Conducting GDPR Compliance Assessment
Effective Date: August 2026
Legal Basis: EU Regulation 2016/679 (GDPR), UK GDPR as amended by Data Protection Act 2018 and Data (Use and Access) Act 2025 (ukpga/2025/18)
Pending Changes: Digital Omnibus proposal (COM(2025) 837) would change Article 30(5) threshold from 250 to 750 employees and Article 33 breach notification from 72h to 96h. Still in proposal stage; current requirements remain in force.
When to Use
- When an organization processes personal data of EU residents (Article 3 territorial scope applies)
- When preparing for a supervisory authority audit (ICO, CNIL, BfDI) or responding to formal inquiry
- When implementing privacy-by-design requirements (Article 25) for new systems or data flows
- When scoping compliance gaps before M&A due diligence or contract negotiations with EU entities
- When responding to data subject access requests (DSARs) and discovering gaps in data inventory
- When assessing third-party processors for GDPR compliance before signing Data Processing Agreements (DPAs)
- After data breach incidents to verify notification procedures meet 72-hour requirement (Article 33)
Do not use for:
- Technical implementation of specific GDPR controls (encryption, pseudonymization, access controls) — use implementing-gdpr-data-protection-controls for Article 32 technical/organizational measures
- Automated DSAR processing workflows (identity verification, PII discovery, redaction, delivery) — use implementing-gdpr-data-subject-access-request for DSAR automation
- Non-EU privacy frameworks alone (CCPA, PIPEDA, LGPD); those require separate assessments with jurisdiction-specific criteria
- This skill is for comprehensive compliance assessment across all GDPR articles; use the specialized skills for focused implementation tasks
Prerequisites
- Understanding of GDPR Articles 5-32 and key definitions
- Access to Article 30 records of processing activities
- Data Processing Agreements with third-party processors
- Privacy policies, consent forms, cookie notices
- Knowledge of lawful bases (Article 6)
- Data breach response plan and incident register
- List of international data transfers with safeguards
Workflow
For detailed procedures, templates, and examples, see references/detailed-workflow.md
Phase 1: Determine Territorial Applicability (Article 3)
GDPR applies if:
- Organization has establishment in EU
- Offers goods/services to EU residents
- Monitors behavior of EU residents
Check: EU office? EU website targeting? Behavioral tracking?
Phase 2: Inventory Data Processing Activities (Article 30)
Document for EACH activity:
- Controller/processor details
- Processing purposes (specific)
- Data categories and special categories (Art. 9)
- Recipients and international transfers
- Retention periods
- Security measures
Tools: Use scripts/article30_parser.py, article30_validator.py, generate_ropa_report.py
Common gaps: Missing retention periods (68%), vague purposes, undocumented transfers
Phase 3: Validate Lawful Basis (Article 6)
| Basis |
Use Case |
Key Requirement |
| Consent (6(1)(a)) |
Marketing, profiling |
Freely given, specific, withdrawable |
| Contract (6(1)(b)) |
Order fulfillment |
Strictly necessary only |
| Legal Obligation (6(1)(c)) |
Tax records |
Cite specific law |
| Legitimate Interest (6(1)(f)) |
Fraud prevention, analytics |
Three-part test + balancing |
Action: Map each Article 30 activity to one lawful basis. Document legitimate interest assessments.
Phase 4: Assess Data Subject Rights (Articles 12-23)
Verify capability for:
- Access (15): Provide copy in machine-readable format within 1 month
- Rectification (16): Correct inaccurate data
- Erasure (17): "Right to be forgotten" (with exceptions)
- Portability (20): Transfer data in structured format
- Objection (21): Opt-out of legitimate interest processing
- Automated Decision-Making (22): Human review of algorithmic decisions
Test: Process sample DSAR through full workflow. Use scripts/ for automation.
