Published · Last updated
Summary: 20 questions in five areas show whether the basics of your data protection work are in place: responsibility and governance, overview of processing, information and rights, suppliers and security, and risks, breaches and follow-up. The self-test takes about 15 minutes, and the result appears straight away on a scale from red to green, with suggestions for what to do next. It is an indication, not an audit.
About this guide
- Who it is for
- Organisations that process personal data and want to know whether the GDPR basics are in place.
- What you get
- A self-test in five areas with four questions each, which covers the 15 parts into which we divide GDPR work, takes 15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.
The questions cover the 15 parts into which we divide GDPR work. Answer yes only if you can show it, for example with a document, a procedure or a decision. “It should exist” counts as no. Choose Yes, No or Don’t know for each question, and the result appears straight away on the page. If you are reading without the buttons, count the yes answers in each area.
Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.
Area 1: Responsibility and governance
- Has it been decided who owns the data protection work and who in management follows it up? (Article 24)
- Have you assessed whether you must appoint a data protection officer, and documented the assessment? (Article 37)
- Is there a data protection policy adopted by management, and procedures that those concerned know about? (Article 24(2))
- Do those who handle personal data know the rules, for example through recurring training?
Area 2: Overview of processing
- Do you have a record of processing activities that has been updated in the past year? (Article 30)
- Do you know in which systems and with which suppliers the personal data is held?
- Is a legal basis documented for each processing activity, and for sensitive personal data or data on criminal offences also a basis under Article 9 or 10? (Articles 6, 9 and 10)
- Have you decided how long the data is kept, and is it deleted when that time has passed? (Article 5(1)(e))
On the record: the exemption for organisations with fewer than 250 employees does not apply when processing is not occasional, and it almost never is, for example for payroll and customer records. Most organisations therefore need a record.
Area 3: Information and rights
- Do data subjects receive information about the processing when you collect the data, for example in a privacy notice? (Articles 13 and 14)
- Is there a procedure for answering a request for access, rectification or erasure within one month? (Article 12)
- Can you show when and how consent was given, and can it be withdrawn as easily as it was given? (Article 7)
- Can website visitors choose whether to accept cookies other than the necessary ones? (Swedish Electronic Communications Act, Chapter 9, Section 28 – 9 kap. 28 §)
Area 4: Suppliers and security
- Do you have data processing agreements with all suppliers that process personal data on your behalf? (Article 28)
- Is there a valid basis for each transfer outside the EU/EEA, for example Standard Contractual Clauses, and a transfer impact assessment where one is required? (Chapter V)
- Is access to personal data limited to those who need it in their work?
- Are the security measures proportionate to the risks, for example multi-factor authentication and backups? (Article 32)
Area 5: Risks, breaches and follow-up
- Is an impact assessment carried out when a new processing activity may involve high risk? (Article 35)
- Is there a personal data breach procedure so that you can notify IMY within 72 hours when required? (Article 33)
- Are all personal data breaches documented, including those not notified? (Article 33(5))
- Do you check that the procedures work, and does management receive a report on data protection at least once per year?
- Several of the basics are missing. Start with what has the greatest effect: responsibility, the record, information to data subjects and a breach procedure.
- The foundation is partly there, but several parts are missing. Prioritise the areas with two yes answers or fewer.
- Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision.
- The basics are in place. Keep them up to date as the business, the systems and the suppliers change.
- GDPR Start We start with a current state analysis and take you to a working baseline: records, privacy information, policy, procedures and training.
- GDPR current-state and gap analysis A documented current state, gaps per requirement and a prioritised action plan.
- Ongoing GDPR support Support for records, agreements, questions and new systems, from a few hours a quarter.
- External data protection officer (DPO) We assess whether you must appoint one and take the role, or support the person you appoint.
- Impact assessment (DPIA) DPIAs for high-risk processing, and data protection built into new systems.
- Personal data breaches A breach procedure with roles and a flow for notification within 72 hours, an exercise and a breach log.
- Data processing agreements and suppliers Reviewed agreements, risk-assessed suppliers and a basis for each transfer.
- Website review: cookies and public privacy notice Cookies, the consent banner, the public privacy notice and forms, with a prioritised list of fixes.
Would you like to go through the result with us?
Fill in your details and we will be in touch. The result in the box below is sent with the form, exactly as it reads there. We use the details only to contact you about the result and keep them for one year. Read more in our privacy notice.
Interpreting the result
- Solid foundation, 18–20 yes: the basics are in place. Keep them up to date as the business changes.
- Nearly there, 14–17 yes: most of it is in place, and the gaps can usually be closed with a procedure or a decision.
- Clear gaps, 10–13 yes: the foundation is partly there, but several parts are missing and should be prioritised.
- Foundation missing, 9 yes or fewer: start with responsibility, the record, information to data subjects and a breach procedure.
The same scale applies per area: four yes is a solid foundation, three nearly there, two clear gaps, and one or none means the foundation is missing.
The self-test is an indication. It shows whether the basics seem to be there, not that you comply with the GDPR. A current state analysis assesses each requirement with evidence. If you answer no or don’t know to the questions on legal basis, data processing agreements, transfers outside the EU/EEA, impact assessment or breach procedure, it should be looked into even if the total looks good.
What to do next
- Two yes or fewer in at least two areas: start with GDPR Start, which takes you to a working baseline, or with a GDPR current state analysis if you first want a documented basis.
- Gaps in single areas: close them yourselves or with ongoing GDPR support, from a few hours a quarter.
- No to the question about a data protection officer: read When does an organisation need a data protection officer? and about an external data protection officer.
- Solid foundation: plan a recurring review, for example once per year, so that the foundation holds as the business changes.
Would you like to go through the result with us? Read about the 15 parts and our work with data protection and privacy or contact us.
Sources: Regulation (EU) 2016/679 (GDPR), Articles 5–7, 9, 10, 12–14, 24, 28, 30, 32, 33, 35 and 37 and Chapter V; Swedish Electronic Communications Act (2022:482), Chapter 9, Section 28 (9 kap. 28 §); Swedish Authority for Privacy Protection (IMY), guidance on the GDPR. Fact-checked on 4 October 2026.
This text is general information and does not constitute legal advice in an individual matter.

