The complete GDPR roadmap.

Many GDPR duties are documentation duties — a register tool covers them. Others are organisational, legal or technical: they must be decided, signed or set up in your company. This guide shows both sides, with practical tips and a 90-day plan.

🧭 Practitioner's guide, hands on! 📋 From the processing record outwards 🗺️ 90-day roadmap included

Covered by Floriti vs. still your job

The rule of thumb: a register tool like Floriti answers the auditor's question "show me that …". The remaining duties answer "do you actually do it?" — and almost every one of them produces evidence that belongs back in a register. That closes the loop.

ArticlesTopicStatus
Art. 5 (2), 30Accountability, record of processing activities✔ covered by Floriti
Art. 6, 15–22, 28*, 32*, 33/34*, 35, 37–39*Legal-basis documentation, data subject requests, processor directory, TOM documentation, breach process, DPIA, DPO involvement✔ process & evidence in Floriti
Art. 1–4Subject matter, scope & definitions — explanatory groundwork; no direct obligations follow from these articles (Art. 3 merely determines whether the GDPR applies to you at all)ℹ explanation only — nothing to do
Art. 5 (1) e, 17Deletion concept & storage limitation⚙ your job: delete! (how to ↓)
Art. 7, 8Obtaining & proving consent⚙ your job: consent process (how to ↓)
Art. 9, 10Special categories of data⚙ your job: legal assessment (how to ↓)
Art. 12–14Information duties (privacy notices)⚙ your job: write the notices (how to ↓)
Art. 26, 27Joint controllership, EU representative⚙ your job: agreements (how to ↓)
Art. 28Actually signing the DPAs⚙ your job: sign them! (how to ↓)
Art. 29, 32 (4)Staff commitment & training⚙ your job: people (how to ↓)
Art. 32Implementing the TOMs (IT security)⚙ your job: technology (how to ↓)
Art. 33Rehearsing the 72-hour breach path⚙ your job: run the drill (how to ↓)
Art. 37Appointing & registering a DPO⚙ your job: appointment (how to ↓)
Art. 44–49Third-country transfers⚙ your job: safeguards (how to ↓)

* Floriti provides the directory, the workflow and the evidence — the actual act (signing a contract, setting up a measure, filing a report) remains with your organisation. Those acts are exactly what this guide covers.

See the covered half in action: a free Floriti demo workspace comes with a pre-built GDPR register set — processing record, DPIA, incident log.

Get a free demo workspace →

The remaining duties, one by one

For each duty: what the GDPR expects, how to tackle it pragmatically — and how Floriti keeps your back covered while you do.

Art. 5 (1) e, 17 Deletion concept & storage limitation

Data may live only as long as purpose or retention law requires — after that it must actually go.

How to tackle it

  • Set a retention period per processing entry (statutory examples in Germany: 6/10 years commercial/tax law; applicant data: 6 months after rejection).
  • Build deletion classes instead of juggling individual deadlines (DIN 66398 approach): few classes, clear triggers.
  • Establish a fixed "deletion day" per quarter or year: owners work through the due classes in the source systems and log it.
  • Do not forget paper files — and backups: there it suffices that deletion follows the rotation cycle (document it!).
Floriti leverage: retention as a required field in the processing record, a "deletion log" register as proof of execution, reminders as the deletion-day alarm. And register data inside Floriti you delete right there — with an audit-log entry.

Art. 7, 8 Obtaining, proving and revoking consent

Wherever you rely on consent, you must be able to prove it — and withdrawing must be as easy as giving it.

How to tackle it

  • Website: a consent banner with a real choice (no "accept-only" design), decisions logged.
  • Newsletters & forms: double opt-in, an unsubscribe link in every mail.
  • Offline consent (event photos, reference naming): collect in writing and file centrally.
  • Careful with employees: because of the power imbalance, consent is rarely the right legal basis there — check whether Art. 6 (1) b/f carries instead.
Floriti leverage: a "consents" register for all offline cases (who, for what, when, scan attached, withdrawal date) with a report "active consents per purpose". Your consent tool handles the website part; Floriti documents which tool runs with which configuration.

