Checklist: GDPR check of customer data
How to check whether your company's customer data is in order
Use this checklist to get a quick overview of whether the most important GDPR points are in place in your department. It does not replace legal advice, but catches the most common gaps in practice.
§Base and consent
- 01Has a legal basis been noted for each type of data registration (agreement, consent, legitimate interest, legal obligation)?
- 02Have joints, fittings and sealing strips been mounted correctly and do they work as they should?
- 03Can the customer easily withdraw their consent again?
- 04Are pre-checked boxes or silent acceptance avoided completely?
§Storage and deletion
- 01Has a storage period been set for each data type?
- 02Are data deleted or anonymised automatically when the period expires?
- 03Are accounting documents separated from other customer data so they are not deleted too early?
- 04Is there a procedure for when a customer asks to have their data deleted?
§Access and safety
- 01Only employees with a real work need have access to the CRM system?
- 02Is there a data processor agreement with each external IT vendor that stores or processes data?
- 03Are strong passwords used and, where possible, two-factor login for the systems?
- 04Is there a plan for what to do if a data breach occurs?
| Point | Status | Responsible | Deadline |
|---|---|---|---|
| Legal basis documented | |||
| Deletion routine activated | |||
| Data processing agreements in place | |||
| Access control reviewed |