Skip to content

Browser-local readiness check

How robust is your data protection management?

20 questions cover governance, processing activities, data protection risks, data subject rights, service providers and incidents. Your answers stay local.

Back to Data protection

  1. 01

    Governance

    Are data protection roles, responsibilities and escalation paths bindingly defined?

    Expected evidence: Role and responsibility matrix

  2. 02

    Governance

    Does management regularly assess the key data protection risks and measures?

    Expected evidence: Management report or review minutes

  3. 03

    Governance

    Do new projects, systems and changes trigger a data protection review early on?

    Expected evidence: Privacy gate in the change or project process

  4. 04

    Governance

    Are policies, procedures and evidence versioned and up to date?

    Expected evidence: Document and control overview

  5. 05

    Inventory & lawfulness

    Does a complete record of processing activities exist, with named owners and a review date?

    Expected evidence: Current RoPA

  6. 06

    Inventory & lawfulness

    Are purposes concrete and legal bases documented with their preconditions?

    Expected evidence: RoPA and legal basis review

  7. 07

    Inventory & lawfulness

    Are information obligations implemented per processing activity and channel?

    Expected evidence: Approved privacy notices

  8. 08

    Inventory & lawfulness

    Are data flows, recipients and international transfers traceable?

    Expected evidence: Data flow and transfer overview

  9. 09

    Risk & design

    Is there a documented data protection risk method with criteria for rights and freedoms?

    Expected evidence: Risk methodology

  10. 10

    Risk & design

    Are DPIA threshold assessments carried out early and consistently?

    Expected evidence: Threshold assessments and decisions

  11. 11

    Risk & design

    Are required DPIAs complete, approved and documented with residual risk?

    Expected evidence: DPIA reports

  12. 12

    Risk & design

    Are technical and organisational measures derived from the concrete risk and tested for effectiveness?

    Expected evidence: Assessment and tests of technical and organisational measures

  13. 13

    Operations & rights

    Can data subject requests be handled on time across all relevant systems?

    Expected evidence: Procedure and case records

  14. 14

    Operations & rights

    Are deletion rules defined with end of purpose, start of the deadline, system and evidence?

    Expected evidence: Deletion concept or deadline matrix

  15. 15

    Operations & rights

    Are permissions for personal data reviewed regularly?

    Expected evidence: Recertification evidence

  16. 16

    Operations & rights

    Is data protection training delivered on a role and risk basis?

    Expected evidence: Training plan and attendance

  17. 17

    Service providers & incidents

    Are external roles correctly classified and documented before engagement?

    Expected evidence: Controller/processor role assessment

  18. 18

    Service providers & incidents

    Are processors selected and monitored based on the concrete service and its risks?

    Expected evidence: Due diligence, contract and review evidence

  19. 19

    Service providers & incidents

    Is there a tested process for assessing personal data breaches?

    Expected evidence: Incident procedure and exercise evidence

  20. 20

    Service providers & incidents

    Are non-notified personal data breaches also documented, including the justification?

    Expected evidence: Complete incident register