Guide · GDPR

GDPR compliance checklist

GDPR is a program, not a certificate. Here's a practical checklist of what you need in place to handle EU personal data.

The checklist

  • Map your data. Maintain a Record of Processing Activities (RoPA) — what personal data you hold, why, and where it flows.
  • Establish a lawful basis for each processing activity (consent, contract, legitimate interest, etc.).
  • Handle data-subject rights. A process to fulfil access, deletion, rectification and portability requests within the required timelines.
  • Manage consent where it's your basis — clear, granular, withdrawable.
  • Sign DPAs with processors and keep a subprocessor list.
  • Control international transfers — keep EU data in-region where required.
  • Secure the data. Encryption, access control, and the technical/organizational measures GDPR expects.
  • Breach notification. A process to notify authorities within 72 hours where required.
  • Appoint a DPO if your processing requires one.
Where residency mattersGDPR restricts transfers of EU personal data. A self-hosted, region-locked deployment keeps data exactly where it should be — removing an entire category of transfer risk.

A practical starting checklist, not legal advice. Confirm your GDPR obligations with your compliance and legal teams.

See Vallorix on your own infrastructure

Continuous evidence, auditor-ready reports, and controls that stay in your boundary.

Get a demo →
V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect