Gantt Chart for Data Privacy Compliance
Data privacy compliance is not a one-time project. GDPR and CCPA create ongoing obligations — annual assessments, vendor reviews, policy updates, employee training renewals — that sit alongside the initial buildout work. Organizations that treat privacy compliance as a project to complete miss the maintenance cycle and accumulate regulatory risk. Organizations that treat it as a program with a managed timeline stay current.
A Gantt chart for data privacy compliance maps both the initial buildout and the recurring maintenance calendar, so your legal, IT, and operations teams know exactly what work lands when.
The Two-Track Privacy Compliance Timeline
Privacy compliance programs have two distinct tracks running in parallel:
Track 1: Initial compliance buildout — the one-time (or one-cycle) work of documenting data flows, executing vendor agreements, implementing technical controls, and publishing required policies.
Track 2: Ongoing maintenance — the recurring annual and event-triggered obligations that keep the program current after the initial buildout.
New organizations launching a program for the first time run Track 1 for 6–9 months, then shift to Track 2 maintenance. Established organizations with existing programs skip most of Track 1 and focus on gap remediation.
Phase 1: Data Mapping and Inventory (Weeks 1–8)
You cannot build a compliant privacy program without knowing what personal data your organization processes. This is the foundational step, and it's almost always more work than teams expect.
Data inventory components:
- Data categories — what types of personal data do you collect? (name, email, financial data, health data, biometric data, etc.)
- Data subjects — whose data is it? (customers, employees, website visitors, job applicants, vendors)
- Collection sources — how does the data enter your systems? (web forms, cookies, API integrations, paper forms, call center capture)
- Processing purposes — why are you processing each data category? (contract fulfillment, marketing, analytics, legal obligation, legitimate interest)
- Storage locations — where does the data live? (CRM, ERP, data warehouse, third-party SaaS platforms, file servers, email systems)
- Retention periods — how long do you keep each data category, and what's the deletion process?
- Transfer destinations — is the data shared with third parties, including SaaS vendors, analytics providers, or entities outside the EU?
Under GDPR Article 30, organizations with 250 or more employees (and smaller organizations in certain circumstances) must maintain a Record of Processing Activities (RoPA). The data inventory is the source material for the RoPA.
Data mapping is typically done through a combination of IT system audit, department interviews, and vendor documentation review. Assign a data privacy coordinator to own this phase and give them 6–8 weeks minimum. Rushing it produces an incomplete inventory that creates blind spots.
Phase 2: Privacy Impact Assessments (Weeks 6–14)
GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) for processing activities that are "likely to result in a high risk" to data subjects. California's CPRA (the 2023 amendment to CCPA) added similar requirements for certain "high-risk" processing.
Triggering criteria for mandatory DPIA/PIA:
- Systematic profiling with legal or significant effects
- Large-scale processing of sensitive data (health, race, religion, criminal records)
- Systematic monitoring of a publicly accessible area (CCTV)
- Automated decision-making
- New technologies with uncertain risk profiles
- Combining datasets in ways data subjects would not expect
PIA process for each high-risk processing activity:
- Describe the processing and its purposes
- Assess necessity and proportionality
- Identify and assess risks to data subjects
- Identify measures to address those risks
- Document residual risk and, if unacceptable, consult with your supervisory authority
Schedule PIAs concurrently with data mapping, as the mapping output tells you which activities need assessment. Depending on the number of high-risk activities, this phase runs 4–8 weeks.
Phase 3: Vendor DPA Review and Execution (Weeks 8–18)
Every third-party vendor that processes personal data on your behalf is a "data processor" under GDPR and must sign a Data Processing Agreement (DPA). CCPA uses the term "service provider" for similar relationships.
Vendor DPA process:
- Vendor inventory — from your data mapping, identify every SaaS vendor, analytics provider, marketing platform, and contractor that touches personal data
- Prioritization — classify vendors by risk (volume of data, sensitivity of data categories, location of processing)
- DPA collection or drafting — most major vendors (Google, Salesforce, HubSpot, AWS) have standard DPAs available; smaller vendors may need a custom agreement
- DPA review — legal review of vendor-provided DPAs for GDPR adequacy; key provisions to check: sub-processor obligations, data return and deletion obligations, audit rights, breach notification timelines
- Standard Contractual Clauses — for vendors processing data outside the EU/EEA, SCCs must be incorporated
- Execution and filing — signed DPAs must be retained and linked to your vendor inventory
Large organizations may have 50–200 vendors that touch personal data. Prioritize by risk and work through them in batches. Plan 8–10 weeks for a mid-size vendor portfolio.
Phase 4: Privacy Policy and Cookie Banner Updates (Weeks 10–16)
GDPR Articles 13–14 require organizations to provide data subjects with specific information at the time of data collection. CCPA/CPRA requires specific disclosures and opt-out rights.
Privacy policy requirements:
- Identity and contact details of the controller (and DPO if applicable)
- Purposes and legal basis for each processing activity
- Categories of personal data collected
- Recipients or categories of recipients
- Retention periods
- Data subject rights (access, erasure, portability, objection, rectification)
- Right to lodge a complaint with a supervisory authority
- CCPA-specific: right to know, right to delete, right to opt out of sale/sharing, right to non-discrimination
Cookie consent:
- Cookie banner must obtain consent before placing non-essential cookies
- Consent must be freely given, specific, informed, and unambiguous — pre-ticked boxes are not valid consent under GDPR
- Users must be able to withdraw consent as easily as they gave it
- Implement a Consent Management Platform (CMP) that stores consent records
Schedule legal drafting and developer implementation (cookie banner) concurrently. Legal drafting typically takes 2–3 weeks; CMP implementation takes 1–2 weeks for a web team with the vendor selected.
