Privacy Compliance Self-Assessment

Free ยท No Login Required ยท Instant PDF Report ยท 20-Section Comprehensive Framework

๐Ÿ‡ฎ๐Ÿ‡ณ DPDPA 2023 ๐Ÿ‡ช๐Ÿ‡บ GDPR ๐Ÿ‡บ๐Ÿ‡ธ CCPA ๐ŸŒ Multi-Jurisdiction โฑ ~15 minutes
Step 1 of 20

Organization Profile

Tell us about your organization. This information will appear on your assessment report.

Step 2 of 20

Privacy Applicability Screening

Determine the scope and nature of personal data your organization processes.

Does your organization collect, use, store, or process personal data of individuals?

Which categories of personal data does your organization process? (select all that apply)

Approximate number of individuals (data subjects) whose data you hold:

Do you process special category or sensitive personal data (health, biometric, financial)?

Step 3 of 20

Privacy Role Determination

Identify whether your organization acts as a Data Controller, Processor, or both โ€” this determines your legal obligations.

โ„น๏ธ Your privacy role determines which legal obligations apply. Answer truthfully โ€” the assessment will determine whether you are a Data Controller, Data Processor, Joint Controller, or a combination.

Does your organization decide WHY personal data is processed (the purpose) and HOW it is processed (the means)?

Does your organization process personal data only on the instructions of another organization (a client or principal)?

Do you process data on behalf of multiple clients/customers AND also for your own business purposes?

Do you jointly determine the purposes of processing with another organization (a partner, affiliate, or co-controller)?

Your Determined Privacy Role

Answer questions above

Step 4 of 20

Personal Data Inventory

Assess your data inventory and mapping practices. A complete data inventory is the foundation of privacy compliance.

Do you maintain a documented inventory or register of all personal data your organization processes?

For each data set, have you documented the purpose of processing, legal basis, data categories, retention period, and data recipients?

Is your data inventory or register reviewed and kept up to date at least annually?

Have you created data flow maps or diagrams showing how personal data moves within and outside your organization?

Are data owners or stewards formally assigned for each data category?

Step 5 of 20

Data Lifecycle Management

Evaluate how personal data is managed from the moment of collection through to secure deletion.

Are your data collection procedures formally documented?

Are your data use and processing procedures formally documented?

Do you have documented procedures for data archiving?

Do you have documented procedures for data deletion and secure destruction (including verification)?

Do you operate a data classification scheme (e.g. Public, Internal, Confidential, Restricted)?

Step 6 of 20

Data Sources

Identify and assess how and where personal data is collected across your organization.

Which channels does your organization use to collect personal data? (select all that apply)

Are all data collection channels documented and linked to your data inventory?

Is a privacy notice provided to individuals at each point of data collection?

Do you collect only the minimum personal data necessary for the stated purpose (data minimisation)?

Step 7 of 20

Data Storage

Evaluate where and how personal data is stored, and the security controls protecting it.

Where is personal data stored in your organization? (select all that apply)

Are all personal data storage locations formally documented and inventoried?

Is personal data encrypted at rest across all storage systems?

Are role-based access controls (RBAC) implemented to restrict access to personal data on a need-to-know basis?

Are data storage locations in India (for DPDPA compliance) or do you store data outside India?

Step 8 of 20

Cross-Border Data Transfers

Assess your practices for transferring personal data across national or jurisdictional boundaries.

Does your organization transfer personal data to recipients in other countries or jurisdictions?

Step 9 of 20

Third-Party Management

Evaluate how you manage data processors, sub-processors, and other third-party vendors who access personal data.

Does your organization share personal data with third-party vendors, service providers, or partners?

Step 10 of 20

Legal Basis for Processing

Assess whether all processing activities have an identified and documented lawful basis.

โ„น๏ธ Every data processing activity must have a legal basis. Without a documented lawful basis, processing is unlawful under DPDPA, GDPR, and most modern privacy laws.

Have you identified and documented a lawful basis for every personal data processing activity?

Which legal bases does your organization rely on for processing personal data? (select all that apply)

Are the legal bases for processing disclosed to individuals in your privacy notice?

Where you rely on legitimate interests (GDPR) or deemed consent (DPDPA), have you conducted and documented a Legitimate Interests Assessment (LIA)?

