Most GDPR self-assessments ask whether you have a privacy policy. That is not the question a supervisory authority asks. It asks whether you can demonstrate compliance — produce the record, the assessment, the consent log, the decision and its reasoning — and it asks on a short clock.
This assessment works through the articles that create an operational obligation, from lawful basis to international transfers, and scores what you could actually evidence today. It is free, it saves as you go, and you can stop and come back to it.
What is a GDPR gap assessment?
A gap assessment compares your current practice against what Regulation (EU) 2016/679 actually requires, article by article, and records the distance. It is the evidence-gathering step that comes before a remediation plan, and the one that turns a vague sense of exposure into a list with owners on it.
Article 5(2) is the reason it matters. Accountability is not a principle you satisfy by behaving well; it is one you satisfy by being able to prove it. In enforcement decisions, the organisation that had the records almost always fares better than the one that merely had good intentions.
What this assessment covers
88 assessable obligations across the twelve areas a controller or processor is examined on.
| Domain | Items | What it asks about |
|---|---|---|
| Scope and accountability | 8 | Territorial scope, controller or processor role, Article 24 measures, joint controllers, EU representative |
| Principles and lawful basis | 13 | The six principles, basis per purpose, legitimate interests assessments, consent, children, special categories |
| Transparency and notices | 7 | Article 13 and 14 elements, timing for indirectly collected data, exemptions |
| Data subject rights | 11 | Access, rectification, erasure, restriction, portability, objection, automated decisions |
| Records of processing | 4 | Controller and processor records, availability to the authority, the small-organisation exemption |
| Processors and third parties | 6 | Due diligence, Article 28(3) terms, sub-processors, audit rights, documented instructions |
| By design and security | 8 | Article 25 design and defaults, the four Article 32 measures, risk to individuals |
| Personal data breaches | 6 | 72-hour notification, content, the internal register, communication to individuals |
| DPIA and prior consultation | 6 | Screening, mandatory cases, required content, review, Article 36 |
| Data protection officer | 5 | Designation, publication, involvement, independence, tasks |
| International transfers | 7 | Adequacy, safeguards, transfer impact assessments, third-country authority requests, derogations |
| Governance and assurance | 6 | Training, codes, certification, internal audit, management review, supplier review |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records an authority could inspect |
| Not applicable | — | A justified exclusion, removed from the score |
For GDPR the “implemented, not evidenced” row is the whole game. A lawful basis you chose but never recorded, a compatibility test you did in a meeting, a transfer you assessed in someone’s head — all of these are compliant in substance and indefensible in an investigation.
The obligations that fail most often
- Article 30 records that were built once for the 2018 deadline and never updated. They are the first thing an authority asks for.
- Article 13 and 14 notices missing specific elements — usually the legitimate interests pursued, the retention period, or the source of indirectly collected data.
- Article 6(4) compatibility, where existing customer data gets reused for analytics or model training without anyone testing whether the new purpose is compatible.
- Article 44 transfers that nobody classified as transfers — remote support access from a third country is the common one.
- Article 33(5), the internal register of breaches you decided not to notify. Authorities ask for exactly that list.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every article with your status and notes, the score broken down by domain, a prioritised gap list, and the Governance Docs documents that close each gap — as a PDF and a working Excel file you can hand to whoever owns the remediation.
How long does it take?
About 40 minutes if you know your processing, considerably longer if answering honestly means going to find out. Answers save as you go, so it is normal to run it across several sittings and involve more than one team.
Gap assessment, DPIA, audit
- Gap assessment — the whole programme measured against the Regulation. This.
- DPIA — one specific high-risk processing activity assessed in depth, under Article 35. Narrower and deeper, and mandatory in defined cases.
- Data protection audit — an independent review of whether what you say you do is what you actually do, usually annual.
You want the gap assessment first. It tells you which DPIAs you owe.
What to do with your score
Below 40% — start with Article 30. Almost everything else depends on knowing what processing exists.
40–70% — the documentation is the gap, not the practice. Prioritise records, notices and assessments over new controls.
Above 70% — move to assurance: internal audit, processor reviews, and rehearsing how you would respond if an investigation opened.
Frequently asked questions
Is this assessment really free?
Yes. Every article, your section breakdown and your overall score cost nothing. The $39 full report is optional.
Does GDPR apply to us if we are not in the EU?
Possibly. It applies if you have an establishment in the Union, or if you offer goods and services to people in it, or monitor their behaviour. The assessment opens with that question rather than assuming the answer.
Does it cover processors as well as controllers?
Yes. Article 28, 29, 30(2) and the processor-side breach duties are all scored, and the assessment asks you to establish your role per processing activity first.
Does it cover UK GDPR?
The article structure is materially the same, so the assessment is usable for UK GDPR, but it is written against the EU Regulation. Where UK divergence matters — principally transfers and the ICO’s own guidance — check against current UK sources.
Is a high score the same as being compliant?
No. It is a structured self-assessment, not a certification, and no assessment can tell you whether a specific processing activity is lawful. It tells you where the documented gaps are.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.