Art. 9, 10 Special categories (health, religion, …)

Sensitive data is prohibited by default, with narrow exceptions — every such processing needs a verified exception under Art. 9 (2).

How to tackle it

  • Inventory first: where does sensitive data occur at all? (HR: sick notes, disability status, religious affiliation for payroll tax — almost every company has some.)
  • Name the exception per occurrence (usually Art. 9 (2) b — employment-law duties) and apply stricter measures: narrower access, encryption where feasible.
  • When in doubt, get legal advice — fines are highest here.
Floriti leverage: a "special categories? (yes/no)" field in the processing record — a condition then automatically reveals the follow-up questions (exception used, extra measures). The business department cannot skip them.

Art. 12–14 Information duties: privacy notices

Data subjects must be informed clearly at the time of collection — on your website, towards employees and applicants, for video surveillance.

How to tackle it

  • One notice per audience: website, customers, employees, applicants — not one catch-all text.
  • Most of the content already lives in your processing record: purposes, legal bases, recipients, retention. Derive the texts from it instead of inventing them.
  • Video surveillance: signage before entering the area, naming controller and purpose.
  • Review once a year — and whenever a new processing activity is approved.
Floriti leverage: export the processing record as source material for your lawyer or generator; keep a "privacy notices" register with file attachments, versions and a yearly review reminder. A rule can automatically create a check task whenever a new processing entry is approved.

Art. 26, 27 Joint controllership & EU representative

Running joint processing with partners (a shared portal, a Facebook page) requires an Art. 26 agreement. Non-EU companies with EU business need an EU representative (Art. 27).

How to tackle it

  • Check where you determine purposes and means jointly with others — it happens more often than expected (social media presences!).
  • Agree a clear split of roles: who answers data subject requests, who informs?
  • The essence of the agreement must be available to data subjects (privacy notice).
Floriti leverage: the agreements belong as entries in your partner/processor register — with responsibility fields, so in an incident it is instantly clear who delivers.

Art. 28 Actually signing the data processing agreements

Every service provider processing personal data on your behalf (hoster, newsletter tool, payroll office, IT support) needs a DPA — before processing starts.

How to tackle it

  • Take stock via your accounts-payable list: every vendor with data access is a candidate.
  • SaaS providers usually offer the DPA for online signature — sign it, archive the PDF.
  • New tools only with a DPA check in onboarding: no contract, no rollout.
  • Watch the providers' sub-processor lists (subscribe to change notifications).
Floriti leverage: your processor register keeps contract (attachment), signing date and review cycle per vendor; reminders enforce the yearly check, and the approval workflow puts a second pair of eyes on every new entry.

Art. 29, 32 (4) Committing and training your staff

Everyone with access to personal data may act only on instruction and must be bound to confidentiality and trained.

How to tackle it

  • Confidentiality commitment as part of onboarding: signed on day one, copy in the personnel file.
  • A yearly short training (45–60 min is enough): phishing, handling requests, clean desk, breach reporting path. External e-learning saves effort.
  • Train new joiners within their first 4 weeks, not at the next annual date.
Floriti leverage: a "training & commitments" register (person, date, content, proof attached) with a 12-month reminder; rule automation can turn stragglers into real work orders — completion shows up on the admin's task tile.

Art. 32 Actually implementing the TOMs (IT security)

The documented technical and organisational measures must really exist — documentation without implementation backfires in every audit.

The practical minimum

  • Access: two-factor authentication wherever possible; individual accounts instead of shared logins; rights on a need-to-know basis; an offboarding checklist (accounts blocked on the last day).
  • Devices & systems: full-disk encryption, automatic updates, central antivirus, screen lock.
  • Data: daily backups with a tested restore, TLS in transit, encrypted e-mail for sensitive content.
  • Organisation: an emergency plan (who does what when something fails), key/access rules, paper handling (shredder, not wastebasket).
  • For maturity guidance: BSI IT-Grundschutz profiles for SMEs or CIS Controls IG1; more ambitious: ISO 27001.
Floriti leverage: every measure as an entry in the TOM register with status, owner and review reminder — turning declarations into a control loop. For the data inside Floriti itself we already ship 2FA, SSO, a role concept, daily backups and EU hosting.

