GDPR-CHECKLIST
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
- General Data Protection Regulation (EU) 2016/679 - Effective since May 25, 2018 - Applies to any organization processing personal data of EU/EEA residents - Applies regardless of where the organization is based - Supersedes the 1995 Data Protection Directive
DATA PROCESSING PRINCIPLES (ARTICLE 5)#
1. Lawfulness, Fairness, and Transparency - Processing must have a legal basis - Individuals must be informed about how data is used 2. Purpose Limitation - Data collected for specified, explicit, and legitimate purposes - No further processing incompatible with original purpose 3. Data Minimization - Only collect data that is adequate, relevant, and necessary 4. Accuracy - Personal data must be accurate and kept up to date - Inaccurate data must be erased or rectified without delay 5. Storage Limitation - Data kept only as long as necessary for the purpose - Define and enforce retention periods 6. Integrity and Confidentiality - Appropriate security measures to protect personal data - Protection against unauthorized access, loss, or destruction 7. Accountability - Controller must demonstrate compliance with all principles
LAWFUL BASIS FOR PROCESSING (ARTICLE 6)#
[ ] Consent - freely given, specific, informed, unambiguous [ ] Contract - necessary for performance of a contract [ ] Legal Obligation - required by EU or member state law [ ] Vital Interests - necessary to protect someone's life [ ] Public Task - necessary for official authority or public interest [ ] Legitimate Interests - necessary for legitimate interests (balance test required) Note: Consent for children under 16 requires parental authorization (Article 8) Note: Special categories (Article 9) require explicit consent or specific exemption
SPECIAL CATEGORY DATA (ARTICLE 9)#
Requires additional legal basis to process: - Racial or ethnic origin - Political opinions - Religious or philosophical beliefs - Trade union membership - Genetic data - Biometric data (for identification) - Health data - Sex life or sexual orientation
DATA SUBJECT RIGHTS#
[ ] Right to be Informed (Articles 13-14)
- Privacy notice with identity, purposes, legal basis, recipients, transfers
- Must be provided at time of collection or within 1 month
[ ] Right of Access (Article 15)
- Confirm whether data is being processed
- Provide copy of personal data within 1 month
- Information about purposes, categories, recipients, retention
[ ] Right to Rectification (Article 16)
- Correct inaccurate data without undue delay
- Complete incomplete data
[ ] Right to Erasure / Right to be Forgotten (Article 17)
- Delete data when no longer necessary, consent withdrawn, or unlawful
- Not absolute - may conflict with legal obligations
[ ] Right to Restriction (Article 18)
- Restrict processing while accuracy is contested or processing is unlawful
[ ] Right to Data Portability (Article 20)
- Receive data in structured, commonly used, machine-readable format
- Applies when processing is based on consent or contract AND is automated
[ ] Right to Object (Article 21)
- Object to processing based on legitimate interests or public task
- Absolute right to object to direct marketing
[ ] Rights Related to Automated Decision-Making (Article 22)
- Right not to be subject to solely automated decisions with legal effects
- Right to human intervention, express views, contest decision
DATA PROTECTION IMPACT ASSESSMENT (DPIA) - ARTICLE 35#
Required when processing is likely to result in HIGH RISK: [ ] Systematic and extensive profiling with significant effects [ ] Large-scale processing of special category data [ ] Systematic monitoring of publicly accessible areas [ ] New technologies that pose high risk DPIA Must Include: [ ] Systematic description of processing operations and purposes [ ] Assessment of necessity and proportionality [ ] Assessment of risks to rights and freedoms [ ] Measures to address risks (safeguards, security, mechanisms) Prior consultation with supervisory authority (Article 36) if risk cannot be sufficiently mitigated
BREACH NOTIFICATION (ARTICLES 33-34)#
Notification to Supervisory Authority (Article 33):
[ ] Notify within 72 HOURS of becoming aware of the breach
[ ] Include: nature of breach, categories/numbers of data subjects
[ ] Include: likely consequences and measures taken/proposed
[ ] If not possible within 72 hours, provide reasons for delay
[ ] Document ALL breaches regardless of notification requirement
Notification to Data Subjects (Article 34):
[ ] Required when breach likely results in HIGH RISK to rights/freedoms
[ ] Must be in clear and plain language
[ ] Describe nature of breach and likely consequences
