GDPR Compliance Checklist for Product Teams
GDPR compliance is ongoing for every product processing EU resident data. Product teams must build privacy-by-design into every feature.
This checklist covers product-level GDPR requirements for features that collect, process, or store personal data.
Template sections
4 sections covering the complete compliance workflow.
Data Mapping
Document what personal data is collected, why (lawful basis), where stored, who has access, retention period, and third-party sharing.
Consent Management
Ensure consent is freely given, specific, informed, and unambiguous. No pre-checked boxes. Withdrawal must be as easy as giving consent.
Data Subject Rights
Implement right to access, rectification, erasure, data portability, and right to object. Each must be exercisable within 30 days.
Data Processing Impact Assessment
Conduct DPIA for features processing data at scale, using automated decision-making, or processing sensitive categories.
Copy-paste template
# GDPR Checklist — [Feature] ## Data Mapping - [ ] Personal data identified - [ ] Lawful basis documented - [ ] Retention period defined ## Consent - [ ] No pre-checked boxes - [ ] Withdrawal as easy as giving consent ## Rights - [ ] Access/export implemented - [ ] Erasure/deletion implemented - [ ] All exercisable within 30 days ## DPIA: [Required / Not required]
Frequently asked questions
Generate instead of filling in templates
Connect your tools, and Vantage generates the content using real product data. Free to start.
Free to start. No credit card required.