Answer honestly — this is a diagnostic, not an exam. Your result never leaves your browser.
1. Do you have a current, accurate Record of Processing Activities (RoPA)?
2. If a data subject request arrived today, what would happen?
3. How are DPIAs handled for new projects and systems?
4. How confident are you in your vendor and sub-processor privacy posture?
5. Is there a rehearsed breach notification playbook?
6. Who owns privacy accountability in your organisation?
7. How is privacy training handled across the organisation?
8. Could you produce audit-ready evidence of your privacy controls tomorrow?