Phase 5: Review DPIAs (Article 35)
DPIA mandatory for:
- Large-scale profiling with automated decisions
- Large-scale special categories processing
- Systematic monitoring of public areas (facial recognition)
Template: See references/detailed-workflow.md for complete DPIA structure
Content: Description, necessity, risks, mitigation, consultation (DPO, supervisory authority if novel high-risk)
Phase 6: Audit Breach Notification (Articles 33-34)
72-hour rule: Notify supervisory authority within 72 hours of becoming aware of breach likely to risk rights.
Decision tree:
- Unencrypted SSNs stolen? → NOTIFY + notify data subjects
- Encrypted backup stolen (key secure)? → Document only
- Temporary exposure (2 hours, no financial data)? → NOTIFY authority, assess data subject notification
Content: Nature, categories/numbers, DPO contact, consequences, mitigation
Phase 7: Verify International Transfers (Chapter V)
Mechanisms:
- Adequacy decisions (UK, Japan, etc.)
- Standard Contractual Clauses (SCCs) 2021 + Transfer Impact Assessment
- Binding Corporate Rules (BCRs)
- Derogations (Article 49 - limited)
Post-Schrems II: Assess destination country surveillance laws, implement supplementary measures (encryption with EU-held keys)
Phase 8: Assess Security Measures (Article 32)
"Security appropriate to the risk":
- Low risk: TLS 1.2+, password hashing, access logs, patching
- Medium risk: AES-256 encryption, MFA, RBAC, penetration testing, SOC 2
- High risk: HSMs, key rotation, SIEM, bug bounty, ISO 27001
Pseudonymization vs. Anonymization: Pseudo = reversible (still personal data); Anon = irreversible (no longer GDPR)
Phase 9: Compile Findings and Remediation Roadmap
Generate compliance report:
- Executive summary (overall status, high-priority gaps)
- Article-by-article findings
- Risk-prioritized remediation plan (Critical/High/Medium/Low)
- Cost estimates and timelines
- Responsible parties (DPO, IT, Legal, Business)
Format: See Output Format section below
Key Concepts
| Term |
Definition |
| Controller |
Determines purposes and means of processing (Article 4(7)) |
| Processor |
Processes on behalf of controller (Article 4(8); requires DPA per Article 28) |
| Personal Data |
Any information relating to identified/identifiable natural person (Article 4(1)) |
| Special Categories |
Health, biometric, genetic, racial, political, religious, trade union, sex life data (Article 9; heightened protection) |
| Consent |
Freely given, specific, informed, unambiguous indication of wishes (Article 4(11)) |
| Legitimate Interest |
Lawful basis requiring three-part test: purpose, necessity, balancing (Recital 47) |
| DPIA |
Data Protection Impact Assessment for high-risk processing (Article 35) |
| DPO |
Data Protection Officer (Article 37; mandatory for public authorities, large-scale monitoring/special categories) |
| SCCs |
Standard Contractual Clauses for international transfers (Commission Implementing Decision 2021/914) |
| Supervisory Authority |
National data protection regulator (ICO for UK, CNIL for France, BfDI for Germany) |
Tools & Systems
Common Scenarios
Scenario: M&A Due Diligence
Context: Acquiring SaaS company with 50K EU customers. Need compliance assessment within 2 weeks.
Approach:
- Request Article 30 records + DPAs with processors (AWS, Stripe, Mailchimp)
- Validate lawful basis: Consent for marketing, Contract for service delivery
- Check breach notification procedures (Article 33): No procedures found → HIGH RISK
- Review international transfers: AWS US-East-1 without SCCs → BLOCKER
- Deliverable: Gap analysis with remediation costs ($120K for SCCs + DPO hire + breach procedures)
Scenario: Supervisory Authority Audit
Context: ICO formal inquiry after consumer complaint about unsubscribe not working.
