This document outlines 12 steps organizations should take to prepare for the General Data Protection Regulation (GDPR) which takes effect in May 2018. It advises documenting all personal data held, its sources, and who it is shared with. Privacy policies and procedures need updating to clearly communicate information processing activities and individuals' rights. Consent management and data breach response plans should be reviewed. Impact assessments and data protection officer roles may need to be implemented to comply with GDPR principles. International organizations will need a lead supervisory authority. Taking action now allows time to understand changes and ensure compliance.