UK GDPR Readiness Check
The questions an ICO enquiry or a customer's due-diligence pack actually asks. Several are statutory requirements rather than good practice, and their absence is a compliance failure in itself.
18 questions. Nothing is sent anywhere as you answer, the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.
Accountability
Being able to demonstrate compliance, not just claim it.
Do you maintain a Record of Processing Activities covering what personal data you hold, why, and for how long?
Article 30. The first document requested in almost any enquiry.
Have you identified and documented a lawful basis for each processing activity?
Is someone formally accountable for data protection, and are they registered with the ICO if required?
Are Data Protection Impact Assessments carried out for high-risk processing?
Individual rights
Handling requests within the statutory deadline.
Is there a documented process to handle a subject access request within one month?
Could you actually locate every copy of one person's data across your systems, including backups and email?
Most organisations have the policy and could not do this in practice.
Can you honour erasure, rectification and portability requests?
Is your privacy notice accurate, current and written in plain language?
Breach response
The 72-hour clock.
Is there a breach process that would let you assess and report to the ICO within 72 hours of becoming aware?
Do staff know how to report a suspected breach internally, and has that been tested?
Do you keep a breach register, including incidents you decided not to report?
Suppliers and transfers
Data you have handed to someone else.
Do you have written processor agreements with Article 28 terms for every supplier that handles personal data?
Have you identified international transfers and put a transfer mechanism in place: IDTA, addendum or adequacy?
Do you assess a supplier's security before sharing personal data with them?
Security of processing
Article 32 in practice.
Is personal data encrypted at rest and in transit?
Is access to personal data restricted to those who need it, and reviewed?
Are retention periods defined and actually enforced by deletion?
Do staff receive data protection training, recorded and refreshed?