Response:
- Produce Article 30 records within 7 days
- Demonstrate consent records (timestamp, version, scope)
- Show withdrawal mechanism (unsubscribe link functional, processed within 48h)
- Provide audit logs of DSAR/erasure requests
- Outcome: Warning + 3-month corrective order (no fine due to cooperation)
Output Format
GDPR COMPLIANCE ASSESSMENT REPORT
===================================
Organization: XYZ Corp | Assessment Date: 2026-08-24
Assessor: Jane Smith, CIPP/E | DPO: dpo@xyzcorp.com
EXECUTIVE SUMMARY
━━━━━━━━━━━━━━━━━
Overall Status: PARTIAL COMPLIANCE (67/100)
Critical Gaps: 3 | High: 5 | Medium: 8 | Low: 12
CRITICAL FINDINGS
━━━━━━━━━━━━━━━━━
1. Article 33: No breach notification procedures (72-hour deadline unmet)
2. Chapter V: International transfers to US without SCCs (Schrems II violation)
3. Article 30: Records incomplete (retention periods missing for 40% of activities)
ARTICLE-BY-ARTICLE STATUS
━━━━━━━━━━━━━━━━━━━━━━━━
✅ Article 3: Applicability confirmed (EU establishment)
⚠️ Article 6: Lawful basis documented but 3 activities use invalid bundled consent
✅ Article 15-23: DSAR procedures operational (18-day avg response time)
❌ Article 28: 40% of processors lack signed DPAs
⚠️ Article 32: Encryption at rest implemented but no MFA on admin accounts
❌ Article 33/34: No breach notification procedures
⚠️ Article 35: DPIA completed for profiling but not reviewed in 18 months
❌ Chapter V: US transfers without SCCs
REMEDIATION ROADMAP
━━━━━━━━━━━━━━━━━━━
Priority 1 (0-30 days, $50K):
- Implement breach notification procedures + incident register
- Execute SCCs with AWS, Stripe (Module 2)
- Complete Article 30 records (retention periods, security measures)
Priority 2 (1-3 months, $80K):
- Execute DPAs with remaining 8 processors
- Deploy MFA on all admin accounts
- Conduct legitimate interest assessments for analytics
Priority 3 (3-6 months, $40K):
- Review and update DPIA
- Automated DSAR response workflow
- Annual GDPR training for staff
COMPLIANCE SCORE: 67/100 → Target 90/100 (6 months post-remediation)
Verification Checklist
1---2name: conducting-gdpr-compliance-assessment3description: Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory authority audits, implementing privacy-by-design for new systems, scoping compliance gaps for M&A due diligence, assessing third-party processors, or responding to data subject access requests at scale. Incorporates 2026 guidance from ICO, EDPB, and post-Data (Use and Access) Act 2025 UK-GDPR considerations. Do not use for implementing specific Article 32 controls — use implementing-gdpr-data-protection-controls; or for DSAR automation — use implementing-gdpr-data-subject-access-request.4license: Apache-2.05---6# Conducting GDPR Compliance Assessment
7
8> **Effective Date**: August 2026
9> **Legal Basis**: EU Regulation 2016/679 (GDPR), UK GDPR as amended by Data Protection Act 2018 and Data (Use and Access) Act 2025 (ukpga/2025/18)
10> **Pending Changes**: Digital Omnibus proposal (COM(2025) 837) would change Article 30(5) threshold from 250 to 750 employees and Article 33 breach notification from 72h to 96h. Still in proposal stage; current requirements remain in force.
