HomeTemplates › GDPR Compliance Timeline Template

GDPR Compliance Timeline Template

A free GDPR compliance timeline template built for a programme that reaches a defensible state and then keeps running, rather than one that finishes. The organising idea is that the records of processing come first: lawful basis, retention rules, transfer mechanisms and data protection impact assessments are all derived from knowing what you actually do with personal data. The two externally-driven clocks — the response period for data subject requests and the breach notification deadline — are put on the chart as processes that get tested before anyone needs them.

Preview of the gdpr compliance timeline template showing phases across a timeline

What's included

The records of processing bar gates almost everything after it, and the two rehearsal rows exist because a process nobody has run is not a process:

Two figures come from the Regulation itself and are worth stating precisely. Article 12 sets the period for responding to a data subject request at one month from receipt, extendable by two further months where requests are complex or numerous, provided the data subject is told of the extension and the reasons within the first month. Article 33 requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a later notification must be accompanied by reasons for the delay. Both figures have conditions attached — when the clock starts, when it can be extended, when notification is not required — and supervisory authorities across member states publish their own guidance on how they read them. Do not flatten either into a slogan on a poster, and check the position that applies to you with counsel rather than relying on a summary.

How to customize it

  1. Split the discovery and records rows to one line per function or business unit; a single row hides the largest piece of work in the plan.
  2. If you are a processor rather than a controller, rebuild the rights and breach phases around your obligation to assist and notify your controllers.
  3. Add a row per transfer route if you move data across borders — the mechanism and the assessment differ by route and destination.
  4. Lengthen the DSAR phase if your data lives in many systems; extraction tooling is almost always the long pole, not the legal analysis.
  5. Add rows for any regulator engagement, prior consultation or existing complaint that is already live, since they will preempt the plan.
  6. Keep the final phase running after the milestone — the records of processing decay the moment a new system or vendor arrives.

Scheduling tips

Frequently asked questions

How long does a GDPR compliance programme take?

The template runs about fifteen months to a defensible position. Most of that is the records of processing work and the tooling behind data subject requests, not legal drafting. It is worth saying plainly that the programme does not end there: the records need maintaining, impact assessments recur, and vendors and systems keep changing.

What is the deadline for responding to a data subject access request?

Article 12 of the Regulation sets the period at one month from receipt of the request. It can be extended by two further months where necessary, taking account of the complexity and number of requests, and the controller must inform the data subject of the extension and the reasons for it within one month of receiving the request. The detail around when the period starts, identity verification and manifestly unfounded or excessive requests is where the practical difficulty sits, so confirm the position for your situation with counsel.

What is the 72-hour breach notification rule?

Article 33 requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it — unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification is later than 72 hours it must be accompanied by reasons for the delay. Separately, Article 34 requires communication to affected individuals where the breach is likely to result in a high risk to them. When you are treated as having become aware is a judgement call, which is why the template rehearses the assessment rather than only the technical containment.

Why does the records of processing come before everything else?

Because lawful basis, retention periods, transfer mechanisms, privacy notices and impact assessments are all statements about specific processing activities. Without a record of what those activities are, each of them is written against an assumption. Programmes that start with a policy library and work backwards usually rebuild it once discovery is done.

How is this different from ISO 27001 or SOC 2?

GDPR is law and applies to you whether or not anyone certifies you. ISO 27001 is an accredited certification against an information security management standard, and SOC 2 is an AICPA attestation report produced by an auditor — neither is a legal compliance finding. They overlap heavily on security controls, so the evidence is reusable, but a certificate is not a defence. See the ISO 27001 certification plan and the SOC 2 compliance timeline if you are running those alongside.

Is the GDPR timeline template free?

Yes. Free Excel, PowerPoint and CSV downloads, and free online editing with no account and no watermark. This template is a planning aid, not legal advice.

Plan it online — free

Open this template in the editor, drag the bars to fit your dates, and export to PDF, Excel or PowerPoint. No account, no watermark.

Open the free editor