Executive self-assessment

GDPR Security & Privacy Readiness Assessment

Evaluate whether privacy obligations are translated into owned operational controls and evidence across security, engineering, vendors, and business teams.

Result logic

What this tool evaluates

Evaluates data governance, security, processors, high-risk processing, rights operations, incidents, retention, and transfers.

Data mapping 20%
Security measures 22%
Processors & transfers 20%
Privacy operations 20%
Breach readiness 18%
0 / 10
0%
01 Is the record of processing activities current and connected to actual systems, vendors, and owners?
02 Can the organization trace sensitive data from collection through storage, sharing, transfer, and deletion?
03 Are security measures selected based on personal-data and processing risk?
04 Are access, encryption, logging, vulnerability, backup, and resilience controls evidenced?
05 Are processors and subprocessors risk-reviewed and contractually governed?
06 Are international transfer mechanisms and actual transfer paths documented and reviewed?
07 Is there a repeatable DPIA/high-risk processing review for material changes?
08 Can data-subject requests, retention, correction, export, and deletion be executed reliably in systems?
09 Can the organization rapidly determine whether a security incident involves personal data and who must decide next steps?
10 Are breach decisions, timelines, evidence, and lessons learned documented?