How ready is your organisation, honestly?
23 questions across 5 areas, each with why it matters and what good looks like. Grounded in the regulation text and in what the supervisory authorities have actually fined. Answer yes, partly or no; the readiness score updates as you go and tells you where to start. Your answers stay in your browser.
- Questions
- 23
- Time
- about 20 minutes
- To use it
- nothing
- Pen and paper
- printable
- Written report
- your email
Lawful basis and transparency
Do you know what you process, why, and can you show it?
We have a written record of what personal data we process, where it comes from, who it goes to and how long we keep it.
Why it matters and what good looks likeHide
- Why
- Article 30 requires most controllers to keep this record, and every other item on this list depends on it.
- Good looks like
- A maintained record of processing activities, one row per purpose, that names the data categories, recipients, retention period and legal basis. Reviewed when systems change, not once a year.
Every processing purpose has a named legal basis, decided before the processing started.
Why it matters and what good looks likeHide
- Why
- Consent, contract, legal obligation, vital interests, public task or legitimate interests. Processing without one is unlawful regardless of how careful the rest is.
- Good looks like
- The basis is recorded per purpose. Where it is legitimate interests, a balancing test exists. Where it is consent, the consent meets the Article 7 standard: specific, informed, freely given, withdrawable.
Our privacy notice states each purpose, its legal basis, the recipients and the retention period, in language a visitor can follow.
Why it matters and what good looks likeHide
- Why
- Articles 13 and 14 set the content. A notice that lists categories without purposes, or purposes without a basis, does not meet it.
- Good looks like
- A notice that a reader can map to the record of processing, updated when the record changes, with a version date.
We tell people about processing at the moment we collect the data, not only in a policy page.
Why it matters and what good looks likeHide
- Why
- Transparency is judged at the point of collection: the form, the banner, the sign-up screen.
- Good looks like
- A short layered notice at each collection point that links to the full policy.
Consent, cookies and tracking
Does the website actually do what the banner says?
No non-essential tag, pixel or cookie loads before the visitor has made a choice.
Why it matters and what good looks likeHide
- Why
- ePrivacy Article 5(3) requires consent before anything is stored on or read from the device. Tags that fire on page load, then wait for consent, are the most common finding in our audits.
- Good looks like
- Tags are gated in the tag manager so they do not exist until the consent state allows them. Verified in the browser's network tab, not in the platform's dashboard.
- Read
- What fires before consent: the free audit →
Rejecting is as easy as accepting: same screen, same number of clicks, equal visual weight.
Why it matters and what good looks likeHide
- Why
- Supervisory authorities across the EU have fined for reject buttons hidden behind a second layer or styled to be overlooked.
- Good looks like
- Accept and reject as equal buttons on the first layer. Closing the banner is not treated as consent.
- Read
- GDPR cookie consent in 2026 →
Consent is granular by purpose, and a rejection is respected on every subsequent page and visit.
Why it matters and what good looks likeHide
- Why
- A single accept-all is not specific consent. A choice that resets on the next page was never stored.
- Good looks like
- Categories the visitor can set individually, the state stored and re-read on every page, and the same state driving the tag manager.
The consent state is passed to Google, Microsoft and any ad-tech vendors as a signal they act on.
Why it matters and what good looks likeHide
- Why
- A banner that stores a choice but never tells the tags is compliant on paper only.
- Good looks like
- Consent Mode v2 parameters, the IAB TCF string where ad-tech is used, and platform-specific consent APIs, all set from the same state.
- Read
- Consent Mode v2, GPC and the IAB GPP →
We keep a record of each consent: what was shown, what was chosen, when, and under which version of the notice.
Why it matters and what good looks likeHide
- Why
- Article 7(1): the controller must be able to demonstrate consent.
- Good looks like
- Consent records with a timestamp, the categories chosen and the banner version, exportable for a regulator or a subject access request.
A visitor can find and change their choice at any time, as easily as they gave it.
Why it matters and what good looks likeHide
- Why
- Article 7(3): withdrawal must be as easy as giving consent.
- Good looks like
- A preference centre link in the footer and in the privacy notice that reopens the same categories.
Security and breach readiness
Is the data protected, and do you know what to do when it is not?
We can notify the supervisory authority within 72 hours of becoming aware of a breach, and we have rehearsed it.
Why it matters and what good looks likeHide
- Why
- Article 33 sets the 72-hour deadline. Most organisations that miss it had no plan, not no intent.
