← All cheat sheets

GDPR-CHECKLIST

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

- General Data Protection Regulation (EU) 2016/679
- Effective since May 25, 2018
- Applies to any organization processing personal data of EU/EEA residents
- Applies regardless of where the organization is based
- Supersedes the 1995 Data Protection Directive

DATA PROCESSING PRINCIPLES (ARTICLE 5)#

1. Lawfulness, Fairness, and Transparency
   - Processing must have a legal basis
   - Individuals must be informed about how data is used

2. Purpose Limitation
   - Data collected for specified, explicit, and legitimate purposes
   - No further processing incompatible with original purpose

3. Data Minimization
   - Only collect data that is adequate, relevant, and necessary

4. Accuracy
   - Personal data must be accurate and kept up to date
   - Inaccurate data must be erased or rectified without delay

5. Storage Limitation
   - Data kept only as long as necessary for the purpose
   - Define and enforce retention periods

6. Integrity and Confidentiality
   - Appropriate security measures to protect personal data
   - Protection against unauthorized access, loss, or destruction

7. Accountability
   - Controller must demonstrate compliance with all principles

LAWFUL BASIS FOR PROCESSING (ARTICLE 6)#

[ ] Consent - freely given, specific, informed, unambiguous
[ ] Contract - necessary for performance of a contract
[ ] Legal Obligation - required by EU or member state law
[ ] Vital Interests - necessary to protect someone's life
[ ] Public Task - necessary for official authority or public interest
[ ] Legitimate Interests - necessary for legitimate interests (balance test required)

Note: Consent for children under 16 requires parental authorization (Article 8)
Note: Special categories (Article 9) require explicit consent or specific exemption

SPECIAL CATEGORY DATA (ARTICLE 9)#

Requires additional legal basis to process:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data (for identification)
- Health data
- Sex life or sexual orientation

DATA SUBJECT RIGHTS#

[ ] Right to be Informed (Articles 13-14)
    - Privacy notice with identity, purposes, legal basis, recipients, transfers
    - Must be provided at time of collection or within 1 month

[ ] Right of Access (Article 15)
    - Confirm whether data is being processed
    - Provide copy of personal data within 1 month
    - Information about purposes, categories, recipients, retention

[ ] Right to Rectification (Article 16)
    - Correct inaccurate data without undue delay
    - Complete incomplete data

[ ] Right to Erasure / Right to be Forgotten (Article 17)
    - Delete data when no longer necessary, consent withdrawn, or unlawful
    - Not absolute - may conflict with legal obligations

[ ] Right to Restriction (Article 18)
    - Restrict processing while accuracy is contested or processing is unlawful

[ ] Right to Data Portability (Article 20)
    - Receive data in structured, commonly used, machine-readable format
    - Applies when processing is based on consent or contract AND is automated

[ ] Right to Object (Article 21)
    - Object to processing based on legitimate interests or public task
    - Absolute right to object to direct marketing

[ ] Rights Related to Automated Decision-Making (Article 22)
    - Right not to be subject to solely automated decisions with legal effects
    - Right to human intervention, express views, contest decision

DATA PROTECTION IMPACT ASSESSMENT (DPIA) - ARTICLE 35#

Required when processing is likely to result in HIGH RISK:
[ ] Systematic and extensive profiling with significant effects
[ ] Large-scale processing of special category data
[ ] Systematic monitoring of publicly accessible areas
[ ] New technologies that pose high risk

DPIA Must Include:
[ ] Systematic description of processing operations and purposes
[ ] Assessment of necessity and proportionality
[ ] Assessment of risks to rights and freedoms
[ ] Measures to address risks (safeguards, security, mechanisms)

Prior consultation with supervisory authority (Article 36) if risk
cannot be sufficiently mitigated

BREACH NOTIFICATION (ARTICLES 33-34)#

Notification to Supervisory Authority (Article 33):
[ ] Notify within 72 HOURS of becoming aware of the breach
[ ] Include: nature of breach, categories/numbers of data subjects
[ ] Include: likely consequences and measures taken/proposed
[ ] If not possible within 72 hours, provide reasons for delay
[ ] Document ALL breaches regardless of notification requirement

Notification to Data Subjects (Article 34):
[ ] Required when breach likely results in HIGH RISK to rights/freedoms
[ ] Must be in clear and plain language
[ ] Describe nature of breach and likely consequences
[ ] Describe measures taken to address the breach
[ ] Not required if: data was encrypted, subsequent measures eliminate risk,
    or it would involve disproportionate effort (use public communication)

