Adds comprehensive GDPR compliance assessment skill covering Article 30 records, lawful basis validation, data subject rights, DPIAs, breach notification, international transfers, and technical/organizational measures. Features: - 295-line skill body (under 500-line cap) - 1008-char description with negative triggers (under 1024 limit) - 9 files total, all within skill directory - 3 production scripts: article30_parser.py, article30_validator.py, generate_ropa_report.py - Detailed workflow, templates, and references Negative triggers direct users to: - implementing-gdpr-data-protection-controls for Article 32 technical controls - implementing-gdpr-data-subject-access-request for DSAR automation Legal basis: EU Regulation 2016/679, UK GDPR as amended by Data Protection Act 2018 and Data (Use and Access) Act 2025. Effective date: August 2026. Validation: validate-skill.py PASS, lint-descriptions.py PASS
9.9 KiB
GDPR Compliance Scorecard Template
Use this template to assess and track GDPR compliance across all key areas. Replace [ORGANIZATION NAME] and fill in assessment results.
Organization Information
- Organization Name: [ORGANIZATION NAME]
- Assessment Date: [YYYY-MM-DD]
- Assessor: [Name, Role]
- Scope: [All EU operations / Specific business unit / Specific system]
- Next Review Date: [YYYY-MM-DD] (recommended: annual)
Executive Summary
| Metric | Score | Target | Status |
|---|---|---|---|
| Overall Compliance | __/100 | 100 | 🔴 / 🟡 / 🟢 |
| Critical Issues | __ | 0 | 🔴 / 🟡 / 🟢 |
| High Priority Gaps | __ | 0 | 🔴 / 🟡 / 🟢 |
| Medium Priority Gaps | __ | - | 🔴 / 🟡 / 🟢 |
Compliance Status Legend:
- 🟢 Compliant (≥90%): Minor gaps only
- 🟡 Partially Compliant (70-89%): Action required
- 🔴 Non-Compliant (<70%): Immediate remediation required
1. Territorial Applicability (Article 3)
| Check | Status | Evidence |
|---|---|---|
| EU establishment identified? | ☐ Yes ☐ No ☐ N/A | [Location/entity] |
| Targeting EU data subjects? | ☐ Yes ☐ No ☐ N/A | [Website/marketing evidence] |
| Monitoring EU data subjects? | ☐ Yes ☐ No ☐ N/A | [Tracking/profiling activities] |
| Article 27 representative (if non-EU)? | ☐ Yes ☐ No ☐ N/A | [Representative contact] |
Assessment: ☐ Applies ☐ Does not apply
Score: __/4
2. Article 30 Records of Processing (RoPA)
| Requirement | Status | Score | Notes |
|---|---|---|---|
| Written RoPA exists | ☐ Yes ☐ Partial ☐ No | __/10 | [Last updated: date] |
| All processing activities documented | ☐ Yes ☐ Partial ☐ No | __/10 | [X of Y activities] |
| Purposes specified | ☐ Yes ☐ Partial ☐ No | __/5 | |
| Data subjects categorized | ☐ Yes ☐ Partial ☐ No | __/5 | |
| Personal data categories listed | ☐ Yes ☐ Partial ☐ No | __/5 | |
| Recipients documented | ☐ Yes ☐ Partial ☐ No | __/5 | |
| Retention periods specified | ☐ Yes ☐ Partial ☐ No | __/10 | [Gap: __% missing] |
| International transfers documented | ☐ Yes ☐ Partial ☐ No ☐ N/A | __/5 | |
| Security measures described | ☐ Yes ☐ Partial ☐ No | __/5 |
Assessment Notes: [Key gaps identified]
Score: __/55 → __% compliant
3. Lawful Basis (Article 6)
| Check | Status | Evidence |
|---|---|---|
| Lawful basis identified for all processing | ☐ Yes ☐ Partial ☐ No | [X of Y activities] |
| Consent mechanisms valid (if used) | ☐ Yes ☐ Partial ☐ No ☐ N/A | [Consent tool: name] |
