The gdpr compliance checklist.

A step-by-step GDPR compliance checklist

Written by
No items found.
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

In today’s data-driven economy, companies across industries are collecting data from users who visit their sites and interact with their brands. However, this could be costly if your business is not collecting this data in a GDPR-compliant way.

Enacted in May 2018, the General Data Protection Regulation (GDPR) is the European Union’s data privacy and security law. GDPR establishes data protection as a fundamental right to EU-based users and includes numerous protections covering the use, storage, confidentiality, and transfer of personal data. The fines for violating GDPR are severe, maxing out at €20 million or 4% of your global revenue (whichever is higher).

To protect your organization from these costly penalties, you’ll need to ensure your data collection practices comply with this law. We've created this checklist to make it easy for you to get GDPR compliant.

What are the benefits of GDPR compliance?

GDPR compliance is critical for businesses globally that collect data from EU residents. It’s legally required for these businesses and offers benefits, such as:

  • Protecting your organization from severe fines.
  • Maintaining the trust of consumers and clients.
  • Removing barriers that prevent your business from expanding into the EU.
  • Strengthening your data security.

Six benefits of GDPR compliance.
Benefits of GDPR compliance.

GDPR compliance requirements

The GDPR legislation includes various requirements your organization must follow. We’ve included the steps you’ll need to take to be GDPR compliant in this checklist:

{{gdpr="/checklists"}}

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.