GDPR readiness assessment

How ready is your organisation, honestly?

23 questions across 5 areas, each with why it matters and what good looks like. Grounded in the regulation text and in what the supervisory authorities have actually fined. Answer yes, partly or no; the readiness score updates as you go and tells you where to start. Your answers stay in your browser.

Questions
23
Time
about 20 minutes
To use it
nothing
Pen and paper
printable
Written report
your email
01

Lawful basis and transparency

Do you know what you process, why, and can you show it?

  1. We have a written record of what personal data we process, where it comes from, who it goes to and how long we keep it.

    Why it matters and what good looks like
    Why
    Article 30 requires most controllers to keep this record, and every other item on this list depends on it.
    Good looks like
    A maintained record of processing activities, one row per purpose, that names the data categories, recipients, retention period and legal basis. Reviewed when systems change, not once a year.
  2. Every processing purpose has a named legal basis, decided before the processing started.

    Why it matters and what good looks like
    Why
    Consent, contract, legal obligation, vital interests, public task or legitimate interests. Processing without one is unlawful regardless of how careful the rest is.
    Good looks like
    The basis is recorded per purpose. Where it is legitimate interests, a balancing test exists. Where it is consent, the consent meets the Article 7 standard: specific, informed, freely given, withdrawable.
  3. Our privacy notice states each purpose, its legal basis, the recipients and the retention period, in language a visitor can follow.

    Why it matters and what good looks like
    Why
    Articles 13 and 14 set the content. A notice that lists categories without purposes, or purposes without a basis, does not meet it.
    Good looks like
    A notice that a reader can map to the record of processing, updated when the record changes, with a version date.
  4. We tell people about processing at the moment we collect the data, not only in a policy page.

    Why it matters and what good looks like
    Why
    Transparency is judged at the point of collection: the form, the banner, the sign-up screen.
    Good looks like
    A short layered notice at each collection point that links to the full policy.
03

Security and breach readiness

Is the data protected, and do you know what to do when it is not?

  1. We can notify the supervisory authority within 72 hours of becoming aware of a breach, and we have rehearsed it.

    Why it matters and what good looks like
    Why
    Article 33 sets the 72-hour deadline. Most organisations that miss it had no plan, not no intent.
    Good looks like
    A written breach procedure naming who decides, who notifies, and what the notification contains, with a contact at the authority and a template ready.
  2. Personal data is encrypted in transit and at rest, and pseudonymised or minimised where the purpose allows.

    Why it matters and what good looks like
    Why
    Article 32 asks for measures appropriate to the risk. Encryption and pseudonymisation are named in the text.
    Good looks like
    TLS everywhere, encrypted storage and backups, and identifiers replaced with tokens in analytics and test environments.
  3. Access to personal data is limited to the people whose role needs it, and access is reviewed.

    Why it matters and what good looks like
    Why
    Most breaches involve an account that should not have had access, or that should have been closed.
    Good looks like
    Role-based access, leavers removed on their last day, and a periodic review with a record of who has what.
  4. Staff who handle personal data have been trained, and know how to recognise and report an incident.

    Why it matters and what good looks like
    Why
    A breach is usually first noticed by someone who is not in the security team.
    Good looks like
    Short role-specific training at onboarding and on a repeat cycle, with a single reporting channel everyone knows.
04

Accountability and governance

Who is responsible, and what do the contracts say?

  1. Every processor that handles personal data for us is bound by a data processing agreement with the Article 28 terms.

    Why it matters and what good looks like
    Why
    Cloud hosting, analytics, email, CRM, payroll, support tools: each one is a processor and needs the contract.
    Good looks like
    A list of processors matched to the record of processing, each with a signed DPA, sub-processor lists reviewed, and transfer mechanisms in place for anything outside the EEA.
  2. We know whether we need a Data Protection Officer, and if so one is appointed and registered.

    Why it matters and what good looks like
    Why
    Article 37: mandatory for public authorities, for large-scale regular monitoring, and for large-scale special-category processing.
    Good looks like
    The decision documented either way. If appointed, the DPO reports to top management, is independent, and their contact details are published.
  3. If we are established outside the EU, we have appointed a representative in a member state.

    Why it matters and what good looks like
    Why
    Article 27 applies to any organisation outside the EU that offers goods or services to, or monitors, people in the EU.
    Good looks like
    A representative named in the privacy notice, reachable by authorities and data subjects.
  4. We know when a data protection impact assessment is required, and we have carried one out where it is.

    Why it matters and what good looks like
    Why
    Article 35: required for high-risk processing, including systematic monitoring and large-scale special-category data.
    Good looks like
    A screening question in the project process, a DPIA template, and completed assessments for the processing that needed them.
05

Individual rights

Can a person exercise their rights, and can you answer within a month?

  1. A person can ask for a copy of their data and receive it within one month, in a usable format.

    Why it matters and what good looks like
    Why
    Article 15. The one-month deadline runs from receipt, and the answer must cover every system, not just the CRM.
    Good looks like
    A single intake channel, an identity check proportionate to the risk, a search across every system in the record of processing, and a template response.
  2. Requests to correct, delete or restrict data are handled through a defined process, including notifying recipients.

    Why it matters and what good looks like
    Why
    Articles 16 to 19. Deletion has to reach backups and processors, and recipients must be told.
    Good looks like
    One workflow for all rights requests, with the recipient list drawn from the record of processing.
  3. A person can object to direct marketing and to processing based on legitimate interests, and the objection stops it.

    Why it matters and what good looks like
    Why
    Article 21. Objection to direct marketing is absolute; there is no balancing test.
    Good looks like
    Unsubscribe and objection routes that suppress across every channel and every tool, not just the one that sent the message.
  4. Data can be exported in a structured, machine-readable format when a person asks to move it.

    Why it matters and what good looks like
    Why
    Article 20 covers data the person provided, processed by automated means under consent or contract.
    Good looks like
    An export in CSV or JSON produced from the systems of record, without manual assembly.
  5. Where decisions with legal or similar effects are made automatically, a person can obtain human review and contest the outcome.

    Why it matters and what good looks like
    Why
    Article 22, and now the AI Act adds transparency duties for the same systems.
    Good looks like
    An inventory of automated decisions, a notice at the point of decision, and a route to a human reviewer.

Nothing on this page is legal advice. It reflects how we assess readiness before an engagement; apply it to your own circumstances with counsel where the stakes require it.

Self-assessed is a start. Verified is better.

The consent and tracking section is the one most organisations get wrong without knowing. The free audit records what your site actually does, from several regions, and comes with a 30-minute call.