Self-assessment · Data protection
GDPR Self-Assessment
In 16 simple questions, assess your organisation’s GDPR compliance, from the record of processing activities to individual rights. Instant score; detailed per-criterion analysis on request.
No expertise required: answer honestly, based on your organisation’s real situation. It takes about 5 minutes.
- 1
Do you keep an up-to-date record of your personal-data processing activities (customers, employees, prospects)?
- 2
For each processing activity, have you identified a legal basis (contract, consent, legitimate interest, legal obligation)?
- 3
Have you defined retention periods, and do you actually delete or archive data when they expire?
- 4
Do you check that you only collect the data genuinely needed for each purpose (minimisation)?
- 5
Do you clearly inform people about how their data is used (privacy policy, notices on forms)?
- 6
Do you collect valid consent where required (cookies, marketing…), with an easy way to withdraw it?
- 7
Do you have a process to answer access, rectification or erasure requests within one month?
- 8
Can people easily object to marketing, and do you honour that choice?
- 9
Is access to personal data limited to the people who need it, with individual accounts?
- 10
Do you protect data with appropriate measures (encryption, strong passwords, MFA, backups)?
- 11
Do you train your teams on data protection and confidentiality?
- 12
Do you carry out an impact assessment (DPIA) before high-risk processing (sensitive data, large-scale monitoring)?
- 13
Are your processors (hosting, SaaS tools, payroll…) bound by GDPR-compliant contracts?
- 14
Could you detect a data breach and notify the supervisory authority within 72h if required?
- 15
If you transfer data outside the EU, have you checked the safeguards (standard clauses, adequacy decision)?
- 16
Have you appointed someone to steer compliance (DPO or lead) and do you document your choices so you can account for them?
0 / 16