Compliance
GDPR checklist for software — twelve questions about what is in the code
A privacy policy is a document. GDPR in a system is concrete machinery: deleting data once retention expires, exporting everything about one person, restricted access to the production database. This checklist skips the paperwork layer and asks only about what can be verified in code and configuration.
Free · no signup · runs in your browser
Answer every question. The score updates as you go.
Plenty to do
Key pieces are not in place yet. Good that you are checking now rather than under deadline pressure.
Readiness
Readiness
0%
A weighted score - the data inventory and legal basis count for the most, because without them the rest is guesswork.
Answered
0 / 12
What to close, most important first
Answer every question to see the full gap list.
Want this fixed in the code, not just in the policy?
We run technical audits of systems covering security and data processing (from PLN 3,000), then implement the fixes. A human replies within 24 hours.
Estimate your project in 2 minHow it works
- 01
Answer 12 questions
Data inventory, legal basis, encryption, access, subprocessors, retention, data subject rights, backups, breach procedure, test data, consent and transfers outside the EEA.
- 02
See the weighted score
The data inventory and legal basis count for the most, because without them the other answers are guesswork.
- 03
Get a gap list
Each gap with a concrete hint on where to start. The list can be copied and handed to your team.
Assumptions and limits
- This is not legal advice or a compliance audit. It is a checklist for the technical layer, written from the perspective of a team that builds and maintains systems - for questions about interpreting the rules, consult a lawyer or your data protection officer.
- The checklist deliberately skips documentation (policies, privacy notices). Not because it does not matter, but because its existence says nothing about what the system actually does.
- A high score does not mean GDPR compliance. It means no obvious technical gaps are visible in the twelve most commonly neglected areas.
- All answers stay in your browser - nothing is sent or stored.
Frequently asked questions
Does this replace a GDPR audit? +
No. It is a checklist that shows where technical gaps most likely are, so that a conversation with a lawyer or DPO starts from specifics rather than from zero. A formal compliance audit is a separate, broader exercise.
Why does the data inventory count for the most? +
Because without answering "what data do we even have and why", every later answer is an unbacked claim. You cannot honestly set retention or a legal basis for a dataset nobody has listed.
We have a production copy in our test environment - is that a big problem? +
It is one of the most common and most easily fixed problems. Anonymising data on the way to non-production environments is usually a few days of work and removes an entire risk category.
Do you run technical audits of systems? +
Yes, a technical audit starts from PLN 3,000 and covers code, architecture and security, with a prioritised list of fixes. A human replies to your first message within 24 hours.
Related tools
All tools →KSeF readiness
Fourteen questions about systems, data and processes. You get a readiness score and a concrete list of gaps to close.
Data quality audit
Invalid tax IDs, duplicates, gaps and inconsistent formats in your database - a report in seconds, the file never leaves your browser.
Spec generator
Answer a dozen questions and download a ready Markdown brief that every vendor will read the same way.
Turn the numbers into a project
Get a ballpark instantly, a reply from a human within 24 hours and a firm quote after a short call. No obligation.
Estimate your project in 2 min