DATA PRIVACY READINESS CHECKLIST

Free Privacy Readiness Checklist

Complete this 24-question assessment to understand where your organization stands on data privacy — and receive a personalized report by email.

⏱ Takes under 30 minutes  ·  Instant results

01

Data Governance

Does your organization maintain a current inventory of all personal data you collect, store, and process?

Do you have documented data flows showing how personal data moves between systems and third parties?

Is there a designated privacy officer or responsible person for data protection in your organization?

Do you have a formal data retention and deletion policy that is actively enforced?

02

Regulatory Compliance

Have you identified which privacy regulations apply to your organization (GDPR, PIPEDA, Law 25, etc.)?

Do you have documented lawful bases for each category of personal data you process?

Is your privacy policy up to date, accessible, and written in plain language?

Do you have a process to handle data subject access requests within the required timeframes?

Can individuals exercise their rights (access, correction, deletion, portability) through a defined process?

03

Third-Party & Vendor Risk

Do you have Data Processing Agreements (DPAs) in place with all vendors who process personal data on your behalf?

Do you assess the privacy practices of new vendors before sharing personal data with them?

Do you know in which countries your vendors store or process the personal data you share with them?

04

Emerging Technology

Have you assessed the privacy risks of any AI or machine learning tools used in your organization?

Do you have a policy governing employee use of generative AI tools (e.g., ChatGPT, Copilot) with company data?

If you use cloud services, have you reviewed the shared responsibility model for privacy compliance?

If you collect biometric data (fingerprints, facial recognition), do you have explicit consent and a lawful basis for doing so?

Do you know where your cloud data is physically stored, and have you verified this meets your regulatory requirements?

05

Security Controls

Is personal data encrypted at rest and in transit across all your systems?

Do you enforce role-based access controls so that employees only access personal data relevant to their role?

Are access logs maintained and regularly reviewed for unauthorized access to personal data?

06

Incident Readiness

Do you have a documented data breach response plan that has been tested in the last 12 months?

Do you know your regulatory notification deadlines in the event of a breach (e.g., 72 hours under GDPR)?

Have all staff who handle personal data received privacy awareness training in the last 12 months?

Do you conduct regular privacy impact assessments before launching new products, services, or technology deployments?

By submitting this form you agree to be contacted by Strategy Up regarding your privacy readiness. We will never sell your data.