Skip to main content
0%
Non Conforme

10 elemento/i critico/i non completato/i

Raccolta Dati

0%

Consenso

0%

Diritti degli Interessati

0%

Sicurezza

0%

DPO e Organizzazione

0%

Violazioni dei Dati

0%

Trasferimenti Internazionali

0%

Azioni Critiche Prioritarie

  • Registro dei trattamenti (Art. 30)
  • Base giuridica identificata (Art. 6)
  • Consenso libero, specifico, informato (Art. 7)
  • Diritto di accesso (Art. 15)
  • Diritto alla cancellazione (Art. 17)
  • Misure tecniche adeguate (Art. 32)
  • Responsabili esterni contrattualizzati (Art. 28)
  • Procedura di risposta agli incidenti
  • Notifica all'Autorita' entro 72 ore (Art. 33)
  • Meccanismo di trasferimento adeguato (Art. 46)

Come utilizzare GDPR Compliance Checker

Scroll through the 7 categories

The checklist is organized into 7 areas: data collection, consent, data subject rights, security, Data Protection Officer and organization, data breaches, international transfers.

Click on existing elements

Click on each voice to mark it as compliant. Each item has a severity level (critical, high, medium, low) indicating how urgent it is to fill the potential gap.

Check your score and critical actions

Score banner at the top shows overall percentage and compliance level. The "Critical Priority Actions" panel lists items still to be completed with critical severity.

Generate and copy the report

Click "Generate Report" to get a textual summary with score by category and priority actions, then copy it into your notes to share with the team or DPO.

Suggerimenti

  • Always start with harsh criticism; it's those that expose you to immediate sanctions.
  • Repeat the checklist periodically (e.g., every 6 months) because processes and suppliers change over time.
  • Use the copied report as a basis for updating the treatment record (Article 30), not as a substitute.

Domande frequenti

How is percentage of compliance calculated?

The ratio of the number of checked voices as conforming to the total of 33 checklist voices across all 7 categories, not weighted by severity: one critical voice and one low-priority voice count equally in the percentage score.

What changes between Non Conformity, Partially Conformity, Substantially Conformity and Fully Conformity levels?

Score thresholds: Below 40% Nonconformity, 40-69% Partially Conformity, 70-89% Substantially Conformity, 90% and above Fully Conformed. Even with a high score, always check critical action priority panels.

Why do some items have severity levels of "critical" and others "low"?

Conciseness is key — similar length as severity. Severity reflects the risk of sanctions and operational gravity of absence of that measure: treatment registry, legal basis, DPA with suppliers or breach notification within 72 hours are critical because their lack exposes to direct sanctions. Low-severity voices (e.g., updated internal policies) are good practices but less urgent.

Does the generated report have legal value or is it an auto-certification?

No, it's an internal self-assessment report to quickly identify gaps. It does not replace a compliance audit conducted by a DPO or legal advisor, and is not proof of compliance with the Guarantor.

Are data entered in this checklist saved or sent elsewhere?

No, the state of the checklist lives only in the browser session: it is not sent to any server and gets lost when reloading the page (unless you copy the generated report first).