Skip to content
Exmoor Software

Compliance

GDPR checklist for software — twelve questions about what is in the code

A privacy policy is a document. GDPR in a system is concrete machinery: deleting data once retention expires, exporting everything about one person, restricted access to the production database. This checklist skips the paperwork layer and asks only about what can be verified in code and configuration.

Free · no signup · runs in your browser

Answer every question. The score updates as you go.

  1. 1. You know exactly what personal data the system processes and for what purpose
  2. 2. Every category of data has a defined legal basis for processing
  3. 3. Data is encrypted in transit, and sensitive data also at rest
  4. 4. Access to production data is restricted and logged
  5. 5. You have processing agreements with your subprocessors: hosting, email, analytics
  6. 6. Retention periods are set and a deletion mechanism actually works
  7. 7. The system can fulfil data subject rights: access, rectification, erasure, portability
  8. 8. Backups are taken, tested, and covered by the same rules
  9. 9. There is a procedure for reporting a data breach within 72 hours
  10. 10. Test environments do not contain copies of real personal data
  11. 11. Consents are collected separately and are as easy to withdraw as to give
  12. 12. You know whether data leaves the EEA and on what basis

Plenty to do

Key pieces are not in place yet. Good that you are checking now rather than under deadline pressure.

Readiness

Readiness

0%

A weighted score - the data inventory and legal basis count for the most, because without them the rest is guesswork.

Answered

0 / 12

What to close, most important first

Answer every question to see the full gap list.

Want this fixed in the code, not just in the policy?

We run technical audits of systems covering security and data processing (from PLN 3,000), then implement the fixes. A human replies within 24 hours.

Estimate your project in 2 min

How it works

  1. 01

    Answer 12 questions

    Data inventory, legal basis, encryption, access, subprocessors, retention, data subject rights, backups, breach procedure, test data, consent and transfers outside the EEA.

  2. 02

    See the weighted score

    The data inventory and legal basis count for the most, because without them the other answers are guesswork.

  3. 03

    Get a gap list

    Each gap with a concrete hint on where to start. The list can be copied and handed to your team.

Assumptions and limits

  • This is not legal advice or a compliance audit. It is a checklist for the technical layer, written from the perspective of a team that builds and maintains systems - for questions about interpreting the rules, consult a lawyer or your data protection officer.
  • The checklist deliberately skips documentation (policies, privacy notices). Not because it does not matter, but because its existence says nothing about what the system actually does.
  • A high score does not mean GDPR compliance. It means no obvious technical gaps are visible in the twelve most commonly neglected areas.
  • All answers stay in your browser - nothing is sent or stored.

Frequently asked questions

Does this replace a GDPR audit? +

No. It is a checklist that shows where technical gaps most likely are, so that a conversation with a lawyer or DPO starts from specifics rather than from zero. A formal compliance audit is a separate, broader exercise.

Why does the data inventory count for the most? +

Because without answering "what data do we even have and why", every later answer is an unbacked claim. You cannot honestly set retention or a legal basis for a dataset nobody has listed.

We have a production copy in our test environment - is that a big problem? +

It is one of the most common and most easily fixed problems. Anonymising data on the way to non-production environments is usually a few days of work and removes an entire risk category.

Do you run technical audits of systems? +

Yes, a technical audit starts from PLN 3,000 and covers code, architecture and security, with a prioritised list of fixes. A human replies to your first message within 24 hours.

Turn the numbers into a project

Get a ballpark instantly, a reply from a human within 24 hours and a firm quote after a short call. No obligation.

Estimate your project in 2 min