Regmindr
Templates

Data protection compliance checklist

Data protection · 6 deadlines

GDPR asks you to keep your records, notices and assessments accurate, but rarely says how often to check them. This template adds the reviews most firms run once a year: the record of processing activities, privacy notices, staff training, processor agreements, data retention and data protection impact assessments.

The deadlines in this template

  • Annual record of processing activities reviewInternal · Once a year, on your own date

    Check that your record of processing activities still matches what personal data you collect, why, where it goes and how long you keep it.

  • Annual privacy notice reviewInternal · Once a year, on your own date

    Review your privacy notices against the record of processing activities and update them for any new purposes, recipients or retention periods.

  • Annual data protection staff trainingInternal · Once a year, on your own date

    Train staff on handling personal data and spotting data breaches, and keep a record of who completed it.

  • Annual processor and data-sharing agreement reviewInternal · Once a year, on your own date

    Review the suppliers that process personal data for you and the agreements with them, including where they store the data.

  • Annual data retention and deletion reviewInternal · Once a year, on your own date

    Check that personal data past its retention period has been deleted or anonymised, as your retention schedule says.

  • Annual review of data protection impact assessmentsInternal · Once a year, on your own date

    Review the impact assessments for high-risk processing and update them if the processing or its risks have changed.

Download this checklist

Get these tasks as a spreadsheet, with columns for your own dates, owners and evidence, free.

6 deadlines

Where the duties come from

UK GDPR and EU GDPR cover the record of processing activities (Art. 30), privacy information (Arts. 13 and 14), processor contracts (Art. 28) and storage limitation (Art. 5(1)(e)). DPIAs are reviewed at least when the risk of the processing changes (Art. 35(11)). A yearly review on a fixed date shows you keep all of them current.

The ICO fee

UK organisations that process personal data also pay the ICO data protection fee every year, unless they're exempt. It's in the UK limited company template.

Start with this template

Pick this template when you set up Regmindr, tick the deadlines that apply and check each date. Your team gets an email before each one is due.

Sources

This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.

Related