Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

GDPR Implementation — guide from Governance Docs

How to Implement GDPR: A Ten-Step Plan

GDPR implementation differs from an ISO project in one fundamental respect:
there is no certificate at the end. Nobody audits you until something goes wrong, which is precisely
why the work gets deferred. This is a ten-step plan that produces the evidence a regulator would
actually ask for.

Before step one of GDPR implementation: decide controller or processor

Almost every GDPR implementation obligation flows from this. A controller determines the purposes and means of
processing; a processor acts on instructions. Most organisations are both, for different activities,
and the contracts, the records and the liability differ. Get this wrong at the start and the entire
documentation set is addressed to the wrong obligations.

The ten steps of GDPR implementation

  1. Data mapping and the record of processing (4–8 weeks). The first move in any GDPR implementation. Article 30. This
    is the foundation, it is mandatory for most organisations, and it is the first thing a regulator
    asks for.
  2. Lawful basis for each processing activity (2–3 weeks). Chosen per
    activity and documented, not chosen once for the organisation. Where you rely on legitimate
    interests, record the balancing test.
  3. Privacy notices (2–3 weeks). Articles 13 and 14, written for the people
    reading them rather than for lawyers.
  4. Data subject rights procedure (2–4 weeks). Access, rectification,
    erasure, restriction, portability and objection, with a workflow that meets the one-month deadline.
    See GDPR data subject rights.
  5. Security measures (4–10 weeks). Article 32, appropriate to the risk. If
    you also run ISO 27001, this is largely done.
  6. Processor contracts (3–6 weeks). Article 28 terms with every processor,
    and due diligence on them. See our guide to the data processing
    agreement
    .
  7. International transfers (2–4 weeks). Transfer mechanism plus a transfer
    impact assessment where required.
  8. DPIAs and the DPO decision (2–4 weeks). Article 35 assessments for
    high-risk processing; Article 37 to determine whether a Data Protection Officer is mandatory.
  9. Breach response (2–3 weeks, then exercised). The 72-hour
    notification deadline
    is the tightest clock in the regulation and it starts when you become
    aware, not when you finish investigating. Rehearse it.
  10. Retention, training and review (ongoing). A retention schedule that is actually
    applied, role-appropriate training, and a review cycle. See
    GDPR documentation requirements.

The full GDPR document set, ready to edit.

The GDPR Toolkit provides the record of processing, lawful basis assessments, privacy notices, data subject rights procedures, DPIA templates, Article 28 contract terms and the breach response pack — editable and mapped to the article each satisfies.

Explore the GDPR Toolkit →

The three steps GDPR implementation always underestimate

Step 1, data mapping. Budgeted as a workshop, takes weeks, and everything else
depends on it. You cannot state a lawful basis, set retention or answer an access request for
processing you have not documented. Do it by interviewing the people who handle the data rather than
by circulating a spreadsheet.

Step 9, breach response. Written and filed, never exercised. The 72 hours are
consumed by deciding whether it is notifiable, not by drafting the notification. Run a tabletop.

Step 10, retention. The schedule that everyone writes and nobody applies.
Keeping data indefinitely breaches the storage limitation principle and enlarges every breach you
subsequently have.

GDPR implementation alongside ISO 27001

They overlap usefully but are not substitutes. ISO 27001 gives you the security measures Article
32 requires, plus the risk, supplier, incident and audit machinery. It does not give you lawful
basis, transparency, data subject rights or retention — those are GDPR-specific and no amount
of security controls will cover them. Where organisations get into trouble is assuming a certificate
proves compliance with a regulation it was never designed to address.

A realistic total for GDPR implementation

Four to nine months to a defensible position for a mid-sized organisation, and
longer where processing is complex, international or involves special category data. But GDPR
implementation does not finish. The record of processing has to track the business, and an
untouched one is itself evidence of failure. Start with our
GDPR gap analysis and the
GDPR principles.

References

Implementation guides for the other standards

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.