GDPR Compliance Review Checklist
Data Mapping and DPIA
Walk each service line — tax prep, bookkeeping, payroll, audit — and document what personal data is collected, where it is stored (TaxDome, SmartVault, QBO, Gusto, local files), and which staff have access. Attach the updated flow map; this is the input to the Article 30 record and the DPIA scoping.
The ROPA must list each processing activity, purpose, lawful basis, data categories, recipients, retention period, and transfer safeguards. Pull last year's ROPA and reconcile against the new data flow map — new clients in EU jurisdictions and new sub-processors are the usual additions.
High-risk triggers under Article 35: large-scale processing of special-category data (health, biometric), systematic monitoring, automated decisioning, or new cross-border transfers without an adequacy decision. Forensic-accounting and litigation-support engagements often trip the threshold.
Document the necessity and proportionality assessment, the risks to data subjects, and the mitigations applied. Where residual risk remains high after mitigation, Article 36 prior consultation with the supervisory authority is required before processing begins.
New software (e.g., switching from Lacerte to UltraTax), a new sub-processor, or a change in retention period each warrant re-running the affected DPIA. Note the trigger and the conclusion in the DPIA register.
Policies and Documentation
The policy should cross-reference the WISP required by IRS Pub 4557 — many firms keep one document covering both. Confirm the controller/processor designation, named DPO or privacy lead, and the breach-notification escalation chain.
Most engagement work runs on contract (Article 6(1)(b)) or legal obligation (6(1)(c)) for tax filings. Marketing lists run on legitimate interests or consent — get this distinction right before sending the next newsletter.
Reconcile GDPR storage-limitation against IRS / state record-retention rules. Tax workpapers commonly held 7 years; audit workpapers 7 years under SSARS / SAS 103; payroll 4 years under FLSA. Align deletion runs in TaxDome / SmartVault to the schedule.
Privacy notice must list controller identity, processing purposes and lawful bases, recipients (including sub-processors), retention periods, data subject rights, and the right to lodge a complaint with the supervisory authority. Date-stamp the version.
Data Subject Rights
Submit a dummy access request through the public channel (web form, privacy@ inbox) and confirm it lands with the privacy lead, not a generic admin queue. The 30-day clock starts on receipt — silent inbox routing is the most common SLA breach.
Article 12(6) allows the controller to request additional information to confirm identity. For client-record requests, confirm engagement-letter signatory match; for employee requests, confirm against HRIS. Don't accept a bare email claim.
Erasure has carve-outs — Article 17(3)(b) preserves data needed for legal obligations such as tax record retention. Document the carve-out reasoning so a refusal can be defended. Portability applies only to data the subject provided, in a machine-readable format.
Pull the prior-year DSAR log and confirm every request closed within one month, or that an Article 12(3) extension was issued in writing within the first month with reasons. Late responses without an extension are a reportable failure.
Technical and Organizational Security
Confirm TLS in transit and AES-256 at rest from the vendor's SOC 2 report (TaxDome, SmartVault, ShareFile, Liscio all publish these). Pull the most recent report into the workpaper rather than relying on the marketing page.
Pull the user list from UltraTax / Lacerte / QBO Accountant and confirm every active user is still employed and assigned to engagements that need access. Departed-staff accounts and shared logins are the recurring findings.
Walk through a stolen-laptop scenario and a phishing-compromise scenario. Test the 72-hour Article 33 notification timeline to the supervisory authority and the Article 34 notification to data subjects when the breach is high-risk.
Pull the MDM report (Jamf, Intune) and confirm BitLocker / FileVault enabled on every endpoint with client data. MFA must be enforced on email, the client portal, and the GL — not just opt-in.
Staff Training and Awareness
Cover the named cases from the past year — phishing attempts, mis-sent tax returns, unauthorized portal access. Concrete incidents land better than abstract principles. New hires get this within their first week, not at the annual cycle.
Reconcile the LMS roster against the active-employee list from HR. Contractors and seasonal tax-season hires are the usual gap — their access to client data is the same, the training requirement is the same.
Suspend portal and tax-software access until training is complete. The HR escalation path applies if a staff member misses the second deadline. Document the suspension and reinstatement so the audit trail is intact.
Sub-Processors and Transfers
Includes the obvious (TaxDome, QBO, Gusto, Bill.com, Avalara) and the easy-to-miss (Hubdoc, DocuSign, the email-marketing platform, the shred-bin vendor). Each entry needs purpose, data categories, and processing location.
The DPA must include the Article 28(3) clauses — purpose, duration, sub-processor authorization, confidentiality, security, audit rights. Most major vendors publish a standard DPA; small specialty vendors are where signed copies go missing.
Request the standard DPA from each gap vendor; if they will not sign, escalate to the partner for a replace-or-accept-the-risk decision. Suspend new data sharing with the vendor until the DPA is countersigned.
US sub-processors require the 2021 EU Standard Contractual Clauses (Module 2 controller-to-processor) plus a transfer impact assessment per Schrems II. Confirm the vendor is on the latest SCC version, not the pre-2021 form.
