---
title: GDPR Checklist to Avoid an Auditor's Crosshairs
description: The deadline for GDPR compliance is long past, yet many organizations are not compliant. Here is a GDPR checklist for avoiding the auditor's crosshairs.
image: https://insights.comforte.com/hubfs/Stock%20images/Compliance%20Concept%20on%20Folder%20Register%20in%20Multicolor%20Card%20Index.%20Closeup%20View.%20Selective%20Focus..jpeg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![Compliance Concept on Folder Register in Multicolor Card Index. Closeup View. Selective Focus.](https://insights.comforte.com/hubfs/Stock%20images/Compliance%20Concept%20on%20Folder%20Register%20in%20Multicolor%20Card%20Index.%20Closeup%20View.%20Selective%20Focus..jpeg)](https://insights.comforte.com/how-to-avoid-the-gdpr-auditors-crosshairs)

[Thomas Stoesser](https://insights.comforte.com/author/thomas-stoesser) l Nov 16, 2018 l [GDPR](https://insights.comforte.com/tag/gdpr), [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# GDPR Checklist to Avoid an Auditor's Crosshairs

The General Data Protection Regulation came into effect on May 25, 2018 and while there was tremendous noise around this event and it seemed as if the end is near, the world is still turning. Some people even compared the GDPR deadline to the [Y2K hype](https://en.wikipedia.org/wiki/Year_2000_problem). This, however, is a bad comparison because GDPR – unlike the Y2K bug – was not a singular event that organizations can safely ignore after May 25th has passed. Quite the opposite is true: GDPR is here to stay and ensuring [compliance](https://www.comforte.com/enterprise-data-protection/compliance/) is something that organizations have to consider and monitor continually, so that they don’t forget about it and suddenly find themselves non-compliant in the future. So what areas should organizations pay attention to in the long-term to stay out of the GDPR auditor’s crosshairs?

Make sure you have all your bases covered not just right now, but also going forward. Specifically, you want to be paying attention to the following areas:

**Maintain appropriate documentation**

A very large part of GDPR compliance is to make sure that you have documented which aspects of your organization are impacted. Specifically, this means that you have a document describing who the data controller(s) are, who represents them, and who the responsible Data Privacy Officer is. You will also need to establish the purposes of data processing and a description of the categories of data subjects and of the categories of personal data. If your organization is planning to share this data, especially internationally, you will also have to document the categories of recipients to whom the personal data will be disclosed and what appropriate safeguards have been put in place. Time limits for erasure of different categories of data should also be part of your documentation. In addition, you need to have records of when the data subject gives their consent of the collection and use of their personal data. Lastly, you need to have a general description of the technical and organizational security measures that are implemented.

Here is your GDPR checklist to avoid auditor's crosshairs:

**Maintain an understanding of your processes**

Organizations need to work across departments and functions to gain and maintain an understanding of where personal data is being used in your business processes. Determine the lawful basis for processing each of them and figure out for which processes a data protection impact assessment (DPIA) is mandatory. Make sure that this understanding is maintained going forward as your business processes change or as new processes get created.

**Keep your roles & responsibilities clearly defined**

You have probably defined roles and responsibilities in your organization in preparation for GDPR. You also made sure that necessary trainings took place and you ensured the right level of awareness in your organization. Again, don’t regard this is a one-off activity. As your organizations changes, you need to ensure that everything stays clearly defined and that key stakeholders are trained. Also, expect GDPR to change in the coming years, so make sure that you organization stays up to date.

**Treat privacy risk just like any other risk factor that you are permanently monitoring**

If privacy risk is not part of your standard risk register, add it there. Now apply the same risk management fundamentals to it as you would with any other item in your risk register.

**Ongoing internal funding**

Make sure that senior management understands that maintaining GDPR compliance requires ongoing funding and sponsorship. Your annual planning needs to include a budget for GDPR compliance related investments and someone from the board should be appointed as a long-term sponsor.

**Don’t let your guard down on data governance & keep your data security strategy aligned**

Data management in the context of GDPR means data accountability, responsibility as well as policies & procedures. It also means that you have reporting in place to monitor compliance. Your data landscape will change over time. Make sure that your data management & governance captures these changes and aligns them with GDPR requirements.

You will also have to ensure that appropriate technical and organizational measures are (and remain!) in place to ensure that there is adequate security of personal data stored in or processed by your organization’s systems. This actually means that you should have a data-centric security strategy in place by now. Pseudonymization is the magic term here. GDPR describes in a few of its articles that data needs to be protected by such means.

Make no mistake, all the guiding principles above mean a lot of work for your company on an ongoing basis. However, there is little choice in this matter as privacy has never been more important than today and it looks like the sensibility around privacy is actually going to increase going forward. More and more GDPR-like laws and regulations are coming into play, so ignoring the topic is not an option. Get it tackled now. Going forward, treat it as a core requirement in everything your organization does. Otherwise, you will eventually be in the crosshairs of a GDPR auditor.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/how-to-avoid-the-gdpr-auditors-crosshairs&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/how-to-avoid-the-gdpr-auditors-crosshairs&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/how-to-avoid-the-gdpr-auditors-crosshairs&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/how-to-avoid-the-gdpr-auditors-crosshairs&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/how-to-avoid-the-gdpr-auditors-crosshairs&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Want to learn more?

Click the button below to learn about three key GDPR risks and opportunities every organization should consider when creating an overall GDPR strategy.

[![Download White Paper](https://no-cache.hubspot.com/cta/default/4026697/30d9ae61-6d42-4ea0-a520-356a004873c8.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/30d9ae61-6d42-4ea0-a520-356a004873c8)

### Related posts

![OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/hubfs/comforte%20AG_blog%20post_AI.png)

 Apr 6, 2023 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [AI](https://insights.comforte.com/tag/ai)

### [OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

After several weeks of incredible growth, OpenAI has come in for a bumpy ride of late. First it revealed details of a data breach exposing a significant number of ChatGPT subscribers. Then the Italian data protection regulator (GPDP) became the...

[Read more](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

![How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/hubfs/Analytics%20on%20Red%20Button%20Enter%20on%20Black%20Computer%20Keyboard..jpeg)

 Aug 4, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

Cloud-based analytics offer a truly transformative opportunity for global organizations. By extracting insights from data, they are already helping companies better serve their customers, improve operational efficiencies and make better business...

[Read more](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

![17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/hubfs/Int_Datenschutz_Strategie_1.png)

 Jan 13, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

GDPR wasn't the beginning and it certainly won't be the end. Strict data privacy legislation with extraterritorial applicability is appearing in more and more economies across the globe, meaning the list of “GDPR-free” havens is growing shorter by...

[Read more](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>