Am I GDPR Compliant?

Find out if you are GDPR-compliant with our GDPR-compliant quiz and guide.

The EU general data protection regulation (GDPR) is the strongest privacy and security law in the world.

What should we call your product, company, or service?

If your product had a personal data breach today, could you notify the relevant authority within 72 hours?

Article 33 requires notification without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach.

Do you know, in writing, what personal data your product collects and why?

Article 30 requires most organizations to keep records of processing, with a narrow exemption for smaller ones doing only occasional, low risk processing.

If your product does large scale monitoring or handles large amounts of sensitive data, have you appointed a Data Protection Officer?

Article 37 requires a DPO for public authorities and for organizations whose core activities involve large scale monitoring or large scale processing of sensitive data.

If someone under 16 could sign up for your product, do you verify age or get parental consent?

Article 8 sets the default age at 16, though member states can lower it, not below 13.

For every way your product uses personal data, do you know which lawful basis you're relying on, like consent or contract?

Article 6 requires a lawful basis, such as consent, contract, or legitimate interests, for every kind of processing.

If a user asked for their data from your product in a portable file, could you actually produce it?

Article 20 gives this right when processing is based on consent or contract and carried out by automated means.

If someone asked your product to delete their data, could you actually do it?

Article 17 requires erasure on specific grounds, with narrow exceptions like legal claims or freedom of expression.

Does your product only collect the personal data it actually needs, and delete it once it's no longer needed?

Article 5 requires data minimisation and storage limitation, meaning only what's necessary, kept only as long as necessary.

Does your product have reasonable technical measures in place, like encryption or access controls, to protect personal data?

Article 32 requires appropriate technical and organizational security, including things like encryption and the ability to restore access after an incident.

If your product is based outside the EU, do you still apply these rules to visitors, users, or customers in the EU?

Article 3 extends GDPR to non-EU companies that offer goods or services to, or monitor the behavior of, people in the EU.