About this program
A practical 30-minute self-check on the GDPR controls that fail most audits — not a full DPIA.
Risks addressed
- High No basis recorded for processing categories of data
- Critical Breach notification timeline missed (>72h)
- High No DPA with a Tier-1 processor
Controls (7)
-
Article-30 Record of Processing Activities maintained
HighArticle 30 of the GDPR mandates that organizations acting as data controllers or processors maintain comprehensive, up-to-date written records of all personal data processing activities. These records document the purposes of processing, categories of data subjects and personal data, recipients,…
How to test + evidence
Testing procedure: RoPA exists, covers all processing activities, dated within 6 months.
Evidence to collect: RoPA file.
-
Lawful basis recorded per processing activity
HighThis control requires organizations to document the lawful basis for each personal data processing activity in accordance with applicable privacy regulations such as GDPR Article 6, CCPA, or other jurisdictions. Each processing activity recorded in the Record of Processing Activities…
How to test + evidence
Testing procedure: Each activity has a documented basis (consent, contract, legitimate interest, …).
Evidence to collect: RoPA — basis column.
-
DPAs in place for all processors
HighThis control requires that formal Data Processing Agreements (DPAs) are executed with all third-party data processors who handle personal or sensitive data on behalf of the organization. DPAs define the scope, duration, nature, and purpose of data processing, establish processor…
How to test + evidence
Testing procedure: Article-28 contracts on file for every Tier-1/2 processor.
Evidence to collect: DPA inventory.
-
Breach notification process tested
CriticalThis control requires organizations to periodically test their data breach notification process through simulated exercises or tabletop scenarios. Testing validates that procedures for identifying, classifying, escalating, and notifying stakeholders (customers, regulators, partners) of security incidents function as documented. Regular testing…
How to test + evidence
Testing procedure: Workflow tested; named DPO + comms templates; <72h timeline understood.
Evidence to collect: Tabletop AAR.
-
Subject access (DSAR) workflow tested
MediumThis control validates that the organization has designed, documented, and operationally tested its Data Subject Access Request (DSAR) workflow to ensure timely, accurate, and complete responses to individual rights requests under privacy regulations such as GDPR, CCPA, or similar. Testing…
How to test + evidence
Testing procedure: Test request handled end-to-end within statutory window.
Evidence to collect: DSAR test report.
-
Privacy notice up to date
MediumThis control requires that privacy notices provided to data subjects are kept current with actual data processing activities, legal requirements, and organizational practices. It ensures that individuals receive accurate, complete information about how their personal data is collected, used, stored,…
How to test + evidence
Testing procedure: Public-facing notice reflects current processing + last reviewed within 12 months.
Evidence to collect: Notice + review date.
-
Cross-border transfers via SCCs / adequacy
HighThis control ensures that personal data transferred outside the European Economic Area (EEA) or other jurisdictions with strict data protection laws is protected through legally recognized mechanisms. Organizations must rely on European Commission adequacy decisions (recognizing equivalent protection in destination…
How to test + evidence
Testing procedure: Transfers outside EEA covered by SCCs or adequacy decision; TIAs done.
Evidence to collect: SCC inventory + TIAs.