GDPR is a program, not a certificate. Here's a practical checklist of what you need in place to handle EU personal data.
The checklist
- Map your data. Maintain a Record of Processing Activities (RoPA) — what personal data you hold, why, and where it flows.
- Establish a lawful basis for each processing activity (consent, contract, legitimate interest, etc.).
- Handle data-subject rights. A process to fulfil access, deletion, rectification and portability requests within the required timelines.
- Manage consent where it's your basis — clear, granular, withdrawable.
- Sign DPAs with processors and keep a subprocessor list.
- Control international transfers — keep EU data in-region where required.
- Secure the data. Encryption, access control, and the technical/organizational measures GDPR expects.
- Breach notification. A process to notify authorities within 72 hours where required.
- Appoint a DPO if your processing requires one.
Where residency mattersGDPR restricts transfers of EU personal data. A self-hosted, region-locked deployment keeps data exactly where it should be — removing an entire category of transfer risk.
A practical starting checklist, not legal advice. Confirm your GDPR obligations with your compliance and legal teams.