How to Manage a GDPR Compliance Project Timeline
The Problem: GDPR Compliance Is a Multi-Team Program, Not a Legal Task
GDPR compliance requires coordinated effort across legal, engineering, product, HR, and customer success. Legal writes the privacy policy, but engineering must implement the technical controls (data deletion, consent management, data portability). Product must redesign consent flows. Customer success must respond to data subject requests within the 30-day window.
Without a GDPR compliance project timeline, each team does their part in isolation. Legal updates the privacy policy but engineering hasn't implemented data deletion. Engineering builds a consent banner but it doesn't integrate with the CRM. The result is compliance theater: documents that say the right things but technical systems that don't enforce them.
A Gantt chart maps every workstream with explicit owners and shows where teams are dependent on each other. gantt-chart.io is free and requires no account.
Prerequisites
- Legal counsel: GDPR counsel engaged (internal or external)
- Data Processing Officer: Appointed if required (companies with large-scale processing)
- Scope: Which users are in the EU/EEA? What data is processed?
- Lawful basis: What is the lawful basis for each processing activity? (Consent, legitimate interest, contract, etc.)
- Vendor inventory: What third-party processors handle EU data?
Step-by-Step Instructions
Step 1: Set Up the Timeline
- Open gantt-chart.io
- Title the chart:
GDPR Compliance Program - Plan 16–24 weeks for a comprehensive GDPR implementation
- Add quarterly milestones for board/executive reporting
- Use Week view
Step 2: Define the Six GDPR Workstreams
- Data Mapping — record of processing activities (ROPA)
- Legal & Policies — privacy notice, cookie policy, DPAs
- Consent Management — consent banner, preference center, consent records
- Technical Controls — data deletion, portability, access controls
- Vendor Management — DPAs with all processors, SCCs for international transfers
- Training & Procedures — staff training, DSR response procedure
Step 3: Data Mapping (Week 1-4)
Identify all personal data categories collected— Week 1Map data flows: collection → processing → storage → sharing— Week 1-3Identify data processors and sub-processors— Week 2-3Document retention periods per data category— Week 3Record of Processing Activities (ROPA) drafted— Week 3-4ROPA reviewed by legal— Week 4ROPA approved— Week 4 (milestone)
Step 4: Legal & Policies (Week 3-8)
Privacy notice updated— Week 3-5Cookie policy updated— Week 4-5Lawful basis documented for each processing activity— Week 4-6Data retention policy defined— Week 5-6Data breach notification procedure— Week 6-7All policies reviewed by legal counsel— Week 7-8Policies published on website— Week 8 (milestone)
Step 5: Consent Management (Week 5-10)
Consent banner requirements defined— Week 5Consent management platform selected (OneTrust, Cookiebot, etc.)— Week 5-6Consent banner implemented on website— Week 6-8Cookie scanning and categorization— Week 7Preference center implemented— Week 7-9Consent records stored (who consented, when, to what)— Week 8-10Consent management complete— Week 10 (milestone)
Step 6: Technical Controls (Week 6-14)
Data deletion (right to erasure) endpoint implemented— Week 6-9Data portability (right to data portability) export implemented— Week 8-11Data access request (right of access) process implemented— Week 9-12Data minimization audit— Week 10-12Retention-based data deletion automation— Week 11-14All technical controls tested— Week 14 (milestone)
Step 7: Vendor Management (Week 6-12)
Processor inventory from ROPA— Week 6DPA signed with each processor— Week 7-11Standard Contractual Clauses (SCCs) for US/non-adequate-country transfers— Week 8-12Transfer impact assessments for high-risk transfers— Week 10-12Vendor management complete— Week 12 (milestone)
Step 8: Training & Procedures (Week 10-16)
Data Subject Request (DSR) response procedure documented— Week 10-12
- 30-day response window tracked
- Who handles each type (access, deletion, portability, objection)?
Data breach response procedure— Week 11-13
- 72-hour supervisory authority notification
- Customer notification process
Staff GDPR training— Week 13-15Training completion tracked— Week 15GDPR program operational— Week 16 (milestone)
Data Subject Request Response SLAs
Under GDPR, you must respond to DSRs within one calendar month (extendable to 3 months with notice). Build a response tracker alongside the Gantt chart:
| DSR Type | Required Action | SLA |
|---|---|---|
| Right of access | Provide copy of all personal data | 30 days |
| Right to erasure | Delete all personal data | 30 days |
| Right to portability | Provide data in machine-readable format | 30 days |
| Right to object | Stop processing (if legitimate interest basis) | 30 days |
Add DSR tracking as an ongoing operational task after the project closes.
Common Mistakes
Updating policies without implementing technical controls. A GDPR-compliant privacy notice that promises "we will delete your data on request" without a working deletion endpoint is a false representation and increases legal exposure.
No breach notification procedure. GDPR requires notification to the supervisory authority within 72 hours of discovering a breach. Companies that discover a breach and have no procedure routinely miss this window, compounding the violation.
Build your GDPR compliance timeline at gantt-chart.io—free, no account required.