Your company has a privacy policy. You added a cookie banner. You ticked the visible boxes.
That is not GDPR compliance.
This is the most common misconception among companies that process EU personal data. A privacy policy is one document among many. A GDPR compliance checklist covers a programme – a set of documented processes, controls, and records. You maintain these continuously, not once and then forget.
Here is what that programme actually requires.
1. Record of processing activities (ROPA)
The ROPA is the document most companies are missing – and the first thing a regulator or enterprise buyer will ask for.
Under GDPR Article 30, any organisation with more than 250 employees must maintain a ROPA. Smaller organisations are technically exempt from the strict requirement, but are still expected to maintain records sufficient to demonstrate compliance. In practice, regulators treat the absence of a ROPA as a gap regardless of company size.
A ROPA entry documents:
- What personal data you collect
- The purpose of processing
- The legal basis for that processing
- How long you retain it
- Who you share it with
If you cannot answer those questions for each data category your company processes, you do not have a functioning GDPR programme.
Without a current, accurate data map, no other compliance activity can be performed reliably. This is consistently the first item supervisory authorities request during audits.
2. Legal basis for processing
This is the element most often documented incorrectly.
GDPR requires you to identify and document a legal basis for every category of personal data you process. The six legal bases are:
- Consent
- Contract performance
- Legal obligation
- Vital interests
- Public task
- Legitimate interests
Consent is the default assumption for many companies – and often the wrong choice. It is the hardest to maintain correctly and the easiest to get wrong. Processing necessary for contract performance, or based on legitimate interests properly assessed, is often more appropriate and more sustainable.
Getting this wrong is expensive. The Italian data protection agency fined a San Francisco-based startup EUR 5.64 million for processing user data without a legal basis. Size does not protect you.
3. Data processing agreements (DPAs)
Third-party vendors require Data Processing Agreements and ongoing oversight. This applies to every third party that processes personal data on your behalf – your cloud provider, your CRM, your analytics platform, your payment processor, your support tool.
A DPA specifies what the processor can do with the data and the security measures they must maintain. It also covers what happens in the event of a breach.
Most startups have DPAs with two or three major vendors and ignore the rest. A project management tool storing client names and a support platform processing ticket conversations both require DPAs.
If you are using third-party tools that handle personal data without signed DPAs, that gap shows up immediately in any due diligence review.
4. Data subject request process
GDPR gives individuals rights over their data – the right to access, correct, delete, and port it. You have 30 days to respond to most requests.
The process for handling these requests needs to be mapped and tested before you receive a real one. That means knowing:
- Who receives the request
- Where personal data lives across all your systems
- How to extract or delete it when asked
Most companies document this process but never test it. Testing it once – before a real request arrives – takes less than a day and removes a significant compliance risk.
5. Breach response: the 72-hour clock
If you discover a personal data breach that poses a risk to individuals, you must notify the relevant supervisory authority within 72 hours. That clock starts the moment you become aware of the breach – not when the investigation concludes.
That requires a tested incident response plan with clear answers to three questions:
- Who decides whether a breach is reportable?
- Who drafts the notification?
- Who has authority to submit it?
Companies without this process often miss the window. A missed 72-hour notification is itself a regulatory finding, separate from the breach.
6. What regulators actually look for
According to the CNIL’s annual activity report, 42% of enforcement actions cited deficiencies in accountability documentation, even where substantive compliance was arguably present. Compliance that cannot be proven is, in regulatory terms, non-compliance.
The lesson is not that you need perfect systems. It is that you need documented systems. Records that show you assessed your risks, made conscious decisions about legal bases, and have processes in place.
The point where this becomes expensive
The gap between a privacy policy and a real GDPR compliance checklist becomes visible at due diligence.
When an enterprise client or investor reviews your GDPR programme during procurement or M&A, missing documentation is a finding that delays or blocks deals. No ROPA, undocumented legal bases, missing DPAs – each one is a red flag. Building the programme properly before that moment costs significantly less than repairing it under time pressure.
The ICO’s guidance on accountability is useful reading if you want to understand what regulators expect to see in practice.
Your GDPR compliance checklist: the minimum
Before you consider your programme functional, check these off:
- Record of Processing Activities (ROPA) – documented and current
- Legal basis identified and documented for each processing activity
- Data Processing Agreements signed with all vendors handling personal data
- Data subject request process mapped and tested
- Breach response plan written and tested
- Privacy policy accurate and reflecting your actual processing
If any of these are missing or untested, that is where to start.
How Riskora can help
If your company processes EU personal data and you are not confident your programme covers all of the above, contact us. Reach us at support@riskora.io or book a call at calendly.com/riskora to find out where the gaps are.