Art. 33 Rehearse the emergency once

The 72-hour window for notifying the supervisory authority is short — it only works if the path is clear beforehand.

How to tackle it

  • Make the internal reporting path known: every employee must know where to report an incident immediately (and that reporting is never punished).
  • Look at your authority's online notification form once and know the required details.
  • Run a 30-minute dry exercise once a year: fictitious incident, walk the process, note the gaps.
Floriti leverage: the intake channel is built in minutes with Floriti's public forms — every report automatically becomes an entry in your incident register. The follow-up runs on workflow steps, with several departments collaborating on the same case and every deadline in view; the demo workspace has this set up ready to explore. Only sending the notification to the authority is still on you — the workflow hands you the complete chronology at the press of a button. The drill itself, and its protocol, belong in the training register.

Art. 37 Appointing and registering a data protection officer

Whether you need a DPO depends on your activities (in Germany additionally: usually from 20 people with permanent automated processing). If yes: appoint formally and register with the supervisory authority.

How to tackle it

  • Check the obligation — when unsure, a voluntary external DPO is often cheaper than the uncertainty.
  • External vs. internal: external (typically 200–600 €/month for SMEs) avoids conflicts of interest and dismissal-protection issues; internal requires proven expertise and ongoing education.
  • Register the DPO's contact via the authority's online portal and add it to your privacy notice.
Floriti leverage: involve the DPO as an approver with their own scope and send them reports by e-mail subscription — "early involvement" (Art. 38) becomes daily routine instead of a claim.

Art. 44–49 Securing third-country transfers

Data may leave the EU only with safeguards — an adequacy decision, or standard contractual clauses (SCC) plus a transfer impact assessment (TIA).

How to tackle it

  • Transfers almost always hide among your vendors: US cloud, support teams outside the EU, the parent group. The DPA stock-take uncovers them.
  • Check in this order: adequacy decision (e.g. EU-US Data Privacy Framework — is the provider certified?) → otherwise SCC + a short TIA → otherwise switch providers.
  • Prefer EU alternatives when selecting tools — it spares you the whole assessment cascade.
Floriti leverage: a "third-country transfer?" field in the processing/processor register; a condition then reveals the safeguard questions (DPF? SCC? TIA date?). Floriti itself is hosted in the EU, and for the AI features you can plug in an EU or on-premise endpoint.

🗺️ The 90-day roadmap

A realistic sequence for an SME starting (almost) from scratch — each phase produces evidence you keep.

  1. Weeks 1–2: stock-take.Complete the record of processing activities (invite the business departments via questionnaire) — it is the source for almost everything else.
  2. Weeks 3–4: vendors.Fill the processor register, sign missing DPAs, flag third-country transfers and check safeguards.
  3. Weeks 5–6: texts.Derive privacy notices from the processing record (website, employees, applicants), settle the DPO question and appoint if needed.
  4. Weeks 7–9: technology.Implement the TOM minimum (2FA, backups with restore test, encryption, offboarding) and document it in the TOM register with review cycles.
  5. Weeks 10–11: people.Collect confidentiality commitments, run the first training round, communicate the breach reporting path.
  6. Week 12: close the loop.Deletion concept with a first deletion day, reminders for all yearly reviews, a short emergency drill — from here, the cycle carries itself.

Ready to start week 1? A Floriti demo workspace is free, prefilled with linked GDPR sample registers — and everything in this guide that says "register" is a few clicks away.

Start your stock-take now →

📥 Take the roadmap with you — as a print-ready PDF

The whole guide as a tick-off checklist for your next data protection meeting — including the 90-day plan. Enter your e-mail address, confirm the link we send you (double opt-in, of course), and the PDF is yours.

⚠️ Important: this guide is practical orientation from a tooling perspective and does not replace legal advice. Sector specifics (healthcare, finance, telemedia) and national add-on duties are best discussed once with a specialised lawyer or your DPO — with your register export as the basis, those are short meetings.