The six steps for complying with GDPR are: 1) Know your data - conduct an audit to understand what personal data is collected and where it is stored. 2) Classify the data - determine what is personal data, sensitive personal data, and confidential business information. 3) Justify the data - establish the lawful basis and purpose for collecting and processing each type of data. 4) Plan how the data will be handled - establish processes for collection, storage, processing, deletion and retention. 5) Control access to data and keep it secure. 6) Be prepared to respond to a data breach by notifying authorities and individuals whose data was involved within 72 hours.