Assess your GDPR compliance in 5 minutes. Answer 30 questions across 5 categories — legal basis, data security, subject rights, governance, and transparency — to get an A-F grade with a prioritized action plan.

What This Assessment Covers

Most GDPR compliance checklists only look at cookie banners. This tool goes further. It checks the six core obligations that supervisory authorities actually investigate when they receive a complaint or conduct an inspection: your legal basis for each processing activity, how you obtain and record consent, how you handle data subject access requests (DSARs), your third-party data-sharing arrangements, your data retention and deletion practices, and your privacy transparency obligations.

The 30 questions are mapped to specific GDPR articles so that every low score points directly to a legal obligation, not just a best practice. Your identity data — IP addresses, device fingerprints, login credentials, names in analytics events — falls under the same rules as any other personal data. The assessment is calibrated to catch the gaps that commonly arise when organisations collect identity signals through analytics, authentication flows, or third-party integrations.

The 5 GDPR Compliance Areas Assessed

1. Lawfulness of Processing

Article 6 GDPR requires a valid legal basis for every processing activity. The six available bases are consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. The assessment checks whether you have identified and documented a basis for each category of data you collect — including analytics data, marketing profiles, and authentication logs. It also checks whether your legitimate-interests processing is supported by a balancing test, as required by Recital 47. Organisations that collect analytics or A/B testing data without a documented basis under Article 6(1)(f) — or without consent where required — are routinely fined by EU data protection authorities.

2. Consent Collection and Records

Where consent is your legal basis, Article 7 requires that you can demonstrate it was freely given, specific, informed, and unambiguous. The assessment checks three things: whether you present a genuine choice (no pre-ticked boxes, no bundled consent), whether you maintain consent records that show who consented, to what, when, and through which interface, and whether your withdrawal mechanism is as easy as the opt-in. To check your consent requirements for your specific processing activities and jurisdiction, the Consent Requirements Wizard maps your use cases to the correct legal standard — GDPR Article 7, ePrivacy, or national law.

3. Data Subject Rights and DSARs

Articles 15 to 22 GDPR give individuals eight enforceable rights: access, rectification, erasure, restriction of processing, data portability, object to processing, and rights in relation to automated decision-making. The assessment checks whether you have a documented process for each right, whether you can meet the 30-day response deadline for access and erasure requests, and whether you have identified all the systems where personal data sits — including third-party analytics and CRM platforms. If you receive a subject access request, you can generate a DSAR response template that covers the mandatory disclosure fields under Article 15.

4. Third-Party Data Sharing

Every tool, plugin, or API that receives personal data from your site is either a processor (Article 28) or a controller in its own right. Article 28 requires a written Data Processing Agreement (DPA) with every processor. The assessment checks whether you have DPAs in place with your analytics provider, hosting company, email platform, and any other vendor that processes personal data on your behalf. It also checks whether you have conducted transfer impact assessments for any transfers to countries outside the EEA — required following the Schrems II ruling and clarified in the EDPB Recommendations 01/2020. If you are unsure of your fine exposure for a transfer violation, you can estimate your fine exposure based on your revenue and the severity of the breach.

5. Data Retention and Deletion

Article 5(1)(e) GDPR — the storage limitation principle — requires that personal data is not kept longer than necessary for the purpose for which it was collected. The assessment checks whether you have defined and documented retention periods for each data category, whether those periods are enforced by automated deletion or anonymisation, and whether your backup and archive processes are covered by the same retention rules. Analytics data is a common failure point: many organisations retain raw session data indefinitely when a rolling 14-month window — the period Google Analytics 4 defaults to — is typically sufficient for operational analysis and satisfies the storage limitation principle.

How to Use Your Score

The assessment returns an A-to-F grade and a category-by-category breakdown. Use it as follows.

Grade Score What to do next
A 90–100 % Document your practices and schedule a review in 12 months or when you make a material change to your processing.
B 75–89 % Address the specific gaps flagged in your results. Most are procedural rather than structural — update your records and policies.
C 60–74 % Several areas need attention. Prioritise the critical gaps (red flags) first; these carry the highest enforcement risk.
D 40–59 % Significant compliance risks are present. Consider engaging a data protection consultant alongside the action plan.
F Below 40 % Major gaps that could result in regulatory enforcement. Treat this as a project with an owner, a deadline, and a budget.

