# GDPR Compliance Scorecard Template > Use this template to assess and track GDPR compliance across all key areas. > Replace [ORGANIZATION NAME] and fill in assessment results. ## Organization Information - **Organization Name**: [ORGANIZATION NAME] - **Assessment Date**: [YYYY-MM-DD] - **Assessor**: [Name, Role] - **Scope**: [All EU operations / Specific business unit / Specific system] - **Next Review Date**: [YYYY-MM-DD] (recommended: annual) --- ## Executive Summary | Metric | Score | Target | Status | |--------|-------|--------|--------| | Overall Compliance | __/100 | 100 | 🔴 / 🟡 / 🟢 | | Critical Issues | __ | 0 | 🔴 / 🟡 / 🟢 | | High Priority Gaps | __ | 0 | 🔴 / 🟡 / 🟢 | | Medium Priority Gaps | __ | - | 🔴 / 🟡 / 🟢 | **Compliance Status Legend**: - 🟢 **Compliant** (≥90%): Minor gaps only - 🟡 **Partially Compliant** (70-89%): Action required - 🔴 **Non-Compliant** (<70%): Immediate remediation required --- ## 1. Territorial Applicability (Article 3) | Check | Status | Evidence | |-------|--------|----------| | EU establishment identified? | ☐ Yes ☐ No ☐ N/A | [Location/entity] | | Targeting EU data subjects? | ☐ Yes ☐ No ☐ N/A | [Website/marketing evidence] | | Monitoring EU data subjects? | ☐ Yes ☐ No ☐ N/A | [Tracking/profiling activities] | | Article 27 representative (if non-EU)? | ☐ Yes ☐ No ☐ N/A | [Representative contact] | **Assessment**: ☐ Applies ☐ Does not apply **Score**: __/4 --- ## 2. Article 30 Records of Processing (RoPA) | Requirement | Status | Score | Notes | |-------------|--------|-------|-------| | Written RoPA exists | ☐ Yes ☐ Partial ☐ No | __/10 | [Last updated: date] | | All processing activities documented | ☐ Yes ☐ Partial ☐ No | __/10 | [X of Y activities] | | Purposes specified | ☐ Yes ☐ Partial ☐ No | __/5 | | | Data subjects categorized | ☐ Yes ☐ Partial ☐ No | __/5 | | | Personal data categories listed | ☐ Yes ☐ Partial ☐ No | __/5 | | | Recipients documented | ☐ Yes ☐ Partial ☐ No | __/5 | | | Retention periods specified | ☐ Yes ☐ Partial ☐ No | __/10 | [Gap: __% missing] | | International transfers documented | ☐ Yes ☐ Partial ☐ No ☐ N/A | __/5 | | | Security measures described | ☐ Yes ☐ Partial ☐ No | __/5 | | **Assessment Notes**: [Key gaps identified] **Score**: __/55 → __% compliant --- ## 3. Lawful Basis (Article 6) | Check | Status | Evidence | |-------|--------|----------| | Lawful basis identified for all processing | ☐ Yes ☐ Partial ☐ No | [X of Y activities] | | Consent mechanisms valid (if used) | ☐ Yes ☐ Partial ☐ No ☐ N/A | [Consent tool: name] | | Legitimate Interest Assessments (LIAs) conducted | ☐ Yes ☐ Partial ☐ No ☐ N/A | [X LIAs on file] | | Special category data legal basis (Article 9) | ☐ Yes ☐ Partial ☐ No ☐ N/A | [Additional condition documented] | **Common Issues Found**: - [ ] Consent not freely given (bundled) - [ ] "Legitimate interest" claimed without LIA - [ ] Contract claimed for non-essential processing - [ ] Special category data without explicit consent **Score**: __/10 --- ## 4. Data Subject Rights (Articles 12-23) | Right | Capability | Response Time | Status | |-------|------------|---------------|--------| | **Right to be Informed** (Art 