Legal Tools

GDPR Compliance Checklist

Self-assess your organisation's GDPR readiness across 15 core requirements and get an instant compliance score.

Advertisement
GDPR Compliance Checklist
Check your organisation's GDPR readiness with a self-assessment score

Check each item that applies to your organisation. Your compliance score updates automatically.

Disclaimer. This checklist is a self-assessment aid only, not a formal legal or regulatory compliance audit, and does not constitute legal advice. A high score does not guarantee GDPR compliance in practice. Engage a qualified data protection professional or lawyer for a formal compliance assessment, especially before processing sensitive data or launching in the EU/UK. Read full disclaimer →

About GDPR Compliance Checker

The General Data Protection Regulation (GDPR) applies to any organisation processing personal data of EU residents, regardless of where the organisation is based. Indian businesses serving EU customers must comply. Key requirements: lawful basis for every data processing activity; data subject rights including access, erasure, portability, and restriction; privacy by design; data breach notification within 72 hours of discovery.

High-risk areas: analytics and advertising cookies require genuine opt-in consent; email lists need explicit opt-in with no pre-ticked boxes; age verification is required for users under 16. GDPR fines can reach 20 million euros or 4% of global annual turnover whichever is higher. India's Digital Personal Data Protection Act, 2023 (DPDPA) has similar requirements for domestic operations. Use this checklist to identify compliance gaps before launching or auditing your platform.

Frequently Asked Questions

It is the percentage of the 15 checklist items you've marked as complete, out of the total. It is a rough self-assessment indicator, not a certified audit score: 80%+ is labelled Good Compliance, 60-79% Partial Compliance, and below 60% Needs Attention.
Yes, potentially. GDPR applies to any organisation processing personal data of EU residents, regardless of where the organisation itself is based. If you have EU customers, site visitors you track, or EU-based staff, GDPR requirements can still apply to you.
Fines can reach up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious breaches. Non-compliance can also mean regulatory investigations, mandatory breach notifications, and reputational damage.
India's Digital Personal Data Protection Act 2023 (DPDPA) imposes similar requirements for domestic data processing operations, such as lawful basis for processing, data subject rights and breach notification duties. Many items on this GDPR checklist (privacy notices, consent management, security measures) are useful groundwork for DPDPA readiness too, though the two laws are not identical.
Advertisement