GDPR Checklist

General Data Protection Regulation compliance, in plain English, in one afternoon.

A free 30-question self-assessment, built for small businesses with European customers, visitors, or staff. With it comes a three-tier toolkit: templates, deepened guides, and Excel workbooks. The assessment runs in your browser. Your answers never leave your device.

Pick a tier

Three tiers, one-time purchase, files you own forever.

Existing $99 buyers have been grandfathered to the new SMB tier and continue to receive every new asset as it ships. Tier 3 buyers also receive the quarterly law-update bulletin by email.

Solo
$49one-time
Freelancers, single-operator businesses, indie consultants
  • 30-question self-assessment
  • 72-hour breach decision tree
  • Single-operator Records of Processing Activities workbook
  • Privacy notice cheat-sheet and consent copy library
  • Three-letter Data Subject Access Request pack
Buy Solo — $49
Pro & Data Protection Officer
$299one-time + bulletin
Outsourced DPOs, in-house counsel, privacy consultants
  • Everything in SMB
  • Data Protection Impact Assessment template
  • Industry case gallery
  • Lead Supervisory Authority directory
  • Quarterly law-update bulletin by email
  • Optional agency add-on ($199) for white-label / co-brand rights
Buy Pro — $299
How it works

Two paths into the toolkit.

1. Take the free assessment

30 questions across data collection, processing, storage, sharing, and breach response. About ten minutes. Returns a score across all five areas, names your weakest area, and lists priority actions. Runs entirely in your browser — no email required, no data transmitted.

Take the free assessment →

2. Browse the SMB Edition contents

See the full list of guides, workbooks, and templates before you buy. The lead magnet ("The 5 Most Common GDPR Mistakes") gives you a sense of the tone and depth in three minutes.

Read the free 5-mistakes guide →

Privacy-first by design — and that matters more for a GDPR product.

The free GDPR self-assessment never transmits your answers. They are scored in your browser, displayed only to you, and stored only on your own device. We collect your email address only if you choose to enter it for the 5 GDPR Mistakes guide. Nothing else.

Our website uses Cloudflare's server-side traffic analytics for aggregate page counts — no JavaScript injection, no cookies, no identifiable data.

Related toolkits

If you handle EU customer data and need a security baseline, the SMB Security Assessment covers the controls cyber insurers ask about and overlaps usefully with Article 32 of GDPR.