Assess your GDPR compliance in 5 minutes. Answer 30 questions across 5 categories — legal basis, data security, subject rights, governance, and transparency — to get an A-F grade with a prioritized action plan.

Why Self-Assess Your GDPR Compliance?

GDPR compliance is not binary — it is a spectrum. Most organizations fall somewhere between fully compliant and completely non-compliant. A self-assessment helps you identify critical gaps that could lead to fines, quick wins that improve your compliance posture, and areas for improvement to prioritize in your privacy roadmap.

What This Assessment Covers

  • Legal Basis & Consent (25%) — lawful processing, cookie consent, consent records
  • Data Security (20%) — encryption, access controls, breach response
  • Data Subject Rights (20%) — access requests, deletion, portability
  • Governance (20%) — DPO, ROPA, DPIA, processor agreements, retention
  • Transparency (15%) — privacy policy, third-party disclosure, clear language

Understanding Your Grade

  • A (90-100%) — Excellent. You have comprehensive GDPR compliance practices in place.
  • B (75-89%) — Good. Minor gaps exist but you have strong fundamentals.
  • C (60-74%) — Fair. Several areas need attention, especially any critical gaps.
  • D (40-59%) — Poor. Significant compliance risks that need immediate action.
  • F (below 40%) — Failing. Major compliance gaps that could result in enforcement action.