Browser-local readiness check
How robust is your data protection management?
20 questions cover governance, processing activities, data protection risks, data subject rights, service providers and incidents. Your answers stay local.
- 01
Governance
Are data protection roles, responsibilities and escalation paths bindingly defined?
Expected evidence: Role and responsibility matrix
- 02
Governance
Does management regularly assess the key data protection risks and measures?
Expected evidence: Management report or review minutes
- 03
Governance
Do new projects, systems and changes trigger a data protection review early on?
Expected evidence: Privacy gate in the change or project process
- 04
Governance
Are policies, procedures and evidence versioned and up to date?
Expected evidence: Document and control overview
- 05
Inventory & lawfulness
Does a complete record of processing activities exist, with named owners and a review date?
Expected evidence: Current RoPA
- 06
Inventory & lawfulness
Are purposes concrete and legal bases documented with their preconditions?
Expected evidence: RoPA and legal basis review
- 07
Inventory & lawfulness
Are information obligations implemented per processing activity and channel?
Expected evidence: Approved privacy notices
- 08
Inventory & lawfulness
Are data flows, recipients and international transfers traceable?
Expected evidence: Data flow and transfer overview
- 09
Risk & design
Is there a documented data protection risk method with criteria for rights and freedoms?
Expected evidence: Risk methodology
- 10
Risk & design
Are DPIA threshold assessments carried out early and consistently?
Expected evidence: Threshold assessments and decisions
- 11
Risk & design
Are required DPIAs complete, approved and documented with residual risk?
Expected evidence: DPIA reports
- 12
Risk & design
Are technical and organisational measures derived from the concrete risk and tested for effectiveness?
Expected evidence: Assessment and tests of technical and organisational measures
- 13
Operations & rights
Can data subject requests be handled on time across all relevant systems?
Expected evidence: Procedure and case records
- 14
Operations & rights
Are deletion rules defined with end of purpose, start of the deadline, system and evidence?
Expected evidence: Deletion concept or deadline matrix
- 15
Operations & rights
Are permissions for personal data reviewed regularly?
Expected evidence: Recertification evidence
- 16
Operations & rights
Is data protection training delivered on a role and risk basis?
Expected evidence: Training plan and attendance
- 17
Service providers & incidents
Are external roles correctly classified and documented before engagement?
Expected evidence: Controller/processor role assessment
- 18
Service providers & incidents
Are processors selected and monitored based on the concrete service and its risks?
Expected evidence: Due diligence, contract and review evidence
- 19
Service providers & incidents
Is there a tested process for assessing personal data breaches?
Expected evidence: Incident procedure and exercise evidence
- 20
Service providers & incidents
Are non-notified personal data breaches also documented, including the justification?
Expected evidence: Complete incident register