Many GDPR programmes were built in one burst before May 2018 and then left to drift. The privacy notice still describes systems that were retired years ago, the records of processing miss the SaaS tools the business now runs on, and nobody can prove when the last access request was answered.
The GDPR does not set an audit date. It requires you to demonstrate compliance and to review your measures where necessary, and an annual audit is the usual way to do that. This free GDPR compliance audit checklist is for DPOs, privacy leads and internal auditors in organisations subject to the EU GDPR, the UK GDPR or both. Seven phases cover the data inventory, lawful basis and transparency, data subject rights, processors, international transfers, security and DPIAs, and accountability. The audit ends in a rated findings report, management sign-off and a remediation plan with an owner and date for every action.
Privacy operations answer this week’s access request and sign this month’s processor contract. The audit steps back once a year and tests whether the whole system still holds together: whether the records of processing match reality, whether every purpose has a lawful basis someone actually assessed, and whether the evidence would satisfy a regulator under the accountability principle in Article 5(2).
Until recently the EU and UK texts were close enough to audit as one. The UK’s Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and most of its changes to the UK GDPR took effect on 5 February 2026. A UK or cross-border organisation now tests the same topics against two slightly different rulebooks. The checklist asks which regimes apply at the start and shows or hides the UK-specific steps to match.
EU GDPR
Regulation (EU) 2016/679, as adopted in 2016
Regulator: the lead or local supervisory authority in each member state.
Access requests: one month from receipt, extendable by two further months for complex or numerous requests.
Transfers: adequacy decisions, the 2021 Standard Contractual Clauses, or another Chapter V safeguard.
Watch: the Digital Omnibus proposal, which is not law.
UK GDPR after the DUAA
The UK version, amended from 5 February 2026
Regulator: the ICO, whose functions pass to the new Information Commission on 30 September 2026.
Access requests: the clock can pause while you seek clarification, and the requester gets what a reasonable and proportionate search finds.
New duties: a complaints procedure for data subjects, required from 19 June 2026.
Lawful basis: a new list of recognised legitimate interests.
What the GDPR Audit Checklist Covers
Seven phases take the audit from scoping to a signed report. The transfers phase and UK-only steps depend on the Phase 1 answers.
Phase 1
Phase 1: Scope & Data Inventory
The first task’s scope answers drive the conditional steps in Phases 3 and 5.
Set the audit scope and applicable regimes — record the audit period, the legal entities and systems in scope, and whether EU GDPR, UK GDPR or both apply
Carry forward last year’s findings — list every open action from the previous audit and confirm its status with evidence, not a verbal update
Refresh the data inventory with system owners — capture every new SaaS tool, AI service and data flow introduced since the last audit
Reconcile the inventory to the Article 30 records — every system and purpose appears, with separate records where the organisation also acts as a processor
Test any reliance on the Article 30(5) exemption — it covers organisations under 250 staff only where processing is occasional, low-risk and excludes special category or criminal offence data
Phase 2
Phase 2: Lawful Basis, Consent & Transparency
Confirm a documented lawful basis for every purpose — an Article 6 basis for each line of the records, plus an Article 9 condition for special category data
Review legitimate interests assessments — each one current and balanced; for UK processing, note where a recognised legitimate interest under Article 6(1)(ea) now applies
Sample consent records — consent is specific and recorded, withdrawal is as easy as giving it, and withdrawals reach every marketing system
Compare privacy notices with the records of processing — every purpose, recipient, retention period and transfer in the record is described under Articles 13 and 14
Check cookie consent against what the site actually sets — scan the live site and compare it with the banner and the cookie policy
Phase 3
Phase 3: Data Subject Rights & Complaints
The last two tasks appear only when the UK GDPR applies.