Use this template in Manifestly
- Annual Attorney Professional Conduct Review
- Restaurant New Hire Checklist
- Restaurant Policy Update Checklist
- Retail Policy Update and Compliance Checklist
- New Hire Paperwork Checklist
- Department of Transportation (DOT) Audit Checklist
- Restaurant Permit and Licensing Renewal Checklist
- Marketing Strategy Checklist
- E-commerce Risk Management Checklist
- E-commerce Legal Compliance Checklist
- CRM Data Entry Checklist
- Cybersecurity Incident Response Checklist
- Agency Compliance and Risk Management Checklist
- Advisor and Staff Onboarding Checklist
- New Hire Onboarding Checklist
- Financial Services IT Security Audit Checklist
- Litigation Preparation Checklist
- Internal Audit Checklist
- PCI DSS Compliance Checklist
- Contract Review Checklist
- Annual Financial Reporting Checklist
- Intellectual Property Management Checklist
- Annual Compliance Program Review
- Project Monitoring Checklist
- Operational Risk Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Regulatory Reporting Checklist
- Advisor and Employee Onboarding Checklist
- Quarterly Performance Measurement Checklist
- IT Policy Review Checklist
- Project Closure Checklist
- Monthly Financial Reporting Checklist
- Quarterly Operations and Compliance QA Review
- Cybersecurity Risk Assessment Checklist
- Know Your Customer (KYC) Checklist
- User Access Review Checklist
- Data Protection Checklist
- Employee File Audit Checklist
- Email Deliverability Checklist
- HR Compliance Checklist
- Law Firm Ethics Compliance Review
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Licensing Renewal Checklist
- Motor Carrier TSA Security Compliance Checklist
- Risk Assessment Checklist
- School First Aid and Emergency Medication Audit
- Annual School Compliance Audit
- Annual Risk Management Review Checklist
- Vendor Contract Review Checklist
- Business Continuity Plan Checklist
- HR Audit Checklist
- Insurance Marketing Campaign Checklist
- Cloud Security Checklist
- Insurance Program Launch Project Monitoring Checklist
- Anti-Money Laundering Compliance Checklist
- System Backup Checklist
- Data Privacy Compliance Checklist
- Quarterly Risk Monitoring Checklist
- Insurance Program Initiation Checklist
- Law Firm Compliance Checklist
- Training Materials Checklist
- Professional Responsibility Compliance Review
- Employee Offboarding Checklist
- Network Security Checklist
- Regulatory Reporting Checklist
- IT Asset Inventory Management Checklist
- Manufacturing Regulatory Compliance Checklist
- Compliance Audit Checklist
- Training Needs Assessment Checklist
- Email Compliance Checklist
- Audit Preparation Checklist
- Skills Development Checklist
- Law Firm Compliance Checklist
- Financial Statement Review Checklist
- Employee Termination Checklist
- Project Planning Checklist
- Project Execution Checklist
- Security Audit Checklist
- Quarterly Compliance Monitoring Checklist
- Regulatory Compliance Checklist
- E-commerce Sales Tax Reporting Checklist
- Annual Risk Assessment Checklist
- Compliance Audit Checklist
- Client Satisfaction Survey Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Financial Services Project Initiation Checklist
- Brokerage HR Policy Compliance Checklist
- Data Privacy Compliance Checklist
- Employee Handbook Annual Review
- Expense Management Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Regulatory Compliance Checklist
- Listing Agreement Intake Checklist
- Employee Records File Audit
- Employee Termination Checklist
- Law Firm Risk Management Checklist
- ISO/IEC 27001 Compliance Checklist
- Complaint Resolution Checklist
- IT Regulatory Compliance Review
- HR Compliance Checklist
- Business Continuity Checklist
- Lead Generation Checklist
- Insurance Program Launch Execution Checklist
- Employee Benefits Checklist
- Law Firm Risk Management Checklist
- Fair Housing Compliance Audit
- Real Estate Website Audit Checklist
- Real Estate Ethics & Compliance Review
- Software Licensing Compliance Checklist
- Property Risk Assessment Checklist
- Lease Agreement Checklist
- Security Audit Checklist
- Legal Compliance Checklist for New Properties
- Fair Housing Compliance Checklist
- IT Security Audit Checklist
- Claims Auditing Checklist
- Document Retention Policy Checklist
- Insurance Training and Development Checklist
- Quarterly Industry Standards Compliance Review
- Risk Management Checklist
- Employee Records Management Checklist
- Building Code Compliance Checklist
- Legal Entity Management Checklist
- SOX Compliance Checklist
- Quarterly Internal Control Review Checklist
- Legal Document Storage Checklist
- Anti-Money Laundering Compliance Checklist
- Regulatory Compliance Checklist
- Insurance Compliance Checklist
- Real Estate Contract Review Checklist
- Employee Termination Checklist
- GDPR Compliance Checklist
- Continuing Education Checklist
- Real Estate License Renewal Checklist
- MLS Listing Review Checklist
- HIPAA Compliance Checklist
- Real Estate Legal Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Professional Development Checklist
- Brokerage Trust Account Management Checklist
- Cybersecurity Protocol Checklist
- HR Compliance Checklist
- Data Security Review Checklist
- Risk Management Checklist
- Sales Tax Reporting Checklist
- Property Safety Inspection Checklist
- Employee File Audit Checklist
- Brokerage Technology Inventory Audit
- Payroll Processing Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
