GDPR · 12 min read · Updated 2026-07-06

GDPR checklist for maintainable evidence

A GDPR evidence checklist for SaaS teams covering processor records, vendors, DSARs, DPIAs, breach response and security controls.

Direct answer: what a maintainable GDPR checklist includes

A maintainable GDPR checklist covers the operational records that show how personal data is handled: data mapping, RoPA, lawful basis, privacy notices, consent records, processor agreements, subprocessor reviews, data subject requests, DPIAs, breach response, retention, deletion, access reviews and security controls.

For SaaS teams, the checklist works best as a set of owned records rather than a one-off legal document. Each record needs the system or process involved, the personal data affected, the owner who reviewed it, the supporting evidence and the next review date.

General information only; this is not legal advice. Ask qualified privacy counsel or a data protection specialist for legal interpretation.

Controller vs processor evidence

  • Record when you act as a controller, processor or both.
  • Keep customer processing instructions, DPA terms and product data-flow notes.
  • Make customer-facing statements match the role you actually perform.

Data mapping and RoPA

  • List systems that collect, store, process or transfer personal data.
  • Record categories of data subjects and personal data.
  • Map subprocessors, hosting regions and retention periods.
  • Keep the RoPA owner and review date visible.

Lawful basis

  • Record lawful basis by processing activity.
  • Keep legitimate interest assessments where relevant.
  • Separate account administration, marketing, analytics and product processing.
  • Review lawful basis when product features change.

Privacy notices and consent records

  • Keep current privacy notices with publication dates.
  • Record who approved material changes.
  • Store consent configuration and withdrawal workflows where consent is used.
  • Avoid privacy promises that are not supported by operational evidence.

DPA and subprocessor review

  • Keep signed DPAs or accepted terms for processors.
  • Record subprocessor lists, review dates and customer notification workflows.
  • Connect critical subprocessors to vendor risk reviews.

DSAR workflow

  • Document intake, identity verification, search, approval and response steps.
  • Record owner, deadline and evidence of completion.
  • Keep exemptions or refusals reviewed by an appropriate owner.

DPIA workflow

  • Define triggers for high-risk processing.
  • Record risk assessment, mitigations, reviewers and outcome.
  • Review DPIAs when processing purposes, data types or vendors change.

Breach response

  • Keep an incident response process with privacy escalation criteria.
  • Record assessment of personal data impact.
  • Track notification decisions, responsible owners and timestamps.

Retention and deletion

  • Define retention periods by data category or system.
  • Record deletion workflows and exceptions.
  • Keep evidence of deletion jobs, customer offboarding and backup retention assumptions.

Access reviews and security controls

  • Review privileged access to systems containing personal data.
  • Keep MFA, logging, backup and encryption evidence where applicable.
  • Connect access review findings to remediation tasks.

Evidence table

GDPR evidence checklist table
AreaWhat to checkEvidence to keepOwnerReview frequencyStatus
RoPAProcessing activities are currentRoPA export, system mapPrivacy ownerQuarterlyNot started
Lawful basisBasis is recorded per activityLawful basis register, assessment notesPrivacy ownerAnnuallyNot started
NoticesPrivacy notice reflects current processingPublished notice, approval historyLegal/opsAnnuallyNot started
VendorsProcessors and subprocessors are reviewedDPA, subprocessor list, vendor reviewVendor ownerAnnuallyNot started
DSARRequest workflow is testedProcedure, request log, response evidenceSupport leadAnnuallyNot started
DPIAHigh-risk processing is assessedDPIA record, mitigation notesProduct ownerOn changeNot started
BreachPrivacy incident decisions are recordedIncident log, notification assessmentSecurity leadPer incidentNot started
AccessPersonal-data system access is reviewedAccess export, review sign-offIT ownerQuarterlyNot started

Common mistakes

  • Keeping GDPR records only in legal folders.
  • Not connecting subprocessors to vendor security reviews.
  • Letting privacy notices drift away from product reality.
  • Treating DSAR and breach workflows as documents without evidence of operation.

Keeping GDPR evidence current in Trustega

Trustega keeps processor records, vendor reviews, security evidence, access review notes and customer-ready answers together, so privacy and security work can be reviewed without chasing multiple teams.

Common questions

Is this guide legal or certification advice?

No. This guide is for general information and is not legal advice. Use qualified legal, privacy or audit advisers for formal interpretation and assurance decisions.

Can a small SaaS team use this without a GRC team?

Yes. The workflows are designed for lean teams, but each record still needs a named owner, a review date and evidence that matches the actual scope.