Skip to content
Legiscope
Menu
Data Privacy

GDPR Compliance Framework: the 11 Deliverables, in Order

GDPR compliance framework: the 11 deliverables in build order — ROPA, lawful basis register, DPIA triggers, DPAs, transfer map, breach playbook, audit cycle.

In one sentence. A 2026 GDPR compliance programme is built on 11 concrete deliverables: a Record of Processing Activities (Article 30), a lawful basis register (Article 6), DPIAs for high-risk processing (Article 35), an Article 28 processor register with signed DPAs, a Schrems II transfer map, breach response within 72 hours (Article 33), a data subject rights workflow (Articles 15-22), a retention schedule, security measures (Article 32), staff training, and an annual audit cycle. Recent enforcement (Meta €1.2B in 2023, TikTok €530M in 2025) makes the cost of skipping any of these higher than ever.

This guide consolidates the 2025-2026 enforcement reality — EDPB guidelines, CJEU rulings, and 5 billion+ in cumulative GDPR fines — into a deliverables-based roadmap. It mirrors the structure of the official EDPB accountability framework and the European Commission’s GDPR guidance.

Key takeaways

  • 11 mandatory deliverables — no “GDPR-lite” exists.
  • ROPA (Article 30) is the foundation — every other deliverable depends on it.
  • DPIA is required for processing listed in EDPB Guidelines WP248rev.01.
  • Breach notification deadline is 72 hours to the supervisory authority.
  • Top-tier fines reach €20M or 4% of global turnover (Article 83(5)).
  • 2025 fine total exceeded €2.1 billion across the EEA.

1. Map your data: Record of Processing Activities

2. Assign a lawful basis to each activity

3. Run DPIAs for high-risk processing

4. Govern your processors (Article 28)

5. Map and lawfully justify international transfers

6. Build a 72-hour breach response capability

7. Operationalise data subject rights

8. Define retention and storage limits

Article 5(1)(e) — storage limitation — requires deletion or anonymisation when the purpose is fulfilled. Document retention rules per data category in a written schedule; automate purges. For encryption standards, retention periods by data type and secure-deletion workflows, see our detailed GDPR data storage and retention guide.

9. Implement Article 32 security measures

State-of-the-art technical and organisational measures: encryption at rest and in transit, pseudonymisation, access controls, MFA, backups with integrity tests, vulnerability management, incident response procedures. EDPB Guidelines 9/2022 detail breach notification thresholds.

10. Train staff and assign a DPO if required

11. Audit and update annually

12. What DPAs are actually enforcing in 2025-2026

Reading the docket, not the statute, tells you where the risk concentrates. Four themes dominate recent EDPB and national-DPA decisions. International transfers remain the single largest exposure — the €1.2B Meta fine (Irish DPC, May 2023) for EU-US Facebook transfers set the ceiling, and TikTok’s €530M decision (Irish DPC, May 2025) confirmed transfers to China as a live enforcement front. Consent and dark patterns in cookie banners and ad-tech continue to draw fines from the CNIL and the Garante. Legal basis for behavioural advertising — the Meta €390M decision (Irish DPC, January 2023) rejected “contract” as a basis for ads — has reshaped how platforms justify tracking. And children’s data, where TikTok (€345M, Irish DPC, September 2023) established that default-public teen accounts breach the Regulation. If your programme covers these four areas properly, you are aligned with where enforcement energy is going.

13. Sequencing the 11 deliverables

Do not attempt all eleven at once. The dependency order matters: the ROPA comes first because every other deliverable reads from it. With the processing inventory in place, assign lawful bases (Article 6), then layer retention rules and the data controller versus processor mapping on top of the same records. DPIAs and Article 28 processor governance follow, because you cannot assess risk or vendor exposure for activities you have not yet catalogued. Transfers, breach response, and data-subject-rights workflows are the operational layer built last, on a stable inventory. Security measures (Article 32) and staff training run in parallel throughout. A realistic sequence for a mid-market team is: ROPA and lawful bases in month one, processor and transfer mapping in month two, DPIA and rights workflows in month three, then a first internal GDPR audit to close gaps. Trying to boil the ocean produces eleven half-finished artefacts and no defensible accountability record under Article 5(2).

14. Tooling

FAQ

What is the GDPR compliance guide for 2026?

A documented programme covering Article 30 ROPA, Article 6 lawful bases, Article 35 DPIAs, Article 28 processor governance, Schrems II transfers, Article 33 breach response within 72 hours, data subject rights workflow, retention schedule, Article 32 security, training, and annual audit.

How long does GDPR compliance take?

For a mid-size SaaS: 6-12 months with internal effort, 60-90 days with tooling. Programme maintenance is continuous.

What are the biggest GDPR fines in 2025?

TikTok €530M (Irish DPC, May 2025) for Chinese transfers, Uber €290M (Dutch DPA), and multiple Meta and Amazon decisions. Cumulative EEA fines exceeded €2.1B in 2025.

Is GDPR compliance mandatory for non-EU companies?

Yes if they offer goods/services to EU residents or monitor their behaviour (Article 3 territorial scope).

What’s the minimum GDPR compliance deliverable list?

ROPA, lawful basis register, signed DPAs with processors, privacy notice, DSAR procedure, breach response procedure, security measures. Anything less invites Article 83 sanctions.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Data Privacy Compliance: Complete Guide for 2026

Data privacy compliance in 2026 is a multi-jurisdiction challenge. The EU's GDPR is the global benchmark, but ten major frameworks now compete for compliance attention: CCPA/CPRA (California), VCDPA…

April 30, 2026
02Data Privacy

GDPR Right to Data Portability (Art. 20): When + Format

Definition. The right to data portability (GDPR Article 20) allows individuals to receive their personal data in a structured, commonly used, and machine-readable format (e.g., JSON, CSV, XML) and to…

October 8, 2024
03GDPR Compliance

GDPR Compliance Software Buyer's Guide 2026: 5 Core Features + Pricing

GDPR compliance software automates five core obligations: records of processing activities (Art. 30), data protection impact assessments (Art. 35), breach notification (Art. 33), data subject request…

April 12, 2026
04Personal Data

Privacy by Design (Art. 25 GDPR): 7 Principles + Implementation

Art. 25 GDPR makes privacy by design a legal obligation, not a best practice. Controllers must implement appropriate technical and organisational measures — both at the time of determining the means…

05Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
06Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
07Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
08Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026