Plan your GDPR and CCPA compliance program with a Gantt chart — data mapping, PIAs, vendor DPAs, training, breach response, and annual review cycles.
Data privacy compliance is not a one-time project. GDPR and CCPA create ongoing obligations — annual assessments, vendor reviews, policy updates, employee training renewals — that sit alongside the initial buildout work. Organizations that treat privacy compliance as a project to complete miss the maintenance cycle and accumulate regulatory risk. Organizations that treat it as a program with a managed timeline stay current.
A Gantt chart for data privacy compliance maps both the initial buildout and the recurring maintenance calendar, so your legal, IT, and operations teams know exactly what work lands when.
Privacy compliance programs have two distinct tracks running in parallel:
Track 1: Initial compliance buildout — the one-time (or one-cycle) work of documenting data flows, executing vendor agreements, implementing technical controls, and publishing required policies.
Track 2: Ongoing maintenance — the recurring annual and event-triggered obligations that keep the program current after the initial buildout.
New organizations launching a program for the first time run Track 1 for 6–9 months, then shift to Track 2 maintenance. Established organizations with existing programs skip most of Track 1 and focus on gap remediation.
You cannot build a compliant privacy program without knowing what personal data your organization processes. This is the foundational step, and it's almost always more work than teams expect.
Data inventory components:
Under GDPR Article 30, organizations with 250 or more employees (and smaller organizations in certain circumstances) must maintain a Record of Processing Activities (RoPA). The data inventory is the source material for the RoPA.
Data mapping is typically done through a combination of IT system audit, department interviews, and vendor documentation review. Assign a data privacy coordinator to own this phase and give them 6–8 weeks minimum. Rushing it produces an incomplete inventory that creates blind spots.
GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) for processing activities that are "likely to result in a high risk" to data subjects. California's CPRA (the 2023 amendment to CCPA) added similar requirements for certain "high-risk" processing.
Triggering criteria for mandatory DPIA/PIA:
PIA process for each high-risk processing activity:
Schedule PIAs concurrently with data mapping, as the mapping output tells you which activities need assessment. Depending on the number of high-risk activities, this phase runs 4–8 weeks.
Every third-party vendor that processes personal data on your behalf is a "data processor" under GDPR and must sign a Data Processing Agreement (DPA). CCPA uses the term "service provider" for similar relationships.
Vendor DPA process:
Large organizations may have 50–200 vendors that touch personal data. Prioritize by risk and work through them in batches. Plan 8–10 weeks for a mid-size vendor portfolio.
GDPR Articles 13–14 require organizations to provide data subjects with specific information at the time of data collection. CCPA/CPRA requires specific disclosures and opt-out rights.
Privacy policy requirements:
Cookie consent:
Schedule legal drafting and developer implementation (cookie banner) concurrently. Legal drafting typically takes 2–3 weeks; CMP implementation takes 1–2 weeks for a web team with the vendor selected.
GDPR and CCPA violations frequently trace to employee error — phishing susceptibility, improper data sharing, incorrect retention practices. Regulators expect documented training as part of any compliance program.
Training program components:
Training completion must be documented. Use your LMS or a privacy training vendor (OneTrust, NYMITY, etc.) with built-in completion tracking. Plan 4–6 weeks for content development and rollout across the organization.
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming "aware" of a personal data breach. CCPA has separate breach notification requirements under California law.
Breach response plan elements:
Run tabletop exercises after the plan is written — ideally 2 scenarios (a low-severity unencrypted laptop loss and a high-severity system compromise involving customer financial data). Tabletop exercises surface gaps in the plan that reading it doesn't.
GDPR Article 37 mandates appointment of a DPO for public authorities, organizations that conduct large-scale systematic monitoring of individuals, and organizations that process special category data at scale. Even organizations not technically required to appoint a DPO frequently do so.
DPO timeline:
The DPO must be involved in all privacy-related decisions from their appointment date forward, so this step runs in parallel with the other buildout phases.
GDPR Article 30 (Record of Processing Activities):
CCPA opt-out mechanism:
CPRA Data Minimization and Retention:
Privacy compliance is not "done." Build these recurring obligations into your annual calendar:
| Obligation | Frequency | Trigger |
|---|---|---|
| Privacy policy review and update | Annual | January |
| Vendor DPA review | Annual | February |
| Employee training | Annual | Q1 |
| Data inventory refresh | Annual | Q2 |
| PIA review for existing high-risk activities | Annual | Q2 |
| Cookie consent and CMP audit | Annual | Q3 |
| Breach response tabletop | Annual | Q4 |
| DPO review of program | Quarterly | Ongoing |
| New vendor DPA | Event-triggered | On new vendor onboarding |
| New processing PIA | Event-triggered | On new processing activity |
A complete GDPR/CCPA compliance program Gantt chart:
| Phase | Timeline | Owner | Key Deliverable |
|---|---|---|---|
| Data mapping and inventory | Weeks 1–8 | Privacy coordinator + IT | Complete RoPA |
| DPO appointment | Weeks 1–6 | Legal/HR | DPO in role, notified to authority |
| PIA/DPIA assessments | Weeks 6–14 | Privacy coordinator + legal | PIAs complete for all high-risk activities |
| Vendor DPA review | Weeks 8–18 | Legal + procurement | All vendors with signed DPAs |
| Privacy policy and cookie banner | Weeks 10–16 | Legal + IT | Published, compliant policy and CMP live |
| Employee training | Weeks 14–20 | HR + privacy team | 100% completion documented |
| Breach response plan | Weeks 14–20 | Legal + IT + exec | Tested plan, tabletop complete |
| CCPA opt-out mechanism | Weeks 16–20 | IT + legal | Functional opt-out link, GPC signal accepted |
| Annual review cycle | Ongoing | DPO/Privacy coordinator | Calendar of recurring obligations |
The total buildout for an organization starting from scratch is typically 5–7 months. Organizations with mature security and legal functions can compress to 4 months; organizations with fragmented IT systems and no prior privacy work should budget 8–9 months.
The Gantt chart is your accountability layer. Privacy programs that fail to maintain themselves almost always fail because the recurring obligations weren't calendared and owned — they were left to "someone will do it when it comes up." Build the annual review cycle into your Gantt chart from day one.
Build your data privacy compliance Gantt chart free at gantt-chart.io