Build a GDPR compliance project plan with a Gantt chart. Track data mapping, policy updates, consent mechanisms, vendor reviews, and DPA registration on a structured timeline.
The most dangerous misconception about GDPR compliance is treating it as a one-time implementation. In reality, GDPR requires ongoing processes: regular data mapping updates, active consent management, vendor reassessments, data subject request handling, and breach notification procedures that must be functional at all times.
That said, there is a meaningful first-pass compliance project — the work required to get from "we handle EU data but haven't formalized anything" to "we have documented processes, appropriate controls, and can respond to a regulator."
This guide covers building a GDPR compliance Gantt chart for that first-pass project, plus the ongoing compliance tasks that belong in your operational calendar.
| Phase | Work | Duration | Dependency |
|---|---|---|---|
| Data inventory and mapping | Identify all personal data, processing purposes, and data flows | 2–4 weeks | None |
| Lawful basis documentation | Document legal basis for each processing activity | 1–2 weeks | Data mapping complete |
| Consent mechanism review | Audit and update consent flows, cookie banners, opt-outs | 2–3 weeks | Data mapping complete |
| Privacy policy update | Update privacy notice to GDPR standards | 1–2 weeks | Data inventory + lawful basis |
| Vendor assessment | Review third-party processors, update DPAs | 2–4 weeks | Data mapping complete |
| Internal policies | Update HR data policies, retention policies, breach notification procedure | 2–3 weeks | Data mapping complete |
| DSR process | Implement process for data subject access, deletion, portability requests | 2 weeks | Data mapping + policies |
| Staff training | GDPR awareness training for all staff | 1–2 weeks | Policies drafted |
| DPA registration | Register Data Processing Agreement with relevant DPA (if required) | 1–3 weeks | Policies complete |
| Technical controls | Encryption, access controls, retention automation, audit logging | 3–5 weeks | Data mapping complete |
| DPO appointment | Appoint or designate Data Protection Officer (if required) | 1 week | Early task |
Everything in GDPR compliance depends on knowing what personal data you process, where it lives, why you process it, and who has access to it. Data mapping is the foundation.
Don't start drafting privacy policies or updating consent flows before data mapping is complete. You'll draft them based on incomplete information and have to revise them.
Open gantt-chart.io and set data mapping as the first task. Every other workstream has a dependency arrow pointing to data mapping.
After data mapping is complete, four workstreams can run in parallel:
Create a swim lane section for each. Running these in parallel typically saves 4–6 weeks compared to sequencing them.
Consent is the most visible part of GDPR for users. Cookie banners, marketing opt-ins, and analytics tracking all need review.
Add specific tasks:
These are often technically straightforward but require coordination between marketing, engineering, and legal to get the wording and mechanics right.
Vendor assessment is always longer than expected. You need to:
For an average SaaS company, this is 20–50 vendors. Add 3–4 weeks for this track and assign a dedicated owner.
After the initial project completes, GDPR requires ongoing work. Add a "Post-Project Operations" section with recurring tasks:
These belong in your project calendar, not just in policy documents.
Starting with the privacy policy, not data mapping. Privacy policies written before data mapping is complete are inaccurate and will need to be rewritten. Always map first.
Treating cookie consent as a design problem. Cookie banners are a legal requirement with specific behavior requirements (no dark patterns, affirmative consent before non-essential cookies, granular controls). Involve legal in the cookie consent design, not just UX.
Ignoring HR data. Employee data is personal data under GDPR. HR policies, recruitment data retention, and employee monitoring are in scope. Many first-pass GDPR projects miss this entirely.
No DSR process. Data subject rights (access, erasure, portability) require a functioning response process. If your company receives a deletion request and has no process, you'll miss the 30-day response deadline and expose yourself to regulatory risk.
Treating DPA registration as optional. Whether your organization needs to register with a Data Protection Authority depends on size, processing activities, and EU member state. Get a legal determination on this early — it's not optional if it applies.
Foundation
Data Inventory + Mapping |████████░░░░░░░░░░░░░░░░░░░░░░░░| Weeks 1-3
DPO Appointment |████░░░░░░░░░░░░░░░░░░░░░░░░░░░░| Week 1 (parallel)
Legal Track
Lawful Basis Docs |░░░░░░████████░░░░░░░░░░░░░░░░░░| Weeks 4-6
Privacy Policy Update |░░░░░░░░░░████████░░░░░░░░░░░░░░| Weeks 6-8
DPA Registration |░░░░░░░░░░░░░░░░░░░░████░░░░░░░░| Weeks 10-12
Technical Track
Consent Mechanism Audit |░░░░░░████████████░░░░░░░░░░░░░░| Weeks 4-8
Technical Controls |░░░░░░░░░░████████████░░░░░░░░░░| Weeks 6-11
DSR Process Implementation |░░░░░░░░░░░░░░░░████████░░░░░░░░| Weeks 9-12
Procurement Track
Vendor Inventory |░░░░░░████░░░░░░░░░░░░░░░░░░░░░░| Weeks 4-5
Vendor Assessment + DPAs |░░░░░░░░░░████████████░░░░░░░░░░| Weeks 6-12
HR + Internal
Staff Data Policies |░░░░░░████████░░░░░░░░░░░░░░░░░░| Weeks 4-7
Breach Notification Proc |░░░░░░░░░░████░░░░░░░░░░░░░░░░░░| Weeks 6-8
Staff Training |░░░░░░░░░░░░░░░░░░████░░░░░░░░░░| Weeks 10-12
Milestones
Data Mapping Complete Week 3 ◆
Consent Flows Live Week 8 ◆
Vendor DPAs Complete Week 12 ◆
Initial Compliance Review Week 16 ◆
Build your GDPR compliance timeline in gantt-chart.io. Start with data mapping as the anchor task. Add legal, technical, vendor, and HR swim lanes in parallel. Share the chart with your legal counsel and technical lead before project kickoff to validate the dependency sequence and timing.