Review the assessment again whenever you add a new data collection point, integrate a new third-party service, or expand into a new EU member state. GDPR compliance is not a one-time exercise — it tracks the lifecycle of your processing activities.

Most Common Compliance Gaps

Across GDPR enforcement decisions published by European supervisory authorities since 2018, the same failures appear repeatedly. The following five are the most common gaps that organisations discover when they work through a structured GDPR readiness assessment for the first time.

  • Cookies set before consent. Loading analytics or advertising scripts before the user has accepted them violates Article 7 and the ePrivacy Directive. This is the single most-fined GDPR violation category in the EU.
  • No record of processing activities (ROPA). Article 30 requires organisations with more than 250 employees — and smaller organisations that process sensitive data or process on a non-occasional basis — to maintain a written record of all processing activities. Most small businesses that handle customer data regularly are caught by the non-occasional criterion.
  • Missing or inadequate Data Processing Agreements. Article 28 requires a signed DPA before any processor touches your data. Many organisations use tools and plugins without realising they are processors and without any DPA in place.
  • Inability to fulfill DSARs within 30 days. If personal data is scattered across multiple platforms — analytics, CRM, email marketing, support tickets — fulfilling an access or erasure request requires a process that maps all the locations. Without that map, the 30-day deadline is almost impossible to meet.
  • Outdated or incomplete privacy notices. Article 13 and 14 require you to disclose the legal basis, retention period, and recipient categories for each processing activity at the point of collection. Privacy policies that list tools generically without specifying what data they receive and under what basis regularly fail supervisory authority inspections.

The question of how online identity became a privacy problem is directly relevant here: identity systems that federate user data across services multiply the number of processors and transfer relationships that require documentation under GDPR.

Frequently Asked Questions

What does the assessment check?

The tool asks 30 questions across five GDPR compliance areas: lawfulness of processing (legal basis and consent), consent records and withdrawal, data subject rights procedures, third-party data-sharing arrangements (DPAs and international transfers), and data retention and deletion policies. Each question maps to a specific GDPR article. You receive an A-to-F grade, a category breakdown, and a prioritised list of critical gaps to address first.

How often should I review my GDPR compliance?

Review at least once a year and whenever you make a material change to how you collect or process data — for example, when you add a new analytics tool, integrate a new payment processor, or expand to a new market. The Article 5(2) accountability principle requires that you can demonstrate compliance at any point in time, which means compliance must be maintained as a living state rather than a certificate earned once.

What are the most common GDPR failures for websites?

The three most common failures for websites are: setting analytics cookies before the user gives consent (violates Art. 7 and ePrivacy), failing to have a Data Processing Agreement with every tool that receives personal data from the site (violates Art. 28), and being unable to fulfill a data subject access or erasure request within 30 days (violates Art. 12). Cookie and consent violations account for the majority of fines issued to small and medium-sized businesses.

Can I self-assess, or do I need a DPO?

A self-assessment is a legitimate and useful starting point. A Data Protection Officer (DPO) is mandatory under GDPR only for public authorities, organisations that conduct large-scale systematic monitoring of individuals, and organisations that process special categories of data at scale (Article 37). For most small and medium-sized businesses, a thorough self-assessment combined with documented remediation is sufficient — though complex situations (international transfers, sensitive data, high-volume processing) benefit from specialist legal advice.

What is the difference between this assessment and a DPIA?

This is a general GDPR compliance self-assessment covering your baseline obligations across all five compliance areas. A Data Protection Impact Assessment (DPIA) is a specific procedure required under Article 35 when a processing activity is likely to result in a high risk to individuals — for example, large-scale profiling, systematic monitoring of public spaces, or processing of sensitive data. A DPIA is narrower and deeper: it analyses one specific processing activity in detail and must be completed before that activity begins. This assessment helps you identify whether you might need a DPIA and whether your general compliance foundations are in place.

Does a small business need to comply with GDPR?

Yes. GDPR applies to any organisation — regardless of size or location — that processes personal data of individuals in the EU or EEA. There is a partial exemption from the ROPA requirement for organisations with fewer than 250 employees whose processing is non-occasional, but this exemption is narrow. If you have a website with a contact form, a cookie, or any analytics tool, you are processing personal data and GDPR applies. The accountability and security obligations apply in full regardless of company size.