Pull the rights request log for the audit period — volumes by right, response times, extensions, refusals and fees charged
Test response times against the one-month deadline — extensions of up to two further months only for complex or numerous requests, and the requester told within the first month
Sample completed access requests — identity checks proportionate, searches complete, third-party data redacted and the reply explains the requester’s rights
Trace erasure and objection requests to every system — including processors, CRM exports and marketing suppression lists
UK: check use of the stop-the-clock rule — pauses only while clarification was reasonably required to identify the information requested, under Article 12A
UK: confirm the data protection complaints procedure — an easy way to complain, such as an online form, acknowledgement within 30 days and a recorded outcome, under DPA 2018 section 164A
Phase 4
Phase 4: Processors & Article 28 Contracts
Reconcile the processor list to supplier payments — find the tools bought on a company card that never reached the privacy team
Check each processor contract covers Article 28(3) — documented instructions, confidentiality, security, sub-processor terms, assistance, deletion or return and audit rights
Review sub-processor change notices received in the period — each one assessed, and objections raised where the change adds risk
Confirm processors must report breaches to you without undue delay — the contract sets a timescale that leaves you room to meet your own deadline
Flag processors due a security reassessment — pass them to the vendor risk process rather than re-running due diligence inside the audit
Phase 5 — If Transfers
Phase 5: International Transfers
Shown only when Phase 1 records that personal data leaves the UK or EEA.
List every restricted transfer — destination, importer, data categories and purpose, including sub-processors and support access
Record the transfer mechanism for each — adequacy, EU Standard Contractual Clauses, the UK IDTA or Addendum, binding corporate rules or an Article 49 derogation
Verify US importers on the Data Privacy Framework List — certification active, and for UK data, signed up to the UK Extension
Check transfer risk assessments are on file and current — reviewed when the destination’s law or the importer’s processing changes
Document a fallback for each DPF-reliant transfer — which clauses you would switch to if the framework were struck down
Phase 6
Phase 6: Security, Breach Readiness & DPIAs
Review Article 32 security measures against current risk — access reviews, encryption, MFA, backups and test results, evidenced by IT rather than self-declared
Review the breach register — every incident recorded under Article 33(5), including those not notified, with the reasoning for the decision
Test the 72-hour notification clock — for each notified breach, time from awareness to notification, with reasons recorded for any delay
Run a breach decision tabletop — who decides whether to notify the regulator, and when a high risk means telling individuals under Article 34
Check the DPIA register — each high-risk processing started in the period had a DPIA before it began, with mitigations tracked to closure
Screen new projects against Article 35(3) and the regulator’s list — profiling with significant effects, large-scale special category data, large-scale public monitoring
Phase 7
Phase 7: Accountability, Report & Remediation
Assigned to the DPO or privacy lead; sign-off sits with a named senior manager.
Confirm the DPO position — designated where Article 37(1) requires it, reporting to the highest management level, free of conflicts; or record why none is required
Confirm representatives and registrations — an Article 27 representative where required and, for UK controllers, the data protection fee paid unless exempt
Check training and policy reviews — completion against target and every data protection policy reviewed within its stated cycle
Rate each finding and draft the audit report — high, medium or low, with the article reference, an owner and a due date
Present the report and obtain management sign-off — record decisions, accepted risks and who accepted them
Schedule the remediation follow-up — re-test high-rated findings within a quarter rather than waiting for next year’s audit
The table maps each obligation the audit tests to its source in each regime and to the phase that produces the evidence. Article numbers are the same in both texts unless shown otherwise. Your obligations depend on what you process and where, so treat the table as a starting point, not legal advice.
