GDPR self-test: 20 questions on the basics

Are your GDPR basics in place? A self-test in 20 questions

20 questions in five areas show whether the basics of your GDPR work are in place. Takes 15 minutes and shows the result straight away, red to green.

Summary: 20 questions in five areas show whether the basics of your data protection work are in place: responsibility and governance, overview of processing, information and rights, suppliers and security, and risks, breaches and follow-up. The self-test takes about 15 minutes, and the result appears straight away on a scale from red to green, with suggestions for what to do next. It is an indication, not an audit.

About this guide

Who it is for
Organisations that process personal data and want to know whether the GDPR basics are in place.
What you get
A self-test in five areas with four questions each, which covers the 15 parts into which we divide GDPR work, takes 15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.

The questions cover the 15 parts into which we divide GDPR work. Answer yes only if you can show it, for example with a document, a procedure or a decision. “It should exist” counts as no. Choose Yes, No or Don’t know for each question, and the result appears straight away on the page. If you are reading without the buttons, count the yes answers in each area.

Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.

Area 1: Responsibility and governance

  1. Has it been decided who owns the data protection work and who in management follows it up? (Article 24)
  2. Have you assessed whether you must appoint a data protection officer, and documented the assessment? (Article 37)
  3. Is there a data protection policy adopted by management, and procedures that those concerned know about? (Article 24(2))
  4. Do those who handle personal data know the rules, for example through recurring training?

Area 2: Overview of processing

  1. Do you have a record of processing activities that has been updated in the past year? (Article 30)
  2. Do you know in which systems and with which suppliers the personal data is held?
  3. Is a legal basis documented for each processing activity, and for sensitive personal data or data on criminal offences also a basis under Article 9 or 10? (Articles 6, 9 and 10)
  4. Have you decided how long the data is kept, and is it deleted when that time has passed? (Article 5(1)(e))

On the record: the exemption for organisations with fewer than 250 employees does not apply when processing is not occasional, and it almost never is, for example for payroll and customer records. Most organisations therefore need a record.

Area 3: Information and rights

  1. Do data subjects receive information about the processing when you collect the data, for example in a privacy notice? (Articles 13 and 14)
  2. Is there a procedure for answering a request for access, rectification or erasure within one month? (Article 12)
  3. Can you show when and how consent was given, and can it be withdrawn as easily as it was given? (Article 7)
  4. Can website visitors choose whether to accept cookies other than the necessary ones? (Swedish Electronic Communications Act, Chapter 9, Section 28 – 9 kap. 28 §)

Area 4: Suppliers and security

  1. Do you have data processing agreements with all suppliers that process personal data on your behalf? (Article 28)
  2. Is there a valid basis for each transfer outside the EU/EEA, for example Standard Contractual Clauses, and a transfer impact assessment where one is required? (Chapter V)
  3. Is access to personal data limited to those who need it in their work?
  4. Are the security measures proportionate to the risks, for example multi-factor authentication and backups? (Article 32)

Area 5: Risks, breaches and follow-up

  1. Is an impact assessment carried out when a new processing activity may involve high risk? (Article 35)
  2. Is there a personal data breach procedure so that you can notify IMY within 72 hours when required? (Article 33)
  3. Are all personal data breaches documented, including those not notified? (Article 33(5))
  4. Do you check that the procedures work, and does management receive a report on data protection at least once per year?

Interpreting the result

  • Solid foundation, 18–20 yes: the basics are in place. Keep them up to date as the business changes.
  • Nearly there, 14–17 yes: most of it is in place, and the gaps can usually be closed with a procedure or a decision.
  • Clear gaps, 10–13 yes: the foundation is partly there, but several parts are missing and should be prioritised.
  • Foundation missing, 9 yes or fewer: start with responsibility, the record, information to data subjects and a breach procedure.

The same scale applies per area: four yes is a solid foundation, three nearly there, two clear gaps, and one or none means the foundation is missing.

The self-test is an indication. It shows whether the basics seem to be there, not that you comply with the GDPR. A current state analysis assesses each requirement with evidence. If you answer no or don’t know to the questions on legal basis, data processing agreements, transfers outside the EU/EEA, impact assessment or breach procedure, it should be looked into even if the total looks good.

What to do next

Would you like to go through the result with us? Read about the 15 parts and our work with data protection and privacy or contact us.

Sources: Regulation (EU) 2016/679 (GDPR), Articles 5–7, 9, 10, 12–14, 24, 28, 30, 32, 33, 35 and 37 and Chapter V; Swedish Electronic Communications Act (2022:482), Chapter 9, Section 28 (9 kap. 28 §); Swedish Authority for Privacy Protection (IMY), guidance on the GDPR. Fact-checked on 4 October 2026.

This text is general information and does not constitute legal advice in an individual matter.