GDPR Readiness Check
Ten operating questions drawn from the regulation itself — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.
GDPR applies to any organization processing personal data of people in the EU — established in the EU or not — when it offers them goods or services or monitors their behavior. It binds controllers and processors alike.
1.Records: do you keep a record of processing activities that covers every purpose, its lawful basis and its recipients — and is it current?
Art. 30 — records of processing activities
2.Lawful basis: is a documented basis identified for every processing purpose, with special-category data flagged?
Arts. 6, 9 — lawful basis and special categories
3.Transparency: do people get the required privacy information at the moment of collection — purposes, retention, recipients, their rights?
Arts. 12–14 — transparency and information
4.Rights: can you fulfil access, rectification, erasure and portability requests within one month, with an identity-check step?
Arts. 12(3), 15–22 — data-subject rights
5.Security: are technical and organisational measures — encryption, access control, pseudonymization where it helps — appropriate to the risk?
Art. 32 — security of processing
6.Processors: does every processor that touches personal data operate under a data-processing agreement?
Art. 28 — processor engagements
7.Breaches: can you detect, assess and notify the supervisory authority within 72 hours — and the people affected when the risk is high?
Arts. 33–34 — breach notification
8.DPIAs: is high-risk processing identified before it starts, and does it get a data-protection impact assessment?
Art. 35 — data protection impact assessment
9.By design: is data protection built into new products, systems and processes from the start — with defaults set to the minimum data?
Art. 25 — data protection by design and by default
10.Accountability: is a DPO appointed where required, and are privacy policies and measures reviewed as a matter of routine?
Arts. 24, 37 — accountability and the DPO
GDPR readiness
Answer to scoreWhat the score means
80–100% · Low risk
Controls exist and can mostly be shown. Next step: continuous evidence — the processing record and breach log should read from live state, not spreadsheets.
40–79% · Medium / High
The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.
0–39% · Critical
Start with the processing record and the 72-hour breach clock — the GDPR framework page maps both to operating controls.
The GDPR frameworkEvery score
Bring it to a demo — walked through against your actual obligations, not generic advice.
Book a demoTruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.