Art. 12A time periods; Art. 15(1A) reasonable and proportionate search
Phase 3
Complaints
To the supervisory authority, Art. 77
Also to the controller, DPA 2018 s.164A
Phase 3
Processors
Art. 28(3)
Same
Phase 4
International transfers
Chapter V; SCCs under Decision (EU) 2021/914
Arts. 44A–45A data protection test; IDTA or Addendum
Phase 5
Security and breaches
Arts. 32–34; 72 hours to the supervisory authority
Same, notified to the ICO
Phase 6
DPIAs
Arts. 35–36
Same
Phase 6
Data protection officer
Arts. 37–39
Same
Phase 7
Three things were moving at the time of review. The Commission’s Digital Omnibus proposal of 19 November 2025 would require breach notification to the authority only for high-risk breaches, within 96 hours, through a single reporting point. It is still at first reading without a Council position, so the 72-hour rule stands. A separate May 2025 proposal would widen the records-of-processing exemption beyond 250 staff; it is not in force either. And the EU-US Data Privacy Framework faces an appeal to the Court of Justice (Case C-703/25 P).
Why Run Your GDPR Audit in CheckFlow?
1
The scope answers shape the audit
Answer the Phase 1 questions and conditional logic shows the UK complaints and stop-the-clock steps only when the UK GDPR applies, and the transfers phase only when data leaves the UK or EEA. A UK-only company and an EU group run the same template.
2
Evidence sits on the step it proves
Attach the records export, the sampled access requests, the Article 28 contract and the breach register to the task they support. Every task records who completed it and when, and management sign-off is an approval step.
3
Next year starts itself
An annual recurring schedule creates the next audit on the same date and assigns Phase 1 to the privacy lead. When the law changes, as it did in the UK in February 2026, template versioning lets you update the checklist once for every future audit.
CheckFlow is not a GRC platform, a data discovery scanner or a consent management tool, and it does not certify GDPR compliance. It runs the audit steps, holds the evidence and tracks the actions. CheckFlow’s compliance checklist software shows the same approach across the rest of your compliance calendar.
Neither the EU GDPR nor the UK GDPR sets a frequency. Article 24 requires controllers to review and update their measures where necessary, and Article 5(2) requires them to be able to demonstrate compliance at any time. Annual is the common baseline because it lines up with board reporting and policy reviews. Add an out-of-cycle review after an acquisition, a new core system, a notifiable breach or a change in the law.
Who should carry out a GDPR compliance audit?
+
Where a DPO is designated, Article 39 includes monitoring compliance, including the related audits, among their tasks, so the DPO usually owns the programme. Independence still matters: the person who wrote the privacy notice should not be the only one testing it. Internal audit or an external adviser can test a sample of phases each year, with senior management signing off the report.
What is the difference between EU GDPR and UK GDPR?
+
The UK GDPR started as a copy of the EU text and has diverged since the Data (Use and Access) Act 2025. The main changes for an audit are recognised legitimate interests, the stop-the-clock rule for access requests, reasonable and proportionate searches, looser rules on automated decisions outside special category data, a new transfer test and a duty to handle complaints. The Commission renewed its adequacy decision for the UK on 19 December 2025, valid until 27 December 2031, so personal data can still flow from the EEA to the UK without extra safeguards.
What are the maximum fines for GDPR non-compliance?
+
Under Article 83 of the EU GDPR, breaches of obligations such as records, security, breach notification and DPIAs can attract up to €10 million or 2% of worldwide annual turnover, whichever is higher. Breaches of the principles, lawful basis, data subject rights and transfer rules can reach €20 million or 4%. The UK GDPR uses the same structure with caps of £8.7 million and £17.5 million. These are ceilings. Regulators weigh factors including cooperation and the measures already in place, which is where a documented audit helps.
Can we still rely on the EU-US Data Privacy Framework?
+
Yes, at the time of review. The Commission’s adequacy decision of 10 July 2023 remains in force, and the General Court dismissed the challenge to it on 3 September 2025. That judgment is under appeal to the Court of Justice, which struck down the two earlier EU-US arrangements. Check each US importer’s active certification on the Data Privacy Framework List, and for UK data its UK Extension, and keep Standard Contractual Clauses ready as a fallback.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
An Audit File That Proves Accountability, Not Just a Policy Folder
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more