Days 1–30: establish control
- Name executive, privacy, security, legal and business responsibilities.
- Identify priority products, workforce processes, websites and vendors handling personal data.
- Map categories, purposes, systems, recipients, processors and retention.
- Review current notices, consent interfaces and request channels against actual processing.
- Create a risk-ranked remediation register with owners and dates.
Days 31–60: build the operating processes
- Correct inaccurate notices and choice mechanisms.
- Design authenticated intake and response for access, correction, erasure, grievance and withdrawal requests as applicable.
- Review processor contracts, sub-processors, security assistance and deletion or return commitments.
- Connect retention decisions to system and records-management routines.
- Integrate privacy events with the incident-response process and breach register.
Days 61–90: test and evidence
- Walk through a sample individual request from intake to closure.
- Exercise a personal-data incident and escalation decision.
- Test whether consent withdrawal and preference changes work as described.
- Verify selected retention and deletion controls.
- Train process owners and present residual risks and decisions to leadership.
Evidence to retain
Useful evidence can include approved ownership, data inventories, records of notice review, consent configuration, request logs, processor assessments, retention decisions, risk treatment, training records, incident exercises and management actions. Retain only what is necessary, protect it appropriately and avoid creating new privacy risk through excessive evidence collection.
Important boundary
This checklist is operational guidance, not legal advice. Organisations should confirm the current law, rules, notifications and sector-specific obligations with qualified counsel. The implementation plan should change when authoritative requirements or the organisation's processing changes.