Knowledge base
GDPR: documentation and compliance requirements
Everything GDPR requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
Prem Kumar Dvivedi · 12 September 2026
This is what GDPR requires you to have, clause by clause, and what an auditor will ask to see for each of it. It covers 60 requirements across 8 areas.
It is deliberately not a checklist. A checklist asks whether you have something; this says what is required and what counts as evidence, which is the question that matters when you are building a system rather than testing one. If you would rather find out where you stand first, the same ground is covered by our free GDPR readiness assessment, which scores you out of 100.
Where you stand under the Regulation
Clauses Art. 4, Art. 3, Art. 27, Art. 30.
You must be able to answer: For each thing you do with personal data, do you decide why and how it is used, or do you act on someone else's instructions?
Evidence: A written note per activity: controller, joint controller, or processor. What the contract calls you does not settle it — whoever decides the purposes and means is the controller. Settle this first.
You must have worked out whether the GDPR applies to you at all.
Evidence: Territorial scope analysis: are you established in the EU, do you offer goods or services to people in the EU, or do you monitor their behaviour?
If you are outside the EU and caught by the Regulation, you must have appointed a representative in the Union.
Evidence: The written designation, with the details published in your privacy notice. N/A with a reason if you are established in the EU or the exemption applies.
You must keep a record of your processing activities in the form the Regulation sets out.
Evidence: The Article 30 record with all the required content: who you are, the purposes, the categories of people and of data, who you share with, transfers and their safeguard, retention periods, and a description of your security measures. A spreadsheet listing your systems is not an Article 30 record, and this is the first thing most regulators ask for.
That record must be current, in writing, and you must be able to hand it to a regulator today.
Evidence: Revision history. Availability on request.
Having a lawful reason to use the data
Clauses Art. 6, Art. 9, Art. 10, Art. 7.
You must have identified a lawful basis for every processing activity.
Evidence: The basis recorded per activity in your Article 30 record.
Where you rely on legitimate interests, you must have done and written up the balancing test.
Evidence: A legitimate interests assessment covering the purpose, the necessity and the balance, dated.
You must be able to show that the basis fixed before you started, rather than chosen afterwards.
Evidence: Evidence the basis was settled up front. Swapping basis after the fact is not permitted.
It must be defined where you handle special category data — health, race, religion, politics, union membership, biometrics, sex life — you must have identified the extra condition that allows it.
Evidence: The Article 9(2) condition per activity. Any additional national law condition, plus an appropriate policy document where the member state requires one.
Where you handle criminal offence data, you must be allowed to.
Evidence: The official authority or legal authorisation relied on. N/A with a reason if you handle none.
Where you rely on consent, you must be able to show it was freely given, specific, informed and given by a clear action.
Evidence: Consent records showing what, when, how, and which notice version was shown. No pre-ticked boxes.
You must be able to show that the consent request kept separate from your other terms, in clear language.
Evidence: The consent screen or form.
People must be able to withdraw as easily as they gave consent, and you must act when they do.
Evidence: The withdrawal route and records of withdrawals actioned.
You must avoid relying on consent where it cannot really be free — for example from your own staff.
Evidence: Review of where consent is used. In the employment context consent is rarely freely given.
Telling people what you do
Clauses Art. 13, Art. 14, Art. 12.
Where you collect data from the person, you must tell them everything the Regulation requires, at the time.
Evidence: The privacy notice checked against the Article 13 list: who you are, the DPO, the purposes and basis, legitimate interests if relied on, recipients, transfers and safeguards, retention, all the rights, the right to withdraw consent, the right to complain, whether providing the data is required, and any automated decision-making with meaningful information about the logic.
Where you get data from somewhere else, you must tell the person within a month, or at first contact.
Evidence: The Article 14 notice including the categories of data and the source. Evidence of the timing.
The must be notice concise, clear and easy to find, in plain language.
Evidence: The notice as it actually appears. A layered design where it is long.
You must keep old versions, so you know what each person was shown.
Evidence: Version history with dates.