11
12## When to Use
13
14- When an organization **processes personal data of EU residents** (Article 3 territorial scope applies)
15- When preparing for a **supervisory authority audit** (ICO, CNIL, BfDI) or responding to formal inquiry
16- When implementing **privacy-by-design** requirements (Article 25) for new systems or data flows
17- When **scoping compliance gaps** before M&A due diligence or contract negotiations with EU entities
18- When responding to **data subject access requests (DSARs)** and discovering gaps in data inventory
19- When assessing **third-party processors** for GDPR compliance before signing Data Processing Agreements (DPAs)
20- After **data breach incidents** to verify notification procedures meet 72-hour requirement (Article 33)
21
22**Do not use** for:
23- **Technical implementation** of specific GDPR controls (encryption, pseudonymization, access controls) — use **implementing-gdpr-data-protection-controls** for Article 32 technical/organizational measures
24- **Automated DSAR processing workflows** (identity verification, PII discovery, redaction, delivery) — use **implementing-gdpr-data-subject-access-request** for DSAR automation
25- Non-EU privacy frameworks alone (CCPA, PIPEDA, LGPD); those require separate assessments with jurisdiction-specific criteria
26- This skill is for **comprehensive compliance assessment** across all GDPR articles; use the specialized skills for focused implementation tasks
27
28## Prerequisites
29
30- Understanding of GDPR Articles 5-32 and key definitions
31- Access to Article 30 records of processing activities
32- Data Processing Agreements with third-party processors
33- Privacy policies, consent forms, cookie notices
34- Knowledge of lawful bases (Article 6)
35- Data breach response plan and incident register
36- List of international data transfers with safeguards
37
38## Workflow
39
40**For detailed procedures, templates, and examples, see `references/detailed-workflow.md`**
41
42### Phase 1: Determine Territorial Applicability (Article 3)
43
44GDPR applies if:
451. Organization has establishment in EU
462. Offers goods/services to EU residents
473. Monitors behavior of EU residents
48
49**Check**: EU office? EU website targeting? Behavioral tracking?
50
51### Phase 2: Inventory Data Processing Activities (Article 30)
52
53Document for EACH activity:
54- Controller/processor details
55- Processing purposes (specific)
56- Data categories and special categories (Art. 9)
57- Recipients and international transfers
58- Retention periods
59- Security measures
60
61**Tools**: Use `scripts/article30_parser.py`, `article30_validator.py`, `generate_ropa_report.py`
62
63**Common gaps**: Missing retention periods (68%), vague purposes, undocumented transfers
64
65### Phase 3: Validate Lawful Basis (Article 6)
66
67| Basis | Use Case | Key Requirement |
68|-------|----------|-----------------|
69| **Consent** (6(1)(a)) | Marketing, profiling | Freely given, specific, withdrawable |
70| **Contract** (6(1)(b)) | Order fulfillment | Strictly necessary only |
71| **Legal Obligation** (6(1)(c)) | Tax records | Cite specific law |
72| **Legitimate Interest** (6(1)(f)) | Fraud prevention, analytics | Three-part test + balancing |
73
74**Action**: Map each Article 30 activity to one lawful basis. Document legitimate interest assessments.
75
76### Phase 4: Assess Data Subject Rights (Articles 12-23)
77
78Verify capability for:
79- **Access** (15): Provide copy in machine-readable format within 1 month
80- **Rectification** (16): Correct inaccurate data
81- **Erasure** (17): "Right to be forgotten" (with exceptions)
82- **Portability** (20): Transfer data in structured format
83- **Objection** (21): Opt-out of legitimate interest processing
84- **Automated Decision-Making** (22): Human review of algorithmic decisions
85
86**Test**: Process sample DSAR through full workflow. Use `scripts/` for automation.
87
88### Phase 5: Review DPIAs (Article 35)
89
90DPIA **mandatory** for:
91- Large-scale profiling with automated decisions
92- Large-scale special categories processing
93- Systematic monitoring of public areas (facial recognition)
94
95**Template**: See `references/detailed-workflow.md` for complete DPIA structure
96
97**Content**: Description, necessity, risks, mitigation, consultation (DPO, supervisory authority if novel high-risk)
98
99### Phase 6: Audit Breach Notification (Articles 33-34)
100
101**72-hour rule**: Notify supervisory authority within 72 hours of becoming aware of breach likely to risk rights.
