GDPR self-assessment
Review key GDPR governance, documentation, rights, security and risk-management mechanisms.
This questionnaire is a documentation and governance review tool. It is not legal advice and does not prove GDPR compliance. Some obligations depend on the specific context of your processing activities.
METHODOLOGY
Before you start
Questions cover core GDPR mechanisms and link to the relevant Article or CNIL guidance. “Not applicable” should only be used after checking that the requirement or situation genuinely does not apply to the processing under review.
The assessment engine runs entirely in this page: no account, no tracking cookie, no answer transmission and no automatic local storage.
16 questions maximum · 8–12 min
SOURCES & VERSION
Verified on August 24, 2026
- 2016-04-27CNIL — General Data Protection Regulation ↗
GDPR text published by the French data protection authority.
- 2026-05-20CNIL — Record of processing activities ↗
CNIL guidance on Article 30 and records of processing.
- 2026-08-24CNIL — Transparency and information to data subjects ↗
CNIL guidance on purposes, legal basis, recipients and retention periods.
- 2026-04-02CNIL — Data retention periods ↗
CNIL guidance on storage limitation.
- 2026-08-24CNIL — Data protection impact assessment (DPIA) ↗
CNIL guidance for processing likely to result in high risk.
- 2026-08-24CNIL — Managing incidents and personal data breaches ↗
Documentation, risk assessment and notification to the CNIL when required.
- 2026-08-24CNIL — Data Protection Officer ↗
Cases where a DPO must be appointed and the DPO’s missions.
- 2026-05-01CNIL — GDPR security of personal data practical guide ↗
Practical personal-data security guide published by the CNIL.