People's rights
Clauses Art. 15, Art. 16, Art. 17, Art. 18, Art. 19, Art. 20, Art. 21, Art. 22, Art. 12(3), Art. 12(5).
People must be able to get access to their data and a copy of it.
Evidence: A request procedure with proportionate identity checks. A register with dates. A sample response including the Article 15 information as well as the data.
Your search must cover everywhere the data actually lives — email, tickets, backups, analytics, third-party platforms.
Evidence: The systems searched. Searching only the main database is the usual shortfall.
People must be able to get inaccurate data corrected and incomplete data completed.
Evidence: Correction records.
People must be able to get their data erased where they are entitled to it.
Evidence: Erasure records showing the data actually went, including from backups and downstream systems. Refusals recorded with the specific exemption relied on.
People must be able to ask you to restrict processing rather than delete it.
Evidence: Restriction records and how restriction is enforced in the systems.
You must tell the people you shared the data with when you correct, erase or restrict it.
Evidence: Records showing recipients were notified.
People must be able to get their data in a portable, machine-readable form where the right applies.
Evidence: Portability records and the format used.
People must be able to object to processing — and you must stop direct marketing immediately when they do.
Evidence: Objection records. A suppression list honoured across every channel and every system.
You must have identified any decision made purely by a machine that has legal or similarly significant effects.
Evidence: The activities identified, the Article 22(2) ground relied on, and the safeguards: human intervention, the right to express a view and the right to contest.
Where you claim a human is involved, that involvement must be real rather than a rubber stamp.
Evidence: Override rates. Review times. Cases where the human decided differently.
You must answer requests within one month, and record any extension properly.
Evidence: Elapsed times for every request in the last year. Extensions notified inside the first month with the reason. This is the most frequently missed deadline in the whole Regulation, and it is trivially provable from your own register.
Responses must be free unless the request is unfounded or excessive, and is any refusal justified.
Evidence: Fee or refusal decisions recorded with reasons.
Building privacy in, and keeping data no longer than needed
Clauses Art. 25, Art. 35, Art. 36, Art. 5(1)(c), Art. 5(1)(e).
Privacy must be considered at the design stage of anything new, before it is built.
Evidence: Privacy requirements in project, design and procurement gates, with real examples.
The default settings the must be private ones — least data, least sharing, least visibility.
Evidence: Default configuration evidence.
You must know when a data protection impact assessment is required, and you must do them.
Evidence: Screening criteria covering the Article 35(3) cases and your regulator's published list. Completed assessments.
The assessments must cover the processing, whether it is necessary and proportionate, the risks to people, and what you will do about them.
Evidence: The four required elements. The DPO's advice recorded. Views of the people affected sought where appropriate.
Where the risk stays high after your measures, you must consult the supervisory authority first.
Evidence: Prior consultation correspondence. N/A with a reason if this has not arisen.
You must collect only what you actually need.
Evidence: Minimisation review of forms, fields and data structures.
You must have retention periods, and is data actually deleted or anonymised when they expire.
Evidence: A retention schedule with justification per category. Evidence of real deletion, including backups, archives, email and test environments.
Where you say data is anonymised, it must be genuinely impossible to re-identify.
Evidence: The method. Reversible pseudonymisation is still personal data and still in scope.
Security and breaches
Clauses Art. 32, Art. 33, Art. 33(5), Art. 34, Art. 28, Art. 28(2), Art. 26.
Your security measures must be appropriate to the risk, and written down.
Evidence: The measures mapped to assessed risk: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, and the ability to restore after an incident.
You must regularly test, assess and evaluate whether those measures actually work.
Evidence: Penetration tests, vulnerability scans and restore tests on a schedule. This is an express requirement and it is often simply absent.
You must be able to detect a breach, and does everyone know how to report a suspected one.
Evidence: Detection arrangements. A reporting route for staff and processors.
You must notify the supervisory authority within 72 hours of becoming aware, where the threshold is met.
Evidence: Notifications with timestamps. The clock runs from awareness, not from confirming the impact. Phased notification where the facts are not yet clear.
You must record every breach, including the ones you decided not to notify.