102
103**Decision tree**:
104- Unencrypted SSNs stolen? → NOTIFY + notify data subjects
105- Encrypted backup stolen (key secure)? → Document only
106- Temporary exposure (2 hours, no financial data)? → NOTIFY authority, assess data subject notification
107
108**Content**: Nature, categories/numbers, DPO contact, consequences, mitigation
109
110### Phase 7: Verify International Transfers (Chapter V)
111
112**Mechanisms**:
113- Adequacy decisions (UK, Japan, etc.)
114- Standard Contractual Clauses (SCCs) 2021 + Transfer Impact Assessment
115- Binding Corporate Rules (BCRs)
116- Derogations (Article 49 - limited)
117
118**Post-Schrems II**: Assess destination country surveillance laws, implement supplementary measures (encryption with EU-held keys)
119
120### Phase 8: Assess Security Measures (Article 32)
121
122"Security appropriate to the risk":
123- **Low risk**: TLS 1.2+, password hashing, access logs, patching
124- **Medium risk**: AES-256 encryption, MFA, RBAC, penetration testing, SOC 2
125- **High risk**: HSMs, key rotation, SIEM, bug bounty, ISO 27001
126
127**Pseudonymization** vs. **Anonymization**: Pseudo = reversible (still personal data); Anon = irreversible (no longer GDPR)
128
129### Phase 9: Compile Findings and Remediation Roadmap
130
131Generate compliance report:
132- Executive summary (overall status, high-priority gaps)
133- Article-by-article findings
134- Risk-prioritized remediation plan (Critical/High/Medium/Low)
135- Cost estimates and timelines
136- Responsible parties (DPO, IT, Legal, Business)
137
138**Format**: See Output Format section below
139
140## Key Concepts
141
142| Term | Definition |
143|------|------------|
144| **Controller** | Determines purposes and means of processing (Article 4(7)) |
145| **Processor** | Processes on behalf of controller (Article 4(8); requires DPA per Article 28) |
146| **Personal Data** | Any information relating to identified/identifiable natural person (Article 4(1)) |
147| **Special Categories** | Health, biometric, genetic, racial, political, religious, trade union, sex life data (Article 9; heightened protection) |
148| **Consent** | Freely given, specific, informed, unambiguous indication of wishes (Article 4(11)) |
149| **Legitimate Interest** | Lawful basis requiring three-part test: purpose, necessity, balancing (Recital 47) |
150| **DPIA** | Data Protection Impact Assessment for high-risk processing (Article 35) |
151| **DPO** | Data Protection Officer (Article 37; mandatory for public authorities, large-scale monitoring/special categories) |
152| **SCCs** | Standard Contractual Clauses for international transfers (Commission Implementing Decision 2021/914) |
153| **Supervisory Authority** | National data protection regulator (ICO for UK, CNIL for France, BfDI for Germany) |
154
155## Tools & Systems
156
157- **ICO Self-Assessment**: https://ico.org.uk/for-organisations/sme-web-hub/checklists/gdpr-check-list/
158- **EDPB Guidelines**: https://edpb.europa.eu/our-work-tools/general-guidance_en
159- **OneTrust / TrustArc**: Commercial GRC platforms with DPIA, Article 30, cookie consent modules
160- **Article 30 Scripts**: `article30_parser.py`, `article30_validator.py` (included)
161- **SCCs (2021)**: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en
162- **DPO Certification**: IAPP CIPP/E (Certified Information Privacy Professional/Europe)
163
164## Common Scenarios
165
166### Scenario: M&A Due Diligence
167
168**Context**: Acquiring SaaS company with 50K EU customers. Need compliance assessment within 2 weeks.
169
170**Approach**:
1711. Request Article 30 records + DPAs with processors (AWS, Stripe, Mailchimp)
1722. Validate lawful basis: Consent for marketing, Contract for service delivery
1733. Check breach notification procedures (Article 33): No procedures found → HIGH RISK
1744. Review international transfers: AWS US-East-1 without SCCs → BLOCKER
1755. Deliverable: Gap analysis with remediation costs ($120K for SCCs + DPO hire + breach procedures)
176
177### Scenario: Supervisory Authority Audit
178
179**Context**: ICO formal inquiry after consumer complaint about unsubscribe not working.
