Manage a GDPR compliance project with a Gantt chart. Track data mapping, policy updates, consent management, and DPA milestones. Free online Gantt chart tool.
GDPR compliance requires coordinated effort across legal, engineering, product, HR, and customer success. Legal writes the privacy policy, but engineering must implement the technical controls (data deletion, consent management, data portability). Product must redesign consent flows. Customer success must respond to data subject requests within the 30-day window.
Without a GDPR compliance project timeline, each team does their part in isolation. Legal updates the privacy policy but engineering hasn't implemented data deletion. Engineering builds a consent banner but it doesn't integrate with the CRM. The result is compliance theater: documents that say the right things but technical systems that don't enforce them.
A Gantt chart maps every workstream with explicit owners and shows where teams are dependent on each other. gantt-chart.io is free and requires no account.
GDPR Compliance ProgramIdentify all personal data categories collected — Week 1Map data flows: collection → processing → storage → sharing — Week 1-3Identify data processors and sub-processors — Week 2-3Document retention periods per data category — Week 3Record of Processing Activities (ROPA) drafted — Week 3-4ROPA reviewed by legal — Week 4ROPA approved — Week 4 (milestone)Privacy notice updated — Week 3-5Cookie policy updated — Week 4-5Lawful basis documented for each processing activity — Week 4-6Data retention policy defined — Week 5-6Data breach notification procedure — Week 6-7All policies reviewed by legal counsel — Week 7-8Policies published on website — Week 8 (milestone)Consent banner requirements defined — Week 5Consent management platform selected (OneTrust, Cookiebot, etc.) — Week 5-6Consent banner implemented on website — Week 6-8Cookie scanning and categorization — Week 7Preference center implemented — Week 7-9Consent records stored (who consented, when, to what) — Week 8-10Consent management complete — Week 10 (milestone)Data deletion (right to erasure) endpoint implemented — Week 6-9Data portability (right to data portability) export implemented — Week 8-11Data access request (right of access) process implemented — Week 9-12Data minimization audit — Week 10-12Retention-based data deletion automation — Week 11-14All technical controls tested — Week 14 (milestone)Processor inventory from ROPA — Week 6DPA signed with each processor — Week 7-11Standard Contractual Clauses (SCCs) for US/non-adequate-country transfers — Week 8-12Transfer impact assessments for high-risk transfers — Week 10-12Vendor management complete — Week 12 (milestone)Data Subject Request (DSR) response procedure documented — Week 10-12Data breach response procedure — Week 11-13Staff GDPR training — Week 13-15Training completion tracked — Week 15GDPR program operational — Week 16 (milestone)Under GDPR, you must respond to DSRs within one calendar month (extendable to 3 months with notice). Build a response tracker alongside the Gantt chart:
| DSR Type | Required Action | SLA |
|----------|----------------|-----|
| Right of access | Provide copy of all personal data | 30 days |
| Right to erasure | Delete all personal data | 30 days |
| Right to portability | Provide data in machine-readable format | 30 days |
| Right to object | Stop processing (if legitimate interest basis) | 30 days |
Add DSR tracking as an ongoing operational task after the project closes.
Updating policies without implementing technical controls. A GDPR-compliant privacy notice that promises "we will delete your data on request" without a working deletion endpoint is a false representation and increases legal exposure.
No breach notification procedure. GDPR requires notification to the supervisory authority within 72 hours of discovering a breach. Companies that discover a breach and have no procedure routinely miss this window, compounding the violation.
Build your GDPR compliance timeline at gantt-chart.io—free, no account required.