BREACH RESPONSE CHECKLIST#

[ ] Detect and contain the breach immediately
[ ] Assess risk to individuals (likelihood and severity)
[ ] Document the breach in internal breach register
[ ] Notify supervisory authority within 72 hours (if required)
[ ] Notify affected individuals without undue delay (if high risk)
[ ] Conduct post-incident review and implement improvements

DATA PROTECTION OFFICER (DPO) - ARTICLES 37-39#

DPO Required When:
[ ] Processing carried out by a public authority or body
[ ] Core activities require regular and systematic monitoring at scale
[ ] Core activities involve large-scale processing of special categories

DPO Requirements:
[ ] Expert knowledge of data protection law and practices
[ ] Must be independent - no conflict of interest
[ ] Must report to highest management level
[ ] Must be provided with adequate resources
[ ] Contact details published and communicated to supervisory authority

CROSS-BORDER TRANSFER MECHANISMS (CHAPTER V)#

[ ] Adequacy Decision (Article 45)
    - EU Commission determines adequate protection level
    - Current: Japan, UK, South Korea, Switzerland, Canada (commercial),
      Israel, New Zealand, Argentina, Uruguay, and others

[ ] Standard Contractual Clauses (SCCs) (Article 46)
    - EU Commission-approved contract terms
    - Updated SCCs adopted June 2021 (modular approach)
    - Requires Transfer Impact Assessment (TIA)

[ ] Binding Corporate Rules (BCRs) (Article 47)
    - Intra-group transfers for multinational organizations
    - Must be approved by competent supervisory authority

[ ] EU-US Data Privacy Framework (Article 45)
    - Adequacy decision adopted July 2023
    - Replaces Privacy Shield (invalidated by Schrems II)
    - US organizations must self-certify

[ ] Derogations (Article 49)
    - Explicit consent, contractual necessity, public interest
    - Only for occasional, non-repetitive transfers

TECHNICAL AND ORGANIZATIONAL MEASURES (ARTICLE 32)#

[ ] Pseudonymization of personal data
[ ] Encryption of personal data (at rest and in transit)
[ ] Ability to ensure confidentiality, integrity, availability, resilience
[ ] Ability to restore access to personal data in a timely manner
[ ] Regular testing and evaluation of security measures
[ ] Access controls and authentication mechanisms
[ ] Logging and monitoring of data processing activities
[ ] Data backup and disaster recovery procedures
[ ] Secure development practices (privacy by design)
[ ] Vendor and third-party security assessments

DATA PROTECTION BY DESIGN AND DEFAULT (ARTICLE 25)#

[ ] Integrate data protection into processing activities from the start
[ ] Default settings must be privacy-friendly
[ ] Only process data necessary for each specific purpose
[ ] Data not made accessible to unlimited number of people by default
[ ] Consider: state of art, cost, nature/scope/context, risks

RECORDS OF PROCESSING ACTIVITIES (ARTICLE 30)#

Controllers must maintain records including:
[ ] Name and contact details of controller and DPO
[ ] Purposes of processing
[ ] Categories of data subjects and personal data
[ ] Categories of recipients
[ ] Transfers to third countries and safeguards
[ ] Retention periods
[ ] Description of technical and organizational security measures

PENALTIES AND FINES#

Tier 1 (Lower): Up to 10 million EUR or 2% of global annual turnover
  - Violations of controller/processor obligations
  - Certification body obligations
  - Monitoring body obligations

Tier 2 (Higher): Up to 20 million EUR or 4% of global annual turnover
  - Violations of data processing principles
  - Violations of data subject rights
  - Violations of transfer provisions
  - Non-compliance with supervisory authority orders

Notable Fines:
  - Meta (Ireland): 1.2 billion EUR (2023) - data transfers
  - Amazon (Luxembourg): 746 million EUR (2021) - targeting
  - WhatsApp (Ireland): 225 million EUR (2021) - transparency

SECURITY TEAM ACTION ITEMS#

[ ] Maintain data inventory and data flow maps
[ ] Implement encryption for personal data at rest and in transit
[ ] Deploy access controls with least privilege principle
[ ] Enable logging and monitoring for personal data access
[ ] Establish and test breach detection and notification procedures
[ ] Conduct regular vulnerability assessments and penetration tests
[ ] Review and update retention policies and enforce deletion
[ ] Ensure secure disposal of media containing personal data
[ ] Include GDPR requirements in vendor security assessments
[ ] Participate in DPIAs for new systems handling personal data
[ ] Maintain documentation for accountability obligations