Intro
1Collection
2Processing
3Storage
4Sharing
5Breaches
Results

Where does your company stand on GDPR?

The General Data Protection Regulation (GDPR) is the EU law for how organisations handle people's personal data. This assessment walks 30 questions across five areas — see your score in under 10 minutes.

No email required. Nothing is transmitted. Responses stay in your browser.

Section 1

Data Collection

Consent, lawful bases, privacy notices, user rights.

Section 2

Data Processing

Vendor agreements, retention, breach notification readiness.

Section 3

Data Storage

Encryption, access controls, audit logs, secure deletion.

Section 4

Data Sharing

Third-party agreements, international transfers, user rights.

Section 5

Breach Response

Detection, investigation, notification, post-incident review.

New to GDPR? Start here

What is GDPR? GDPR stands for the General Data Protection Regulation — the European Union law that sets the rules for how organisations collect, use, and protect the personal data of people in Europe.

Does it apply to my business? It applies to any organisation that handles the personal data of people in the EU or EEA — customers, website visitors, or employees — even if your business is based outside Europe.

Why it matters. Regulators can investigate complaints, require changes to how you handle personal data, and issue fines that are tiered and proportionate to the problem. The headline maximum is up to €20 million or 4% of annual global turnover, whichever is higher — but maximum fines are rare and reserved for the most serious infringements. For most small businesses, the practical goal is simply knowing where you genuinely stand and handling customer data with confidence.

All responses are stored locally in your browser. Nothing is transmitted or tracked.

Your overall compliance score
Calculating…

Score by section

Areas commonly addressed first

Free one-page guide

The 5 most common GDPR mistakes — and how to avoid them

A plain-English, one-page guide for small business owners. Enter your email and we'll send it over.

Optional, and separate from your assessment — your assessment answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.

Full Edition — from $49, one-time

Ready for in-depth guidance?

The Full Edition adds the depth that turns a score into a remediation plan you can actually act on. Three editions: Solo ($49), Team ($129), and Pro & Data Protection Officer ($299) — one-time, files you own forever.

  • Regulatory rationale on each high-impact question — Article references, supervisory-authority guidance, common enforcement context
  • Per-section toolkit methodology preview with a five-phase remediation approach for each area
  • Personalised "Why this matters / Common fixes" results cards, sequenced as a 30 / 60 / 90 day focus plan
  • Five downloadable PDF guides covering data subject access, records of processing, right-to-erasure, international transfers, and breach response
  • Master bundle: all five guides in one download
  • 30-day money-back guarantee — full refund on request, no questions asked
From $49 one-time See the three editions →

Your full answers

Important — please read

This report and the assessment that produced it provide alignment recommendations and common approaches for handling personal data under the General Data Protection Regulation. It is general guidance for educational and informational purposes only. It is not legal advice and does not create an attorney-client or advisory relationship.

The results, scores, hints, and "areas commonly addressed first" describe approaches commonly used by other organisations. They are illustrative and non-exhaustive — not a complete, sufficient, or correct remediation plan for your organisation. Completing any suggested action does not mean your organisation is compliant.

Actual compliance with the GDPR and any other applicable privacy law remains your responsibility. Verify any guidance against your specific facts, and consult a qualified data protection professional before relying on it. Following this guidance does not guarantee compliance or freedom from enforcement.