The GDPR Readiness Assessment covers 52 controls across 9 categories — from lawful basis and privacy notices to breach notification, vendor contracts, and international data transfers. Free, browser-based, no account required.
The assessment follows the structure of the Regulation itself — from the legal grounds for processing through accountability and governance. Each control links to the specific GDPR article it implements.
GDPR applies to any organization — regardless of where it is based — that processes personal data of individuals in the EU or EEA. These are the most common use cases.
Any business with a website, SaaS product, or service accessible to EU residents is subject to GDPR — regardless of whether you have an EU office.
Baja California operations with European ownership or EU employee data flows face both GDPR and LFPDPPP obligations. This tool covers the EU side.
Software products handling EU user data — even in free tiers — trigger full GDPR obligations including ROPA, DPAs with all processors, and data subject rights procedures.
Telehealth, therapy, legal, and financial services with EU clients process special category or high-sensitivity data — triggering Art. 9, DPIA, and stricter breach notification rules.
Any online store shipping to the EU or using EU customer analytics, ad targeting, or cookie-based personalization needs lawful basis documentation and a compliant cookie notice.
Use the tool to run a structured gap assessment, produce a PDF report for the board, and track remediation progress across the full GDPR obligation set.
The top fine categories: Art. 83(5) violations — lawful basis failures, data subject rights violations, international transfer breaches, and fundamental processing principles — carry fines up to €20M or 4% of global annual turnover. Art. 83(4) violations — DPIA failures, DPO violations, and processor contract gaps — carry fines up to €10M or 2% of turnover. Supervisory authorities across the EU issued over €2.5B in GDPR fines between 2018 and 2025.
The good news: A completed, documented GDPR assessment with a clear remediation plan is evidence of good faith. Supervisory authorities consistently treat organizations with documented compliance programs more favorably than those who cannot demonstrate they ever assessed their obligations. The tool gives you both the assessment and the PDF documentation in under an hour.
No account. No server. Everything runs in your browser. Export PDF or JSON at any time.
Enter organization name, assessor, date, scope, and your lead Supervisory Authority. Multi-client profiles let you run assessments for multiple organizations.
Mark each of the 52 controls as Implemented, Partial, Not Implemented, or N/A. Add notes and evidence references. The DPO requirement flag alerts automatically if Art. 37 gaps are detected.
Weighted readiness score updates in real time. Gap report shows every open control sorted by risk weight. Snapshot history tracks improvement over time.
Generate a PDF report or AI-powered gap analysis using your own Anthropic API key. If remediation requires legal or advisory support, TRA Consulting can help.
Free, browser-based, no account required. Run it in under an hour. Export a PDF report for your board or supervisory authority.