Free ยท No Login Required ยท Instant PDF Report ยท 20-Section Comprehensive Framework
Tell us about your organization. This information will appear on your assessment report.
Determine the scope and nature of personal data your organization processes.
Does your organization collect, use, store, or process personal data of individuals?
Which categories of personal data does your organization process? (select all that apply)
Approximate number of individuals (data subjects) whose data you hold:
Do you process special category or sensitive personal data (health, biometric, financial)?
Identify whether your organization acts as a Data Controller, Processor, or both โ this determines your legal obligations.
Does your organization decide WHY personal data is processed (the purpose) and HOW it is processed (the means)?
Does your organization process personal data only on the instructions of another organization (a client or principal)?
Do you process data on behalf of multiple clients/customers AND also for your own business purposes?
Do you jointly determine the purposes of processing with another organization (a partner, affiliate, or co-controller)?
Your Determined Privacy Role
Answer questions above
Assess your data inventory and mapping practices. A complete data inventory is the foundation of privacy compliance.
Do you maintain a documented inventory or register of all personal data your organization processes?
For each data set, have you documented the purpose of processing, legal basis, data categories, retention period, and data recipients?
Is your data inventory or register reviewed and kept up to date at least annually?
Have you created data flow maps or diagrams showing how personal data moves within and outside your organization?
Are data owners or stewards formally assigned for each data category?
Evaluate how personal data is managed from the moment of collection through to secure deletion.
Are your data collection procedures formally documented?
Are your data use and processing procedures formally documented?
Do you have documented procedures for data archiving?
Do you have documented procedures for data deletion and secure destruction (including verification)?
Do you operate a data classification scheme (e.g. Public, Internal, Confidential, Restricted)?
Identify and assess how and where personal data is collected across your organization.
Which channels does your organization use to collect personal data? (select all that apply)
Are all data collection channels documented and linked to your data inventory?
Is a privacy notice provided to individuals at each point of data collection?
Do you collect only the minimum personal data necessary for the stated purpose (data minimisation)?
Evaluate where and how personal data is stored, and the security controls protecting it.
Where is personal data stored in your organization? (select all that apply)
Are all personal data storage locations formally documented and inventoried?
Is personal data encrypted at rest across all storage systems?
Are role-based access controls (RBAC) implemented to restrict access to personal data on a need-to-know basis?
Are data storage locations in India (for DPDPA compliance) or do you store data outside India?
Assess your practices for transferring personal data across national or jurisdictional boundaries.
Does your organization transfer personal data to recipients in other countries or jurisdictions?
Evaluate how you manage data processors, sub-processors, and other third-party vendors who access personal data.
Does your organization share personal data with third-party vendors, service providers, or partners?
Assess whether all processing activities have an identified and documented lawful basis.
Have you identified and documented a lawful basis for every personal data processing activity?
Which legal bases does your organization rely on for processing personal data? (select all that apply)
Are the legal bases for processing disclosed to individuals in your privacy notice?
Where you rely on legitimate interests (GDPR) or deemed consent (DPDPA), have you conducted and documented a Legitimate Interests Assessment (LIA)?
Evaluate your capability to receive, process, and respond to data subject rights requests within regulatory timeframes.
Do you have a documented process for receiving and responding to data subject rights requests?
Which data subject rights does your organization have processes to fulfil? (select all that apply)
What is your defined SLA for responding to data subject rights requests?
Are rights requests tracked, documented, and auditable?
Is there a contact mechanism (email, form, portal) published to individuals for submitting rights requests?
Assess how your organization obtains, records, and manages consent for personal data processing.
Does your organization obtain and rely on consent as a legal basis for any personal data processing?
Evaluate your data retention policies and procedures for disposing of data once it is no longer needed.
Does your organization have a documented Data Retention Policy covering all data categories?
Are specific retention periods defined, linked to a legal or regulatory basis, for every data category?
Is personal data automatically or systematically deleted / anonymised when its retention period expires?
Do you have a Legal Hold procedure to suspend deletion when data may be needed for litigation or regulatory investigation?
Assess the technical and organisational measures your organisation has implemented to protect personal data.
Do you have a documented Information Security Policy covering personal data?
Which technical security controls are implemented? (select all that apply)
Which organisational security controls are in place? (select all that apply)
Do you have a documented Incident Response Plan for security incidents involving personal data?
Evaluate your organisation's privacy governance framework, accountability structures, and privacy culture.
Has your organization appointed a Data Protection Officer (DPO) or equivalent privacy lead?
Does your organization have a publicly available Privacy Policy / Privacy Notice?
Have Privacy Impact Assessments (PIAs) or Data Protection Impact Assessments (DPIAs) been conducted for high-risk processing activities?
Are employees and contractors provided with privacy awareness training?
Is Privacy by Design embedded in your product and system development process (new features, projects, systems reviewed for privacy impact before launch)?
Assess your practices around AI systems, profiling, and automated decisions that affect individuals.
Does your organization use AI systems, machine learning models, or automated decision-making that affects individuals?
Evaluate your capability to detect, contain, respond to, and report personal data breaches.
Do you have a documented Personal Data Breach / Incident Response Procedure?
What is your target timeframe for notifying the data protection authority (regulator) of a qualifying breach?
Do you have a process to notify affected individuals when a breach creates a high risk to their rights and freedoms?
Do you maintain a Breach / Incident Register logging all incidents (including near-misses and minor incidents, not just notifiable breaches)?
Has your organization experienced a personal data breach in the last 12 months?
Identify which privacy and data protection regulations apply to your organisation based on your geography and activities.
Which data protection / privacy regulations apply to your organization? (select all that apply)
Other applicable regulations or sector-specific rules (e.g. RBI guidelines, IRDAI, SEBI, HIPAA, PCI DSS):
Are you registered with the relevant data protection authority (e.g. notified ICO, registered with DPBI when operational)?
Do you have a process to monitor regulatory updates (new laws, guidance, enforcement actions) in jurisdictions where you operate?
Automated compliance score based on your responses across 12 privacy domains.
Your personalised compliance roadmap based on identified gaps, and your downloadable PDF report.