GDPR · EU Data Protection Regulation Assessment

Benchmark Your GDPR Compliance Posture

25 targeted questions across 5 GDPR domains. Instant scoring, domain-level gap analysis, and actionable recommendations — free, no login required.

⏱ ~8 minutes 📋 5 domains · 25 questions 📊 Instant readiness report ✓ Free · No login required
Art. 6 Art. 13 Art. 17 Art. 25 Art. 30 Art. 33 Art. 35 Art. 44
Domain 1 of 5 0% complete
1
2
3
4
5
Lawful
Rights
Design
Breach
Transfers
⚖️
Art. 6–9
Lawful Basis & Consent
GDPR Articles 6–9 require a documented lawful basis for every processing activity involving personal data. Consent must be freely given, specific, informed, and unambiguous. Special category data requires explicit consent or another Art. 9 condition.
Q1 · Domain 1
Legal basis documented for every personal data processing activity in your inventory?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q2 · Domain 1
Consent mechanisms are specific, informed, freely given, and withdrawable at any time?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q3 · Domain 1
Records of Processing Activities (RoPA) maintained and updated per Article 30?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q4 · Domain 1
Special category data (Art. 9) identified with explicit consent or alternative legal basis?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q5 · Domain 1
Data processing agreements (DPAs) in place with all third-party data processors?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
👤
Art. 15–22
Data Subject Rights
GDPR Articles 15–22 grant individuals rights to access, rectify, erase, restrict, port, and object to processing of their personal data. Organisations must respond within one calendar month.
Q1 · Domain 2
Process to respond to subject access requests (SARs) within 30 days established?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q2 · Domain 2
Right to erasure ("right to be forgotten") operational with documented deletion procedures?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q3 · Domain 2
Data portability process provides data in machine-readable format upon request?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q4 · Domain 2
Privacy notices up to date, written in plain language, and easily accessible?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q5 · Domain 2
Objection and opt-out processes implemented, tested, and communicated to data subjects?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
🏗️
Art. 25
Data Protection by Design & Default
GDPR Article 25 requires organisations to implement data protection principles from the outset of system design and default to the most privacy-protective settings. This includes appointing a DPO where required under Article 37.
Q1 · Domain 3
Privacy by design principles embedded in all new product and system development processes?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q2 · Domain 3
Data minimisation enforced — only minimum necessary personal data collected and retained?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q3 · Domain 3
Pseudonymisation or anonymisation applied where technically and organisationally feasible?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q4 · Domain 3
Data Protection Impact Assessments (DPIAs) conducted for all high-risk processing activities?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q5 · Domain 3
Data Protection Officer (DPO) appointed where required and accessible to data subjects?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
🚨
Art. 33–34
Breach Detection & Reporting
GDPR Articles 33–34 require notification to the supervisory authority within 72 hours of becoming aware of a personal data breach. High-risk breaches must also be communicated to affected data subjects without undue delay.
Q1 · Domain 4
Personal data breach detection capability and real-time logging implemented?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q2 · Domain 4
72-hour supervisory authority notification procedure documented and tested?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q3 · Domain 4
High-risk breach communication procedure for affected data subjects established?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q4 · Domain 4
Breach register maintained with full details of all incidents and organisational responses?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q5 · Domain 4
Annual incident response exercises specifically covering data breach scenarios conducted?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
🌍
Art. 44–49
International Data Transfers
GDPR Articles 44–49 restrict transfers of personal data to countries outside the EEA unless appropriate safeguards are in place — including Standard Contractual Clauses (SCCs), adequacy decisions, or Binding Corporate Rules (BCRs).
Q1 · Domain 5
All cross-border personal data transfers to third countries identified and documented?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q2 · Domain 5
Appropriate transfer mechanisms (SCCs, adequacy decisions, BCRs) in place for all transfers?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q3 · Domain 5
Vendors in third countries assessed for data protection equivalence to EU standards?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q4 · Domain 5
Transfer Impact Assessments (TIAs) conducted for transfers to non-adequate countries?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Q5 · Domain 5
Contractual transfer obligations reviewed and updated following Schrems II and regulatory guidance?
Not Implemented
0 pts
Planned ≤12m
1 pt
Partial
2 pts
Fully Implemented
3 pts
Please answer all questions to continue.
🔗
You're viewing a shared assessment report
Take your own assessment to get personalised results.
0%
0 / 75 pts
GDPR READINESS SCORE
🔴 Critical Risk

Critical GDPR non-compliance. Supervisory authorities regularly impose fines up to €20M or 4% of global annual turnover for these gaps. Immediate remediation required.

Domain Breakdown
Priority Recommendations
GDPR Toolkit → Start Free Tabletop Exercises →

More Free Assessments

🛡️ NIS2 Readiness 🏦 DORA Readiness 🏢 ISO 27001 Gap 🔐 CMMC 2.0 Readiness

This assessment is self-reported and indicative only. It does not constitute formal legal or compliance advice. Consult your supervisory authority or qualified data protection counsel for definitive GDPR obligations.