Phase 5: Employee Training (Weeks 14–20)
GDPR and CCPA violations frequently trace to employee error — phishing susceptibility, improper data sharing, incorrect retention practices. Regulators expect documented training as part of any compliance program.
Training program components:
- General awareness training — all staff, covering what personal data is, why it matters, their individual obligations, and how to report incidents
- Role-specific training — IT (security controls, breach response), HR (employee data), marketing (consent, data use), customer service (data subject rights fulfillment)
- Privacy incident response training — who to call, what to document, what the 72-hour GDPR notification window means
- Annual refresher training — schedule in the maintenance calendar
Training completion must be documented. Use your LMS or a privacy training vendor (OneTrust, NYMITY, etc.) with built-in completion tracking. Plan 4–6 weeks for content development and rollout across the organization.
Phase 6: Breach Response Plan Development (Weeks 14–20)
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming "aware" of a personal data breach. CCPA has separate breach notification requirements under California law.
Breach response plan elements:
- Definition of what constitutes a reportable breach (not all security incidents are personal data breaches)
- Incident response team with defined roles (DPO, legal, IT security, communications, executive)
- Detection and assessment procedures (how do you know you have a breach? who assesses scope within the first 24 hours?)
- 72-hour notification decision tree (does this breach require supervisory authority notification? does it require direct notification to data subjects?)
- Documentation requirements (what must be recorded even for non-reportable incidents, per GDPR Article 33(5))
- Post-incident review process
Run tabletop exercises after the plan is written — ideally 2 scenarios (a low-severity unencrypted laptop loss and a high-severity system compromise involving customer financial data). Tabletop exercises surface gaps in the plan that reading it doesn't.
Phase 7: Data Protection Officer Appointment (Weeks 1–6, if required)
GDPR Article 37 mandates appointment of a DPO for public authorities, organizations that conduct large-scale systematic monitoring of individuals, and organizations that process special category data at scale. Even organizations not technically required to appoint a DPO frequently do so.
DPO timeline:
- Determine if appointment is mandatory (week 1–2)
- Decide internal vs. external DPO (internal requires sufficient independence from business functions; external is often more practical for mid-size companies)
- Selection and onboarding (weeks 3–6)
- Notification to supervisory authority (required under GDPR Article 37(7))
The DPO must be involved in all privacy-related decisions from their appointment date forward, so this step runs in parallel with the other buildout phases.
Phase 8: Regulatory Filing Deadlines
GDPR Article 30 (Record of Processing Activities):
- Must be maintained in writing (electronic is acceptable)
- Must be made available to supervisory authority on request
- No proactive filing required, but must be current and accurate at all times
- Target completion: week 10–12 (after data mapping is finalized)
CCPA opt-out mechanism:
- "Do Not Sell or Share My Personal Information" link must be present on the homepage and in the privacy policy
- Must be functional (requests processed within 15 business days)
- Must accept Global Privacy Control (GPC) signals as opt-out requests
- Target completion: week 16 (when privacy policy and cookie banner work is done)
CPRA Data Minimization and Retention:
- Ongoing obligation; document retention schedules as part of data inventory
- Annual review of retention schedules in maintenance calendar
Phase 9: Annual Compliance Review Cycle
Privacy compliance is not "done." Build these recurring obligations into your annual calendar:
| Obligation | Frequency | Trigger |
|---|---|---|
| Privacy policy review and update | Annual | January |
| Vendor DPA review | Annual | February |
| Employee training | Annual | Q1 |
| Data inventory refresh | Annual | Q2 |
| PIA review for existing high-risk activities | Annual | Q2 |
| Cookie consent and CMP audit | Annual | Q3 |
| Breach response tabletop | Annual | Q4 |
| DPO review of program | Quarterly | Ongoing |
| New vendor DPA | Event-triggered | On new vendor onboarding |
| New processing PIA | Event-triggered | On new processing activity |
Building Your Privacy Compliance Gantt Chart
A complete GDPR/CCPA compliance program Gantt chart:
| Phase | Timeline | Owner | Key Deliverable |
|---|---|---|---|
| Data mapping and inventory | Weeks 1–8 | Privacy coordinator + IT | Complete RoPA |
| DPO appointment | Weeks 1–6 | Legal/HR | DPO in role, notified to authority |
| PIA/DPIA assessments | Weeks 6–14 | Privacy coordinator + legal | PIAs complete for all high-risk activities |
| Vendor DPA review | Weeks 8–18 | Legal + procurement | All vendors with signed DPAs |
| Privacy policy and cookie banner | Weeks 10–16 | Legal + IT | Published, compliant policy and CMP live |
| Employee training | Weeks 14–20 | HR + privacy team | 100% completion documented |
| Breach response plan | Weeks 14–20 | Legal + IT + exec | Tested plan, tabletop complete |
| CCPA opt-out mechanism | Weeks 16–20 | IT + legal | Functional opt-out link, GPC signal accepted |
| Annual review cycle | Ongoing | DPO/Privacy coordinator | Calendar of recurring obligations |
The total buildout for an organization starting from scratch is typically 5–7 months. Organizations with mature security and legal functions can compress to 4 months; organizations with fragmented IT systems and no prior privacy work should budget 8–9 months.
The Gantt chart is your accountability layer. Privacy programs that fail to maintain themselves almost always fail because the recurring obligations weren't calendared and owned — they were left to "someone will do it when it comes up." Build the annual review cycle into your Gantt chart from day one.
Build your data privacy compliance Gantt chart free at gantt-chart.io