GDPR Compliance Checklist (Self-Assessment)
Check your business against the core GDPR / UK GDPR requirements — lawful basis, privacy notice, records, consent, rights handling, security, breaches, processors, transfers, DPIAs and DPO — and get a score with a prioritised to-do list.
For general information only — not legal advice. Laws vary by location; consult a qualified lawyer.
How to use
- 1Tick each item you already have in place.
- 2Generate your report.
- 3Work through the missing items, starting with the high-priority ones.
Frequently asked questions
Does GDPR apply to small businesses?
Yes — to any organisation processing personal data of people in the EU/UK, whatever its size. A few duties (like records of processing) are lighter for under-250-employee firms with low-risk processing.
Do I need a Data Protection Officer?
Only if you're a public authority, or your core activities involve large-scale regular monitoring of people or large-scale sensitive data. Otherwise it's optional.
Do I need to register with the ICO?
In the UK, most organisations processing personal data must pay the ICO data protection fee (£52–£3,763 a year depending on size), unless exempt.