How GDPR-compliant are you?
Nine questions, three minutes: an honest snapshot of your GDPR compliance on the points supervisory authorities actually check, with your most serious gaps highlighted.
- Free
- Instant result
- No email required
- 2-3 minutes
Your result
Adequate
Your GDPR setup is solid: the main obligations are covered. The job now is keeping it alive — periodic updates and vendor checks.
Mind the maintenance: notices and registers age every time you change a vendor, a tool or a process. A scheduled annual review (half a day) is enough to avoid ending up with paper-only compliance in two years.
Partial
There are foundations, but also concrete gaps: some of what is missing is among the first things contested in a complaint or inspection.
The good news: starting from a partial base, closing the main gaps is a matter of weeks, not months. Priorities are listed below — typically the register, the breach procedure and vendor agreements are the three highest-yield fixes.
Critical
Your GDPR compliance is largely still to be built: today a client complaint or a data breach would catch you exposed both legally and practically.
GDPR fines reach €20 million or 4% of worldwide turnover, but for an SME the most concrete risk is a complaint to the authority or a client/partner asking for evidence and finding none. The sensible path: processing register → notices → baseline security → breach procedure. It doesn’t have to happen in a day; it has to start.
This test is an indicative self-assessment, not a legal review: actual compliance depends on the specific processing activities of your business.
Want a professional opinion?
This test is a first orientation. If you want to know what to actually do in your situation, let’s talk: 30 minutes, no commitment.
Request an assessmentFrequently asked questions
Does the test replace a GDPR audit?
No: it is a self-assessment covering the essentials (privacy notices, records of processing, legal bases, data breaches, vendors, security measures). It shows where you stand and which gaps are most urgent; a real audit examines your specific processing activities.
Does the GDPR apply to freelancers too?
Yes: it applies to anyone processing personal data in a professional context, regardless of size. What changes are the measures — proportionate to risk — not the obligation to comply.
Do I have to leave my email to see the result?
No: the summary result is shown immediately. Your email is only needed if you want the full report with an analysis of each answer.
What happens to my answers?
They stay in your browser: the test runs entirely client-side. Only if you request the report by email are your answers and address used — exclusively to send it.
What are the GDPR penalties?
For the most serious violations, Article 83 provides fines of up to €20 million or 4% of worldwide annual turnover, whichever is higher. In practice, penalties are proportionate to severity, duration and the controller’s conduct — but even “small” enforcement actions cost time, reputation and stress.