180
181**Response**:
1821. Produce Article 30 records within 7 days
1832. Demonstrate consent records (timestamp, version, scope)
1843. Show withdrawal mechanism (unsubscribe link functional, processed within 48h)
1854. Provide audit logs of DSAR/erasure requests
1865. Outcome: Warning + 3-month corrective order (no fine due to cooperation)
187
188## Output Format
189
190```
191GDPR COMPLIANCE ASSESSMENT REPORT
192===================================
193Organization: XYZ Corp | Assessment Date: 2026-08-24
194Assessor: Jane Smith, CIPP/E | DPO: dpo@xyzcorp.com
195
196EXECUTIVE SUMMARY
197━━━━━━━━━━━━━━━━━
198Overall Status: PARTIAL COMPLIANCE (67/100)
199Critical Gaps: 3 | High: 5 | Medium: 8 | Low: 12
200
201CRITICAL FINDINGS
202━━━━━━━━━━━━━━━━━
2031. Article 33: No breach notification procedures (72-hour deadline unmet)
2042. Chapter V: International transfers to US without SCCs (Schrems II violation)
2053. Article 30: Records incomplete (retention periods missing for 40% of activities)
206
207ARTICLE-BY-ARTICLE STATUS
208━━━━━━━━━━━━━━━━━━━━━━━━
209✅ Article 3: Applicability confirmed (EU establishment)
210⚠️ Article 6: Lawful basis documented but 3 activities use invalid bundled consent
211✅ Article 15-23: DSAR procedures operational (18-day avg response time)
212❌ Article 28: 40% of processors lack signed DPAs
213⚠️ Article 32: Encryption at rest implemented but no MFA on admin accounts
214❌ Article 33/34: No breach notification procedures
215⚠️ Article 35: DPIA completed for profiling but not reviewed in 18 months
216❌ Chapter V: US transfers without SCCs
217
218REMEDIATION ROADMAP
219━━━━━━━━━━━━━━━━━━━
220Priority 1 (0-30 days, $50K):
221 - Implement breach notification procedures + incident register
222 - Execute SCCs with AWS, Stripe (Module 2)
223 - Complete Article 30 records (retention periods, security measures)
224
225Priority 2 (1-3 months, $80K):
226 - Execute DPAs with remaining 8 processors
227 - Deploy MFA on all admin accounts
228 - Conduct legitimate interest assessments for analytics
229
230Priority 3 (3-6 months, $40K):
231 - Review and update DPIA
232 - Automated DSAR response workflow
233 - Annual GDPR training for staff
234
235COMPLIANCE SCORE: 67/100 → Target 90/100 (6 months post-remediation)
236```
237
238## Verification Checklist
239
240- [ ] Article 3 applicability determination documented
241- [ ] Article 30 records complete for all activities (controller + processor roles)
242- [ ] Lawful basis identified and documented for each activity
243- [ ] Legitimate interest assessments documented with balancing test
244- [ ] Consent mechanism is granular, withdrawable, and logged
245- [ ] Data subject rights procedures operational (1-month response time)
246- [ ] DPIA completed for high-risk processing (profiling, special categories, monitoring)
247- [ ] Breach notification procedures documented (72-hour timeline)
248- [ ] DPAs executed with all processors (Article 28 requirements)
249- [ ] International transfers use SCCs 2021 + Transfer Impact Assessment
250- [ ] Security measures appropriate to risk (encryption, MFA, logging, testing)
251- [ ] Retention periods defined and automated deletion implemented
252- [ ] Privacy policy published and updated within 12 months
253- [ ] DPO designated if required (Article 37 criteria met)
254- [ ] Staff trained on GDPR principles and data subject rights
255