What's included
The records of processing bar gates almost everything after it, and the two rehearsal rows exist because a process nobody has run is not a process:
- Programme setup & scoping — Accountable ownership, whether you are acting as controller or processor for each activity, which entities and jurisdictions are in scope, a gap assessment and the governance forum. Milestone: programme scope and roles agreed.
- Records of processing — the foundation — Discovery workshops with each function, a system inventory, mapping processing activities and data flows, flagging special category data, and signing the records off with the people who own the processing. Milestone: records of processing baselined.
- Lawful basis, retention & transfers — Everything derived from the records: a lawful basis per activity, assessments where legitimate interests are relied on, consent capture and withdrawal, retention and deletion rules, transfer mapping, and privacy notices rewritten from what you actually do. Milestone: lawful basis and retention approved.
- Rights & DSAR response capability — A request procedure, identity verification, an intake channel, search and extraction across systems, trained handlers, and a timed dry run of a full request end to end. Milestone: DSAR process tested end to end.
- Security & breach notification readiness — Technical and organisational measures review, breach detection and escalation, the assessment and notification decision procedure, the breach register, and a tabletop exercise run against the clock. Milestone: breach response rehearsed.
- DPIAs, vendors & continuous operation — Screening criteria and impact assessments on high-risk processing, processor contract remediation, training, and the change process that keeps the records current after the programme stops being a programme. Milestone: defensible position reached.
How to customize it
- Split the discovery and records rows to one line per function or business unit; a single row hides the largest piece of work in the plan.
- If you are a processor rather than a controller, rebuild the rights and breach phases around your obligation to assist and notify your controllers.
- Add a row per transfer route if you move data across borders — the mechanism and the assessment differ by route and destination.
- Lengthen the DSAR phase if your data lives in many systems; extraction tooling is almost always the long pole, not the legal analysis.
- Add rows for any regulator engagement, prior consultation or existing complaint that is already live, since they will preempt the plan.
- Keep the final phase running after the milestone — the records of processing decay the moment a new system or vendor arrives.
Scheduling tips
- Build the records before the policies. Policies written before you know what processing exists describe an organisation you do not have, and the first request will show it.
- Time the dry run. The useful output of a practice request is how many days it took and where it stalled, not whether you eventually produced the file.
- Rehearse the breach decision, not just the technical response. The hard part is assessing risk and deciding whether notification is required, and that decision has to be made by people who have made it before.
- Write down why you did not notify. If you assess a breach as not notifiable, the reasoning and the record are what defends the decision later.
- Put the records into the change process. A new vendor, a new system or a new feature should update the records as a matter of routine, or you will rebuild them in two years.
Related templates
- ISO 27001 Certification Plan Template
- SOC 2 Compliance Timeline Template
- Internal Audit Plan Template
- Data Migration Project Plan Template
- Change Management Plan Template
- Browse all Gantt chart templates
Frequently asked questions
How long does a GDPR compliance programme take?
The template runs about fifteen months to a defensible position. Most of that is the records of processing work and the tooling behind data subject requests, not legal drafting. It is worth saying plainly that the programme does not end there: the records need maintaining, impact assessments recur, and vendors and systems keep changing.
What is the deadline for responding to a data subject access request?
Article 12 of the Regulation sets the period at one month from receipt of the request. It can be extended by two further months where necessary, taking account of the complexity and number of requests, and the controller must inform the data subject of the extension and the reasons for it within one month of receiving the request. The detail around when the period starts, identity verification and manifestly unfounded or excessive requests is where the practical difficulty sits, so confirm the position for your situation with counsel.
What is the 72-hour breach notification rule?
Article 33 requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it — unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification is later than 72 hours it must be accompanied by reasons for the delay. Separately, Article 34 requires communication to affected individuals where the breach is likely to result in a high risk to them. When you are treated as having become aware is a judgement call, which is why the template rehearses the assessment rather than only the technical containment.
Why does the records of processing come before everything else?
Because lawful basis, retention periods, transfer mechanisms, privacy notices and impact assessments are all statements about specific processing activities. Without a record of what those activities are, each of them is written against an assumption. Programmes that start with a policy library and work backwards usually rebuild it once discovery is done.
How is this different from ISO 27001 or SOC 2?
GDPR is law and applies to you whether or not anyone certifies you. ISO 27001 is an accredited certification against an information security management standard, and SOC 2 is an AICPA attestation report produced by an auditor — neither is a legal compliance finding. They overlap heavily on security controls, so the evidence is reusable, but a certificate is not a defence. See the ISO 27001 certification plan and the SOC 2 compliance timeline if you are running those alongside.
Is the GDPR timeline template free?
Yes. Free Excel, PowerPoint and CSV downloads, and free online editing with no account and no watermark. This template is a planning aid, not legal advice.