Assign privacy ownership
HighName the person or team responsible for privacy governance, escalation and periodic review.
Business & Compliance Tools
Review practical privacy controls across governance, data mapping, transparency, individual rights, retention, vendors, security and international transfers. Mark each control, record evidence or actions, then export the assessment for follow-up.
Choose a focus to surface the most relevant operational questions. Applicability depends on your organisation, activities, users, location and current law.
Readiness
0%
Completed applicable items
Completed
0/19
Excludes N/A
Open gaps
19
Needs review
High priority
13
Open high-priority items
Name the person or team responsible for privacy governance, escalation and periodic review.
Keep internal rules for handling personal information, approvals, retention and incident response current.
Provide role-appropriate privacy and security training and record completion where your organisation requires it.
Document what personal data you collect, where it comes from, why it is used, where it is stored and who receives it.
Flag data requiring stronger controls, such as precise identifiers, financial information, health-related data, children’s data or other sensitive categories.
Collect and retain only the personal data that is reasonably needed for the stated purpose.
Record the business purpose for each material use of personal data and review incompatible secondary uses.
Make consent specific, informed and genuinely optional where the applicable rule requires consent, and retain evidence when appropriate.
Explain who you are, what data is collected, purposes, sharing, retention and user choices in clear language.
Know which trackers run, their purpose, provider, lifespan and whether optional technologies are controlled by user choice where required.
Define intake, identity verification, ownership, deadlines, exemptions, fulfilment and recordkeeping for applicable privacy requests.
Set retention rules based on purpose, legal obligations and operational need rather than keeping personal data indefinitely.
Ensure retention/deletion rules are reflected in production systems, archives and vendor workflows where practicable.
List service providers that receive or access personal data and understand what they do with it.
Review processor/service-provider terms, confidentiality, security, assistance obligations and data return/deletion provisions as applicable.
Use access control, least privilege, encryption where appropriate, secure development, patching, logging and tested recovery controls.
Define detection, containment, assessment, evidence preservation, decision ownership and external communication steps.
Review new products, data uses and material changes before launch, including data minimisation and default settings.
Use a documented privacy impact / risk assessment process for processing that may create elevated risk.
This workspace is a general operational self-assessment. It does not determine whether a law applies to you, cover every legal requirement, replace a data protection impact assessment, or certify compliance. Privacy laws and regulator guidance change; verify obligations with current official guidance and qualified counsel where necessary.
Start with the general checklist if you want an operational privacy baseline. Use the EU, UK or California focus to surface additional questions commonly associated with those regimes. Mark a control as Done only when you have reasonable evidence that the process exists and is being followed; use N/A only after considering why the item does not apply.
The score is a progress indicator, not a legal compliance score. A single unresolved high-risk issue can matter more than several completed administrative items, so use the high-priority gap count and notes to plan follow-up work.
This tool intentionally avoids making an automatic legal determination. Applicability and required controls depend on facts such as your organisation, location, users, processing purposes, data categories and current law.
Assessment data stays in the current browser session unless you choose to copy, print or download it. The page does not need an account or backend database for this workflow.
Related: FormatForge Privacy Policy · Quality Standards · Business & Invoice Tools