Where does your company stand on GDPR?
The General Data Protection Regulation (GDPR) is the EU law for how organisations handle people's personal data. This assessment walks 30 questions across five areas — see your score in under 10 minutes.
No email required. Nothing is transmitted. Responses stay in your browser.
Data Collection
Consent, lawful bases, privacy notices, user rights.
Data Processing
Vendor agreements, retention, breach notification readiness.
Data Storage
Encryption, access controls, audit logs, secure deletion.
Data Sharing
Third-party agreements, international transfers, user rights.
Breach Response
Detection, investigation, notification, post-incident review.
New to GDPR? Start here
What is GDPR? GDPR stands for the General Data Protection Regulation — the European Union law that sets the rules for how organisations collect, use, and protect the personal data of people in Europe.
Does it apply to my business? It applies to any organisation that handles the personal data of people in the EU or EEA — customers, website visitors, or employees — even if your business is based outside Europe.
Why it matters. Regulators can investigate complaints, require changes to how you handle personal data, and issue fines that are tiered and proportionate to the problem. The headline maximum is up to €20 million or 4% of annual global turnover, whichever is higher — but maximum fines are rare and reserved for the most serious infringements. For most small businesses, the practical goal is simply knowing where you genuinely stand and handling customer data with confidence.
All responses are stored locally in your browser. Nothing is transmitted or tracked.
Score by section
Areas commonly addressed first
The 5 most common GDPR mistakes — and how to avoid them
A plain-English, one-page guide for small business owners. Enter your email and we'll send it over.
Optional, and separate from your assessment — your assessment answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
Ready for in-depth guidance?
The Full Edition adds the depth that turns a score into a remediation plan you can actually act on. Three editions: Solo ($49), Team ($129), and Pro & Data Protection Officer ($299) — one-time, files you own forever.
- Regulatory rationale on each high-impact question — Article references, supervisory-authority guidance, common enforcement context
- Per-section toolkit methodology preview with a five-phase remediation approach for each area
- Personalised "Why this matters / Common fixes" results cards, sequenced as a 30 / 60 / 90 day focus plan
- Five downloadable PDF guides covering data subject access, records of processing, right-to-erasure, international transfers, and breach response
- Master bundle: all five guides in one download
- 30-day money-back guarantee — full refund on request, no questions asked
Your full answers
This report and the assessment that produced it provide alignment recommendations and common approaches for handling personal data under the General Data Protection Regulation. It is general guidance for educational and informational purposes only. It is not legal advice and does not create an attorney-client or advisory relationship.
The results, scores, hints, and "areas commonly addressed first" describe approaches commonly used by other organisations. They are illustrative and non-exhaustive — not a complete, sufficient, or correct remediation plan for your organisation. Completing any suggested action does not mean your organisation is compliant.
Actual compliance with the GDPR and any other applicable privacy law remains your responsibility. Verify any guidance against your specific facts, and consult a qualified data protection professional before relying on it. Following this guidance does not guarantee compliance or freedom from enforcement.