GDPR Readiness Assessment 📋

Most compliance checklists ask whether you comply with an Article. This one works the other way round. You record which privacy management activities you actually perform, and the tool derives which GDPR Articles those activities evidence. Activities are finite and observable; legal requirements are not. That inversion is what makes the assessment repeatable.

How to fill this in

  1. Set the scope. Thirteen yes or no questions about your organisation. Each one says how many activities depend on it: answering "no" takes those out of the assessment altogether, so you are not marked down for something that cannot apply to you. Leave one blank and its activities stay in.
  2. Work through the activities. Seventy-one of them, grouped into thirteen categories. Click a category to open it. Each activity carries two questions and one status.
  3. Answer honestly rather than aspirationally. The status you pick is a judgement about what happens today, not what is planned or what the policy says should happen. The score is only worth having if it is uncomfortable in the right places.
  4. Read the results three ways. By category shows where to put effort. By Article shows what you could evidence to a regulator. The gap list is an ordered to-do, worst first, with the higher-leverage activities ranked above the rest.

The two questions. The Privacy Office question asks whether the mechanism exists and is built properly. The Operational Unit question is the one to put to a business area such as HR, Marketing or Sales, and asks whether it reflects what actually happens there. They can disagree, and where they do that is the finding: a register that exists but is out of date is the most common way accountability fails. A few activities show only the Privacy Office question, because nobody in a business unit appoints a DPO or notifies a regulator.

Your answers stay in this browser. Nothing is sent anywhere. Save keeps a copy locally, Clear empties the screen but keeps that copy, and Forget saved copy deletes it.

Step 1: Scope

Answer these first. The count on the right of each row is how many activities depend on that answer. Answering "no" removes them from scoring entirely rather than counting them against you.

Step 2: Assessment

For each activity, record its status. The Privacy Office question captures the programme view; the Operational Unit question is the one to put to a business area such as HR, Marketing or Sales.

When the two answers disagree

The status describes the activity, not either answer on its own. Use this so the judgement stays the same across all seventy-one.

Privacy Office Operational Unit Record it as What it tells you
Yes Yes Implemented It works.
Yes No In progress Paper compliance. The mechanism exists but has not reached the business, so it is designed rather than operating. The fix is communication and embedding, not building something new.
No Yes In progress A local practice the programme has never formalised. Rarer, and worth surfacing rather than ignoring.
No No Not in place Nothing you could evidence.
Does not arise Not applicable Genuinely outside what your organisation does. Excluded from the score rather than counted against you.

One "yes, no" row is a finding. Six or seven of them is not six or seven gaps, it is one: the programme is not reaching the business. If you ask more than one area and they disagree with each other, take the worst answer and note which area it came from.

Step 3: Readiness

What this score means. It measures demonstrable accountability, not blanket compliance. Only Articles that a management activity can evidence are scored, so scope, definitions and Member State provisions sit outside it. A high score means you could show a supervisory authority what you do; it is not a legal opinion.