[ ] Describe measures taken to address the breach
[ ] Not required if: data was encrypted, subsequent measures eliminate risk,
or it would involve disproportionate effort (use public communication)
BREACH RESPONSE CHECKLIST#
[ ] Detect and contain the breach immediately [ ] Assess risk to individuals (likelihood and severity) [ ] Document the breach in internal breach register [ ] Notify supervisory authority within 72 hours (if required) [ ] Notify affected individuals without undue delay (if high risk) [ ] Conduct post-incident review and implement improvements
DATA PROTECTION OFFICER (DPO) - ARTICLES 37-39#
DPO Required When: [ ] Processing carried out by a public authority or body [ ] Core activities require regular and systematic monitoring at scale [ ] Core activities involve large-scale processing of special categories DPO Requirements: [ ] Expert knowledge of data protection law and practices [ ] Must be independent - no conflict of interest [ ] Must report to highest management level [ ] Must be provided with adequate resources [ ] Contact details published and communicated to supervisory authority
CROSS-BORDER TRANSFER MECHANISMS (CHAPTER V)#
[ ] Adequacy Decision (Article 45)
- EU Commission determines adequate protection level
- Current: Japan, UK, South Korea, Switzerland, Canada (commercial),
Israel, New Zealand, Argentina, Uruguay, and others
[ ] Standard Contractual Clauses (SCCs) (Article 46)
- EU Commission-approved contract terms
- Updated SCCs adopted June 2021 (modular approach)
- Requires Transfer Impact Assessment (TIA)
[ ] Binding Corporate Rules (BCRs) (Article 47)
- Intra-group transfers for multinational organizations
- Must be approved by competent supervisory authority
[ ] EU-US Data Privacy Framework (Article 45)
- Adequacy decision adopted July 2023
- Replaces Privacy Shield (invalidated by Schrems II)
- US organizations must self-certify
[ ] Derogations (Article 49)
- Explicit consent, contractual necessity, public interest
- Only for occasional, non-repetitive transfers
TECHNICAL AND ORGANIZATIONAL MEASURES (ARTICLE 32)#
[ ] Pseudonymization of personal data [ ] Encryption of personal data (at rest and in transit) [ ] Ability to ensure confidentiality, integrity, availability, resilience [ ] Ability to restore access to personal data in a timely manner [ ] Regular testing and evaluation of security measures [ ] Access controls and authentication mechanisms [ ] Logging and monitoring of data processing activities [ ] Data backup and disaster recovery procedures [ ] Secure development practices (privacy by design) [ ] Vendor and third-party security assessments
DATA PROTECTION BY DESIGN AND DEFAULT (ARTICLE 25)#
[ ] Integrate data protection into processing activities from the start [ ] Default settings must be privacy-friendly [ ] Only process data necessary for each specific purpose [ ] Data not made accessible to unlimited number of people by default [ ] Consider: state of art, cost, nature/scope/context, risks
RECORDS OF PROCESSING ACTIVITIES (ARTICLE 30)#
Controllers must maintain records including: [ ] Name and contact details of controller and DPO [ ] Purposes of processing [ ] Categories of data subjects and personal data [ ] Categories of recipients [ ] Transfers to third countries and safeguards [ ] Retention periods [ ] Description of technical and organizational security measures
PENALTIES AND FINES#
Tier 1 (Lower): Up to 10 million EUR or 2% of global annual turnover - Violations of controller/processor obligations - Certification body obligations - Monitoring body obligations Tier 2 (Higher): Up to 20 million EUR or 4% of global annual turnover - Violations of data processing principles - Violations of data subject rights - Violations of transfer provisions - Non-compliance with supervisory authority orders Notable Fines: - Meta (Ireland): 1.2 billion EUR (2023) - data transfers - Amazon (Luxembourg): 746 million EUR (2021) - targeting - WhatsApp (Ireland): 225 million EUR (2021) - transparency
SECURITY TEAM ACTION ITEMS#
[ ] Maintain data inventory and data flow maps [ ] Implement encryption for personal data at rest and in transit [ ] Deploy access controls with least privilege principle [ ] Enable logging and monitoring for personal data access [ ] Establish and test breach detection and notification procedures [ ] Conduct regular vulnerability assessments and penetration tests [ ] Review and update retention policies and enforce deletion [ ] Ensure secure disposal of media containing personal data [ ] Include GDPR requirements in vendor security assessments [ ] Participate in DPIAs for new systems handling personal data [ ] Maintain documentation for accountability obligations