- Good looks like
- A written breach procedure naming who decides, who notifies, and what the notification contains, with a contact at the authority and a template ready.
Personal data is encrypted in transit and at rest, and pseudonymised or minimised where the purpose allows.
Why it matters and what good looks likeHide
- Why
- Article 32 asks for measures appropriate to the risk. Encryption and pseudonymisation are named in the text.
- Good looks like
- TLS everywhere, encrypted storage and backups, and identifiers replaced with tokens in analytics and test environments.
Access to personal data is limited to the people whose role needs it, and access is reviewed.
Why it matters and what good looks likeHide
- Why
- Most breaches involve an account that should not have had access, or that should have been closed.
- Good looks like
- Role-based access, leavers removed on their last day, and a periodic review with a record of who has what.
Staff who handle personal data have been trained, and know how to recognise and report an incident.
Why it matters and what good looks likeHide
- Why
- A breach is usually first noticed by someone who is not in the security team.
- Good looks like
- Short role-specific training at onboarding and on a repeat cycle, with a single reporting channel everyone knows.
Accountability and governance
Who is responsible, and what do the contracts say?
Every processor that handles personal data for us is bound by a data processing agreement with the Article 28 terms.
Why it matters and what good looks likeHide
- Why
- Cloud hosting, analytics, email, CRM, payroll, support tools: each one is a processor and needs the contract.
- Good looks like
- A list of processors matched to the record of processing, each with a signed DPA, sub-processor lists reviewed, and transfer mechanisms in place for anything outside the EEA.
We know whether we need a Data Protection Officer, and if so one is appointed and registered.
Why it matters and what good looks likeHide
- Why
- Article 37: mandatory for public authorities, for large-scale regular monitoring, and for large-scale special-category processing.
- Good looks like
- The decision documented either way. If appointed, the DPO reports to top management, is independent, and their contact details are published.
If we are established outside the EU, we have appointed a representative in a member state.
Why it matters and what good looks likeHide
- Why
- Article 27 applies to any organisation outside the EU that offers goods or services to, or monitors, people in the EU.
- Good looks like
- A representative named in the privacy notice, reachable by authorities and data subjects.
We know when a data protection impact assessment is required, and we have carried one out where it is.
Why it matters and what good looks likeHide
- Why
- Article 35: required for high-risk processing, including systematic monitoring and large-scale special-category data.
- Good looks like
- A screening question in the project process, a DPIA template, and completed assessments for the processing that needed them.
Individual rights
Can a person exercise their rights, and can you answer within a month?
A person can ask for a copy of their data and receive it within one month, in a usable format.
Why it matters and what good looks likeHide
- Why
- Article 15. The one-month deadline runs from receipt, and the answer must cover every system, not just the CRM.
- Good looks like
- A single intake channel, an identity check proportionate to the risk, a search across every system in the record of processing, and a template response.
Requests to correct, delete or restrict data are handled through a defined process, including notifying recipients.
Why it matters and what good looks likeHide
- Why
- Articles 16 to 19. Deletion has to reach backups and processors, and recipients must be told.
- Good looks like
- One workflow for all rights requests, with the recipient list drawn from the record of processing.
A person can object to direct marketing and to processing based on legitimate interests, and the objection stops it.
Why it matters and what good looks likeHide
- Why
- Article 21. Objection to direct marketing is absolute; there is no balancing test.
- Good looks like
- Unsubscribe and objection routes that suppress across every channel and every tool, not just the one that sent the message.
Data can be exported in a structured, machine-readable format when a person asks to move it.
Why it matters and what good looks likeHide
- Why
- Article 20 covers data the person provided, processed by automated means under consent or contract.
- Good looks like
- An export in CSV or JSON produced from the systems of record, without manual assembly.
Where decisions with legal or similar effects are made automatically, a person can obtain human review and contest the outcome.
Why it matters and what good looks likeHide
- Why
- Article 22, and now the AI Act adds transparency duties for the same systems.
- Good looks like
- An inventory of automated decisions, a notice at the point of decision, and a route to a human reviewer.
Nothing on this page is legal advice. It reflects how we assess readiness before an engagement; apply it to your own circumstances with counsel where the stakes require it.
Self-assessed is a start. Verified is better.
The consent and tracking section is the one most organisations get wrong without knowing. The free audit records what your site actually does, from several regions, and comes with a 30-minute call.