decisions
- Per-section completion counters (e.g., 2/6) plus an overall visual progress bar showing total completion percentage
- Fully client-side state management — compliance data never leaves your browser and is not stored on any server
Frequently Asked Questions
What is the GDPR Compliance Checklist tool?
It is a free, browser-based interactive checklist covering 28 key GDPR compliance requirements organized into five sections: Lawful Basis for Processing, Data Subject Rights, Technical Measures, Organizational Measures, and International Transfers. Check off items as you verify them and track your progress visually.
What are the six lawful bases for processing under GDPR?
GDPR Article 6 defines six lawful bases: (1) Consent — the data subject has given explicit consent; (2) Contract — processing is necessary for a contract with the data subject; (3) Legal Obligation — processing is required by law; (4) Vital Interests — processing is necessary to protect someone's life; (5) Public Task — processing is needed for a task in the public interest; (6) Legitimate Interest — processing is necessary for the controller's or a third party's legitimate interests, provided these interests are not overridden by the data subject's rights.
What are the eight data subject rights under GDPR?
GDPR grants individuals eight rights: (1) Right of Access — to obtain a copy of their personal data; (2) Right to Rectification — to correct inaccurate data; (3) Right to Erasure ("Right to be Forgotten") — to have data deleted in certain circumstances; (4) Right to Restriction of Processing — to limit how data is used; (5) Right to Data Portability — to receive data in a machine-readable format; (6) Right to Object — to object to processing based on legitimate interest or for direct marketing; (7) Rights related to automated decision-making and profiling; (8) Right to Withdraw Consent — to withdraw previously given consent at any time.
What is a DPO and when is one required?
A Data Protection Officer (DPO) is a designated individual responsible for overseeing GDPR compliance within an organization. A DPO is required when: (1) you are a public authority; (2) your core activities involve large-scale systematic monitoring of individuals; or (3) your core activities involve large-scale processing of special category data (health, genetic, biometric data, etc.). Even when not legally required, appointing a DPO is a best practice for compliance governance.
What is a DPIA and when is it needed?
A Data Protection Impact Assessment (DPIA) is a process to identify and minimize data protection risks in high-risk processing activities. It is required when processing is likely to result in high risk to individuals — for example, large-scale profiling, systematic monitoring of public areas, or processing special categories of data at scale. A DPIA should be conducted before starting the processing activity.
What are Standard Contractual Clauses (SCC) for international transfers?
Standard Contractual Clauses are pre-approved contract templates provided by the European Commission that legally bind data importers outside the EEA to GDPR-equivalent data protection standards. They are one of the primary mechanisms for lawfully transferring personal data to third countries that do not have an Adequacy Decision from the European Commission.
Does completing this checklist guarantee GDPR compliance?
No. This tool is a structured reference and self-assessment aid, not a legal compliance certification. GDPR compliance depends on the specific nature of your data processing activities, your jurisdiction, and evolving regulatory guidance. This checklist helps you identify gaps and organize your compliance efforts, but you should consult a qualified data protection lawyer or consultant for a formal compliance assessment.
Is my compliance data saved after I close the browser?
No. All checkbox state is stored only in the browser's React component state for your current session. When you close the tab or browser, your progress is not saved. No data is written to localStorage, cookies, or any server. For persistent tracking, take a screenshot of your progress or use a dedicated compliance management platform.