A general starting point for organisations that handle the personal data of individuals in the European Union. This is not legal advice, and it is not a complete list of obligations; what applies depends on your organisation and its processing.
Map your data — keep records of your processing activities: what personal data you hold, the purposes, who it is shared with, retention periods, and any transfers.
Identify a lawful basis for each processing activity (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
Provide clear privacy notices telling individuals how their personal data is used.
Enable data subject rights — access, rectification, erasure, restriction, portability, and objection — with a process to respond within the required time.
Put written contracts in place with processors handling personal data on your behalf.
Implement appropriate security measures (technical and organisational).
Appoint a Data Protection Officer if required — for example, public authorities, large-scale systematic monitoring, or large-scale processing of special-category data.
Carry out a Data Protection Impact Assessment before processing that is likely to result in a high risk to individuals.
Prepare a breach-response process — notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware; notify affected individuals where required; and keep a breach record.
Use a valid transfer safeguard for personal data sent outside the European Economic Area (such as an adequacy decision, standard contractual clauses, or binding corporate rules).
General information only; the GDPR’s requirements are detailed and fact-specific.