| Awareness | Identify and involve key people | 
| Data Protection Officer (DPO) | Appoint someone to be responsible for compliance Act on their guidance | 
| Lawful Basis for Processing Data | Identify why you hold personal data and how long you will hold it for | 
| Accountability | Put on record how you comply with GDPR principles | 
| Privacy Information | What changes need to be made to your Privacy Policy to comply with the GDPR? How will these changes be publicised? | 
| Information | Describe the data and basis for holding it, eg for: Employees Customers Suppliers Stakeholders Identify data partners: Who do we get data from? Who do we send data to? | 
| Individual Rights | Understand the new rights of individuals Ensure Privacy by Design How do you obtain consent?
 How do you erase records/delete data?
 | 
| Subject Access Requests | Where do you look for data? How quickly can you respond? | 
| Consent | Do you have clear, opted-in permission to hold and use this data? | 
| Children | Do you hold children’s data and, if so, do you understand the new requirements? | 
| Data Breaches | Understand what a breach is Report breaches to the ICO within 72 hours Understand when to report breaches to data subjects | 
| Data Protection by Design | Understand what data your systems store Understand how your systems store data Understand where suppliers’ responsibilities end Understand data partners’ processes & use of data Fix any identified gaps in your protection of data | 
| International | If you operate in more than one EU state, identify your data protection Supervisory Authority. |