Step 11 of 20

Individual Rights Management

Evaluate your capability to receive, process, and respond to data subject rights requests within regulatory timeframes.

โ„น๏ธ Under DPDPA 2023, data principals have rights to access, correction, erasure, grievance redressal, and nomination. GDPR adds portability and the right to object. You must have a working process to handle these.

Do you have a documented process for receiving and responding to data subject rights requests?

Which data subject rights does your organization have processes to fulfil? (select all that apply)

What is your defined SLA for responding to data subject rights requests?

Are rights requests tracked, documented, and auditable?

Is there a contact mechanism (email, form, portal) published to individuals for submitting rights requests?

Step 12 of 20

Consent Management

Assess how your organization obtains, records, and manages consent for personal data processing.

Does your organization obtain and rely on consent as a legal basis for any personal data processing?

Step 13 of 20

Data Retention

Evaluate your data retention policies and procedures for disposing of data once it is no longer needed.

Does your organization have a documented Data Retention Policy covering all data categories?

Are specific retention periods defined, linked to a legal or regulatory basis, for every data category?

Is personal data automatically or systematically deleted / anonymised when its retention period expires?

Do you have a Legal Hold procedure to suspend deletion when data may be needed for litigation or regulatory investigation?

Step 14 of 20

Security Controls

Assess the technical and organisational measures your organisation has implemented to protect personal data.

Do you have a documented Information Security Policy covering personal data?

Which technical security controls are implemented? (select all that apply)

Which organisational security controls are in place? (select all that apply)

Do you have a documented Incident Response Plan for security incidents involving personal data?

Step 15 of 20

Privacy Governance

Evaluate your organisation's privacy governance framework, accountability structures, and privacy culture.

Has your organization appointed a Data Protection Officer (DPO) or equivalent privacy lead?

Does your organization have a publicly available Privacy Policy / Privacy Notice?

Have Privacy Impact Assessments (PIAs) or Data Protection Impact Assessments (DPIAs) been conducted for high-risk processing activities?

Are employees and contractors provided with privacy awareness training?

Is Privacy by Design embedded in your product and system development process (new features, projects, systems reviewed for privacy impact before launch)?

Step 16 of 20

AI & Automated Decision Making

Assess your practices around AI systems, profiling, and automated decisions that affect individuals.

Does your organization use AI systems, machine learning models, or automated decision-making that affects individuals?

Step 17 of 20

Breach & Incident Management

Evaluate your capability to detect, contain, respond to, and report personal data breaches.

Do you have a documented Personal Data Breach / Incident Response Procedure?

What is your target timeframe for notifying the data protection authority (regulator) of a qualifying breach?

Do you have a process to notify affected individuals when a breach creates a high risk to their rights and freedoms?

Do you maintain a Breach / Incident Register logging all incidents (including near-misses and minor incidents, not just notifiable breaches)?

Has your organization experienced a personal data breach in the last 12 months?

Step 18 of 20

Applicable Regulations

Identify which privacy and data protection regulations apply to your organisation based on your geography and activities.

โ„น๏ธ Select all regulations that apply to your organization. Your responses, geography, and data subjects' locations determine applicability.

Which data protection / privacy regulations apply to your organization? (select all that apply)

Other applicable regulations or sector-specific rules (e.g. RBI guidelines, IRDAI, SEBI, HIPAA, PCI DSS):

Are you registered with the relevant data protection authority (e.g. notified ICO, registered with DPBI when operational)?

Do you have a process to monitor regulatory updates (new laws, guidance, enforcement actions) in jurisdictions where you operate?

Step 19 of 20

Your Compliance Score

Automated compliance score based on your responses across 12 privacy domains.

Your compliance score is calculated across 12 privacy domains based on your responses in Steps 4โ€“18. Each domain is scored out of 5, giving a maximum score of 60.
Score calculatingโ€ฆ
Step 20 of 20

Compliance Roadmap & PDF Report

Your personalised compliance roadmap based on identified gaps, and your downloadable PDF report.

Your compliance roadmap highlights priority actions based on gaps identified in your assessment. Address High priority items first to reduce regulatory risk.
Roadmap generatingโ€ฆ
Step 1 of 20