Evidence: An internal breach register with the facts, the effects and the remedial action for each. This is required regardless of whether you notify.
Where the risk to people is high, you must tell them without undue delay, in plain language.
Evidence: Communications sent, with dates and content. Any exemption relied on, with the reasoning.
Where a processor works for you, the contract must contain every term Article 28(3) requires.
Evidence: The contract checked against all of them: documented instructions, confidentiality, security, sub-processor conditions, assistance with rights, assistance with security and breaches, deletion or return, and audit rights.
You must have check the processor could actually deliver, before signing.
Evidence: Due diligence evidence, not just a signed contract.
Sub-processors must be authorised, and are the same duties passed down.
Evidence: The sub-processor list. The authorisation basis. Evidence changes were notified and objections handled. Back-to-back contracts.
If you are a joint controller, there must be an arrangement setting out who does what, and is its essence available to people.
Evidence: The joint controller arrangement. The essence published. N/A with a reason — but note joint controllership arises more often than parties expect, especially in marketing and platform relationships.
Sending data outside the EEA
Clauses Ch. V, Art. 49.
You must know every transfer of personal data outside the EEA.
Evidence: A transfer register with the recipient, the country and the mechanism. Include support access, hosting regions and sub-processor chains — that is where the unmapped transfers usually sit.
Each must transfer have a lawful mechanism.
Evidence: Adequacy decisions cited with their current status. Standard contractual clauses in the 2021 form, with the right module and the annexes actually filled in.
You must have assessed whether the destination country's law undermines the safeguards.
Evidence: Transfer impact assessments per destination and recipient, considering public authority access.
Where the assessment says the safeguards are not enough, you must have added extra measures.
Evidence: Supplementary technical, contractual or organisational measures — for example encryption with the keys held in the EEA. Records where a transfer was stopped.
Where you rely on a derogation, it must be genuinely occasional and non-repetitive.
Evidence: The conditions documented. Derogations cannot cover routine transfers.
Governance and being able to prove it
Clauses Art. 37, Art. 38, Art. 5(2), Art. 42, Art. 31, Art. 83.
You must have assessed whether you must appoint a data protection officer.
Evidence: The assessment against the three mandatory cases.
You must be able to answer: If you have one, do they report to the highest level, work without instruction, and have no conflicting role?
Evidence: The reporting line. Evidence of independence. A conflict of interest analysis — a DPO who also runs IT, HR, legal or security is a recognised conflict.
The must be DPO involved early in anything affecting personal data, and given the resources to act.
Evidence: Evidence of involvement in projects and decisions. Their details notified to the supervisory authority and published.
You must be able to DEMONSTRATE compliance, rather than assert it.
Evidence: The policy set with approval and review dates. Training records covering all staff and contractors, differentiated by role. Governance minutes. Internal audit or compliance monitoring with findings closed.
If you or your suppliers claim GDPR certification, it must be genuinely an Article 42 certification.
Evidence: The approved scheme and the accredited certification body named. Anything else carries no legal weight, and claiming otherwise is itself a risk. N/A if no such claims are made.
You must be able to cooperate with a supervisory authority at short notice.
Evidence: A published complaints route. Your lead supervisory authority identified with the reasoning. Complaint and regulatory correspondence register. An evidence file that could be produced quickly.
Senior management must know the size of the exposure.
Evidence: Evidence the board has been told. Fines reach the higher of €20 million or 4% of total worldwide annual turnover.
Using this document
Nothing above asks for a manual, a template pack, or a filing system. It asks for decisions that have been taken deliberately and can be shown to have been taken — which is a far smaller job than most organisations expect, and a different one.
Length is not compliance. A procedure nobody follows is worse than no procedure, because an auditor finds the gap between the two. The test we apply is whether the person who has to do the job recognises their own work in what is written down.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for GDPR, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- DPDP Act: documentation and compliance requirements
Everything DPDP Act requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
- HIPAA: documentation and compliance requirements
Everything HIPAA requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
- ISO 13485:2016: documentation and compliance requirements
Everything ISO 13485:2016 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
