1. Assess
Select the operational status for each control and record the owner and available evidence.
Assess your organisation’s data practices, evidence, ownership, and remediation priorities across key Digital Personal Data Protection themes.
Complete the assessment, review the weighted result, and turn the highest-risk gaps into an owned remediation plan.
Select the operational status for each control and record the owner and available evidence.
Receive a deterministic 0–100 score, confidence notice, weighted gaps, and urgency bands.
Export or print the action plan and validate legal interpretations before implementation.
Use “Not applicable” only with a documented rationale. Use “Needs legal review” when the correct treatment depends on legal interpretation.
The checker converts self-reported control maturity into a weighted operational-readiness view. It is designed to support planning, not to replace legal analysis or assurance.
Use these assessments to strengthen connected governance, security, and data-management capabilities.
Evaluate decision rights, stewardship, policies, quality, metadata, adoption, and measurement.
Assess accountability, risk, lifecycle controls, oversight, transparency, monitoring, and incidents.
Check whether data ownership, metadata, governance, operating processes, and adoption are ready.
Practical guidance for interpreting and using the readiness check.
No. The score reflects self-reported operational readiness under this tool’s methodology. Compliance depends on legal applicability, facts, current notifications, prescribed requirements, sector rules, contracts, and actual control effectiveness.
A cross-functional group is preferable: privacy or legal, security, product, engineering, data governance, HR, marketing, procurement, customer operations, records management, and internal audit.
Examples include approved policies, data maps, notices, consent logs, rights tickets, contracts, deletion reports, security configurations, incident exercises, training records, audit results, metrics, and management-review minutes.
Use it when the correct status depends on legal interpretation—for example applicability, legitimate uses, children’s processing, exemptions, cross-border restrictions, sector overlays, or possible Significant Data Fiduciary obligations.
Use it only when a documented, approved rationale demonstrates that the control area genuinely does not apply. Review that rationale when processing purposes, data subjects, technology, vendors, or law change.
Security safeguards and breach preparedness materially affect harm, operational resilience, notification readiness, and regulatory exposure. Weaknesses in these areas can create immediate enterprise risk.
Yes. The control themes can be scaled to organisational size, processing volume, sensitivity, and risk. Smaller organisations should still establish clear ownership, proportionate controls, and usable evidence.
Reassess at least periodically and after material changes such as new products, new purposes, acquisitions, major vendors, new geographies, security incidents, or regulatory updates.
The page uses no external APIs. Submission is processed by the hosting server, and export files are created in the browser. Existing hosting, analytics, logging, or site infrastructure may still process technical data independently.
Start with Critical and High gaps, especially security, breach response, data mapping, notices, rights, processor controls, consent, and unresolved legal questions. Then address medium gaps and strengthen assurance.
It is readiness for enhanced obligations that may apply if an organisation is designated under the legal framework. The assessment flags governance capabilities that may require legal confirmation and advance planning.
No. It is a planning output based on self-assessment, not independent assurance. An audit requires defined criteria, evidence sampling, testing, documented findings, and competent independent evaluation.