Skip to main content
TOOLS

GDPR Readiness Check

Ten operating questions drawn from the regulation itself — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.

GDPR applies to any organization processing personal data of people in the EU — established in the EU or not — when it offers them goods or services or monitors their behavior. It binds controllers and processors alike.

0/10
  1. 1.Records: do you keep a record of processing activities that covers every purpose, its lawful basis and its recipients — and is it current?

    Art. 30 — records of processing activities

  2. 2.Lawful basis: is a documented basis identified for every processing purpose, with special-category data flagged?

    Arts. 6, 9 — lawful basis and special categories

  3. 3.Transparency: do people get the required privacy information at the moment of collection — purposes, retention, recipients, their rights?

    Arts. 12–14 — transparency and information

  4. 4.Rights: can you fulfil access, rectification, erasure and portability requests within one month, with an identity-check step?

    Arts. 12(3), 15–22 — data-subject rights

  5. 5.Security: are technical and organisational measures — encryption, access control, pseudonymization where it helps — appropriate to the risk?

    Art. 32 — security of processing

  6. 6.Processors: does every processor that touches personal data operate under a data-processing agreement?

    Art. 28 — processor engagements

  7. 7.Breaches: can you detect, assess and notify the supervisory authority within 72 hours — and the people affected when the risk is high?

    Arts. 33–34 — breach notification

  8. 8.DPIAs: is high-risk processing identified before it starts, and does it get a data-protection impact assessment?

    Art. 35 — data protection impact assessment

  9. 9.By design: is data protection built into new products, systems and processes from the start — with defaults set to the minimum data?

    Art. 25 — data protection by design and by default

  10. 10.Accountability: is a DPO appointed where required, and are privacy policies and measures reviewed as a matter of routine?

    Arts. 24, 37 — accountability and the DPO

0%

GDPR readiness

Answer to score

What the score means

80–100% · Low risk

Controls exist and can mostly be shown. Next step: continuous evidence — the processing record and breach log should read from live state, not spreadsheets.

40–79% · Medium / High

The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.

0–39% · Critical

Start with the processing record and the 72-hour breach clock — the GDPR framework page maps both to operating controls.

The GDPR framework

Every score

Bring it to a demo — walked through against your actual obligations, not generic advice.

Book a demo

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

Frequently Asked Questions

Who has to comply with GDPR?
Any organization processing personal data of people in the EU — established in the EU or not — when it offers them goods or services or monitors their behavior. It binds controllers and processors alike.
What is the GDPR breach-notification deadline?
Seventy-two hours to the supervisory authority from the moment you become aware of a personal-data breach, unless it is unlikely to result in risk. When the risk to people is high, the people affected are notified too.
Do small companies need a record of processing activities?
The Article 30 record has a limited exemption for organizations under 250 employees — but it does not apply where processing is not occasional, touches special categories, or is likely to risk rights and freedoms. Most organizations discover the exemption is narrower than they hoped.
Is the score an official GDPR assessment?
No. It is an indicative maturity score from ten questions drawn from the regulation — not an assessment of record. Supervisors judge compliance against the full regulation; the check tells you where the gaps are.