FormatForge logoFormatForge

Business & Compliance Tools

Privacy Compliance Checklist

Review practical privacy controls across governance, data mapping, transparency, individual rights, retention, vendors, security and international transfers. Mark each control, record evidence or actions, then export the assessment for follow-up.

Choose a focus to surface the most relevant operational questions. Applicability depends on your organisation, activities, users, location and current law.

Readiness

0%

Completed applicable items

Completed

0/19

Excludes N/A

Open gaps

19

Needs review

High priority

13

Open high-priority items

Governance

Assign privacy ownership

High

Name the person or team responsible for privacy governance, escalation and periodic review.

Maintain documented privacy policies

Medium

Keep internal rules for handling personal information, approvals, retention and incident response current.

Train staff who handle personal data

Medium

Provide role-appropriate privacy and security training and record completion where your organisation requires it.

Data mapping

Inventory personal data and processing activities

High

Document what personal data you collect, where it comes from, why it is used, where it is stored and who receives it.

Identify sensitive or higher-risk data

High

Flag data requiring stronger controls, such as precise identifiers, financial information, health-related data, children’s data or other sensitive categories.

Apply data minimisation

Medium

Collect and retain only the personal data that is reasonably needed for the stated purpose.

Purpose & legal basis

Document purposes for processing

High

Record the business purpose for each material use of personal data and review incompatible secondary uses.

Review consent mechanisms where consent is used

Medium

Make consent specific, informed and genuinely optional where the applicable rule requires consent, and retain evidence when appropriate.

Transparency

Publish an accurate privacy notice

High

Explain who you are, what data is collected, purposes, sharing, retention and user choices in clear language.

Cookies & tracking

Inventory cookies, SDKs and tracking technologies

High

Know which trackers run, their purpose, provider, lifespan and whether optional technologies are controlled by user choice where required.

Individual rights

Create a rights-request workflow

High

Define intake, identity verification, ownership, deadlines, exemptions, fulfilment and recordkeeping for applicable privacy requests.

Retention & deletion

Define retention periods

High

Set retention rules based on purpose, legal obligations and operational need rather than keeping personal data indefinitely.

Operationalise deletion across systems and backups

Medium

Ensure retention/deletion rules are reflected in production systems, archives and vendor workflows where practicable.

Vendors & processors

Maintain a vendor / processor inventory

High

List service providers that receive or access personal data and understand what they do with it.

Use appropriate privacy and security contract terms

High

Review processor/service-provider terms, confidentiality, security, assistance obligations and data return/deletion provisions as applicable.

Security

Apply proportionate technical and organisational safeguards

High

Use access control, least privilege, encryption where appropriate, secure development, patching, logging and tested recovery controls.

Maintain a privacy/security incident response plan

High

Define detection, containment, assessment, evidence preservation, decision ownership and external communication steps.

Product & change management

Build privacy review into new projects

Medium

Review new products, data uses and material changes before launch, including data minimisation and default settings.

Assess high-risk processing before launch

High

Use a documented privacy impact / risk assessment process for processing that may create elevated risk.

Important limitation

This workspace is a general operational self-assessment. It does not determine whether a law applies to you, cover every legal requirement, replace a data protection impact assessment, or certify compliance. Privacy laws and regulator guidance change; verify obligations with current official guidance and qualified counsel where necessary.

How to use this privacy readiness checklist

Start with the general checklist if you want an operational privacy baseline. Use the EU, UK or California focus to surface additional questions commonly associated with those regimes. Mark a control as Done only when you have reasonable evidence that the process exists and is being followed; use N/A only after considering why the item does not apply.

The score is a progress indicator, not a legal compliance score. A single unresolved high-risk issue can matter more than several completed administrative items, so use the high-priority gap count and notes to plan follow-up work.

This tool intentionally avoids making an automatic legal determination. Applicability and required controls depend on facts such as your organisation, location, users, processing purposes, data categories and current law.

Privacy by design

Assessment data stays in the current browser session unless you choose to copy, print or download it. The page does not need an account or backend database for this workflow.

Related: FormatForge Privacy Policy · Quality Standards · Business & Invoice Tools