13-14) | Privacy notices at collection | - | ☐ ✓ ☐ ✗ | | **Right of Access** (Art 15) | DSAR process documented | __ days (≤30 required) | ☐ ✓ ☐ ✗ | | **Right to Rectification** (Art 16) | Correction mechanism | __ days | ☐ ✓ ☐ ✗ | | **Right to Erasure** (Art 17) | Deletion across all systems | __ days | ☐ ✓ ☐ ✗ | | **Right to Restrict Processing** (Art 18) | Processing pause capability | __ days | ☐ ✓ ☐ ✗ | | **Right to Data Portability** (Art 20) | CSV/JSON export | __ days | ☐ ✓ ☐ ✗ | | **Right to Object** (Art 21) | Marketing opt-out | Immediate | ☐ ✓ ☐ ✗ | | **Automated Decision-Making** (Art 22) | Human review process | ☐ Yes ☐ No ☐ N/A | ☐ ✓ ☐ ✗ | **DSAR Volume (last 12 months)**: __ requests **Average Response Time**: __ days **Score**: __/8 → __% implemented --- ## 5. Data Protection Impact Assessments (Article 35) | Check | Status | Notes | |-------|--------|-------| | High-risk processing identified | ☐ Yes ☐ No | [List activities requiring DPIA] | | DPIAs conducted for mandatory cases | ☐ Yes ☐ Partial ☐ No | [X of Y required DPIAs completed] | | DPIAs include necessity/proportionality | ☐ Yes ☐ Partial ☐ No | | | Risks to data subjects assessed | ☐ Yes ☐ Partial ☐ No | | | Mitigation measures documented | ☐ Yes ☐ Partial ☐ No | | | DPO consulted (if designated) | ☐ Yes ☐ No ☐ N/A | | | Supervisory authority consulted (if high residual risk) | ☐ Yes ☐ No ☐ N/A | | **Mandatory DPIA Triggers**: - [ ] Large-scale processing of special category data - [ ] Systematic monitoring of public areas - [ ] Systematic extensive profiling - [ ] Large-scale processing of biometric/genetic data **Score**: __/7 --- ## 6. Data Breach Procedures (Articles 33-34) | Requirement | Status | Metric | |-------------|--------|--------| | Breach detection capability | ☐ Yes ☐ Partial ☐ No | Detection time: __ hours | | Incident response plan documented | ☐ Yes ☐ No | [Last updated: date] | | 72-hour notification process | ☐ Yes ☐ No | Current capability: __ hours | | Breach register maintained (Art 33(5)) | ☐ Yes ☐ No | [X breaches in last 12 months] | | Data subject notification process | ☐ Yes ☐ No | | | Breach simulation/tabletop exercise | ☐ Yes ☐ No | [Last conducted: date] | **Last Breach**: [Date or "None"] **Reported to Supervisory Authority**: ☐ Yes ☐ No ☐ N/A **Within 72 Hours**: ☐ Yes ☐ No ☐ N/A **Score**: __/6 --- ## 7. International Data Transfers (Chapter V) | Transfer | Destination | Safeguard | Status | |----------|-------------|-----------|--------| | [Service/System 1] | [Country] | ☐ Adequacy ☐ SCCs ☐ BCRs ☐ None | ☐ ✓ ☐ ✗ | | [Service/System 2] | [Country] | ☐ Adequacy ☐ SCCs ☐ BCRs ☐ None | ☐ ✓ ☐ ✗ | | [Service/System 3] | [Country] | ☐ Adequacy ☐ SCCs ☐ BCRs ☐ None | ☐ ✓ ☐ ✗ | **Common Transfer Destinations**: - USA: ☐ Adequacy (Data Privacy Framework) ☐ SCCs ☐ None - UK: ☐ Adequacy ☐ SCCs - Other: [List countries] **SCCs in Use**: ☐ 2021 version ☐ 2010 version (must update) **Transfer Impact Assessment (TIA) Conducted**: ☐ Yes ☐ No (required for high-risk countries) **Score**: __/10 --- ## 8. Technical & Organizational Measures (Article 32) | Security Control | Implemented | Evidence | |------------------|-------------|----------| | Encryption at rest | ☐ Yes ☐ Partial ☐ No | [Algorithm: AES-256 / other] | | Encryption in transit | ☐ Yes ☐ Partial ☐ No | [TLS 1.2+ / other] | | Access control (least privilege) | ☐ Yes ☐ Partial ☐ No | [IAM tool] | | Multi-factor authentication | ☐ Yes ☐ Partial ☐ No | [X% of users] | | Audit logging | ☐ Yes ☐ Partial ☐ No | [Retention: X months] | | Pseudonymization | ☐ Yes ☐ Partial ☐ No ☐ N/A | [Where implemented] | | Backup and recovery | ☐ Yes ☐ Partial ☐ No | [RPO: __ / RTO: __] | | Vulnerability scanning | ☐ Yes ☐ Partial ☐ No | [Frequency: quarterly / monthly] | | Penetration testing | ☐ Yes ☐ No | [Last conducted: date] | | Security awareness training | ☐ Yes ☐ Partial ☐ No | [X% of staff trained] | **Score**: __/10 --- ## 9. Processor Management (Article 28) | Requirement | Status | Notes | |-------------|--------|-------| | List of all processors maintained | ☐ Yes ☐ Partial ☐ No | [X processors identified] | | Data Processing Agreements (DPAs) signed | ☐ Yes ☐ Partial ☐ No | [__% coverage] | | DPAs contain all Article 28(3) requirements | ☐ Yes ☐ Partial ☐ No | | | Sub-processor list disclosed | ☐ Yes ☐ Partial ☐ No | | | Sub-processor approval mechanism | ☐ Yes ☐ No | | | Processor audits conducted | ☐ Yes ☐ No | [Last audit: date] | **Score**: __/6 --- ## 10. Data Protection Officer (Articles 37-39) | Check | Status | Notes | |-------|--------|-------| | DPO designation required? | ☐ Yes ☐ No | [Public authority / large-scale / special categories] | | DPO designated | ☐ Yes ☐ No ☐ N/A | [Name: / Contact:] | | DPO contact published | ☐ Yes ☐ No ☐ N/A | [Privacy policy / website] | | DPO independence ensured | ☐ Yes ☐ No ☐ N/A | [No conflict of interest] | | DPO involved in compliance matters | ☐ Yes ☐ No ☐ N/A | | **Score**: __/5 (or N/A if not required) --- ## Overall Compliance Score | Category | Weight | Score | Weighted Score | |----------|--------|-------|----------------| | Article 30 RoPA | 20% | __% | __ | | Lawful Basis | 15% | __% | __ | | Data Subject Rights | 15% | __% | __ | | DPIAs | 10% | __% | __ | | Breach Procedures | 10% | __% | __ | | International Transfers | 10% | __% | __ | | Security Measures (Art 32) | 10% | __% | __ | | Processor Management | 5% | __% | __ | | DPO (if required) | 5% | __% | __ | | **TOTAL** | **100%** | - | **__/100** | **Overall Assessment**: 🔴 / 🟡 / 🟢 --- ## Priority Action Items ### 🔴 Critical (Immediate - 0-30 days) 1. [Item] 2. [Item] ### 🟡 High Priority (1-3 months) 1. [Item] 2. [Item] ### 🟠 Medium Priority (3-6 months) 1. [Item] 2. [Item] --- ## Recommendations 1. **Short-term** (0-3 months): - [Recommendation] 2. **Medium-term** (3-6 months): - [Recommendation] 3. **Long-term** (6-12 months): - [Recommendation] --- ## Sign-off **Assessed by**: ________________________ Date: __________ **Reviewed by (DPO)**: ________________________ Date: __________ **Approved by (Senior Management)**: ________________________ Date: __________ --- *This scorecard provides a snapshot of GDPR compliance status. It should be reviewed and updated at least annually or when significant changes occur in data processing activities.*