| Legitimate Interest Assessments (LIAs) conducted | ☐ Yes ☐ Partial ☐ No ☐ N/A | [X LIAs on file] |
| Special category data legal basis (Article 9) | ☐ Yes ☐ Partial ☐ No ☐ N/A | [Additional condition documented] |
Common Issues Found:
- Consent not freely given (bundled)
- "Legitimate interest" claimed without LIA
- Contract claimed for non-essential processing
- Special category data without explicit consent
Score: __/10
4. Data Subject Rights (Articles 12-23)
| Right | Capability | Response Time | Status |
|---|---|---|---|
| Right to be Informed (Art 13-14) | Privacy notices at collection | - | ☐ ✓ ☐ ✗ |
| Right of Access (Art 15) | DSAR process documented | __ days (≤30 required) | ☐ ✓ ☐ ✗ |
| Right to Rectification (Art 16) | Correction mechanism | __ days | ☐ ✓ ☐ ✗ |
| Right to Erasure (Art 17) | Deletion across all systems | __ days | ☐ ✓ ☐ ✗ |
| Right to Restrict Processing (Art 18) | Processing pause capability | __ days | ☐ ✓ ☐ ✗ |
| Right to Data Portability (Art 20) | CSV/JSON export | __ days | ☐ ✓ ☐ ✗ |
| Right to Object (Art 21) | Marketing opt-out | Immediate | ☐ ✓ ☐ ✗ |
| Automated Decision-Making (Art 22) | Human review process | ☐ Yes ☐ No ☐ N/A | ☐ ✓ ☐ ✗ |
DSAR Volume (last 12 months): __ requests
Average Response Time: __ days
Score: __/8 → __% implemented
5. Data Protection Impact Assessments (Article 35)
| Check | Status | Notes |
|---|---|---|
| High-risk processing identified | ☐ Yes ☐ No | [List activities requiring DPIA] |
| DPIAs conducted for mandatory cases | ☐ Yes ☐ Partial ☐ No | [X of Y required DPIAs completed] |
| DPIAs include necessity/proportionality | ☐ Yes ☐ Partial ☐ No | |
| Risks to data subjects assessed | ☐ Yes ☐ Partial ☐ No | |
| Mitigation measures documented | ☐ Yes ☐ Partial ☐ No | |
| DPO consulted (if designated) | ☐ Yes ☐ No ☐ N/A | |
| Supervisory authority consulted (if high residual risk) | ☐ Yes ☐ No ☐ N/A |
Mandatory DPIA Triggers:
- Large-scale processing of special category data
- Systematic monitoring of public areas
- Systematic extensive profiling
- Large-scale processing of biometric/genetic data
Score: __/7
6. Data Breach Procedures (Articles 33-34)
| Requirement | Status | Metric |
|---|---|---|
| Breach detection capability | ☐ Yes ☐ Partial ☐ No | Detection time: __ hours |
| Incident response plan documented | ☐ Yes ☐ No | [Last updated: date] |
| 72-hour notification process | ☐ Yes ☐ No | Current capability: __ hours |
| Breach register maintained (Art 33(5)) | ☐ Yes ☐ No | [X breaches in last 12 months] |
| Data subject notification process | ☐ Yes ☐ No | |
| Breach simulation/tabletop exercise | ☐ Yes ☐ No | [Last conducted: date] |
Last Breach: [Date or "None"]
Reported to Supervisory Authority: ☐ Yes ☐ No ☐ N/A
Within 72 Hours: ☐ Yes ☐ No ☐ N/A
Score: __/6
7. International Data Transfers (Chapter V)
| Transfer | Destination | Safeguard | Status |
|---|---|---|---|
| [Service/System 1] | [Country] | ☐ Adequacy ☐ SCCs ☐ BCRs ☐ None | ☐ ✓ ☐ ✗ |
| [Service/System 2] | [Country] | ☐ Adequacy ☐ SCCs ☐ BCRs ☐ None | ☐ ✓ ☐ ✗ |
| [Service/System 3] | [Country] | ☐ Adequacy ☐ SCCs ☐ BCRs ☐ None | ☐ ✓ ☐ ✗ |
Common Transfer Destinations:
- USA: ☐ Adequacy (Data Privacy Framework) ☐ SCCs ☐ None
- UK: ☐ Adequacy ☐ SCCs
- Other: [List countries]
SCCs in Use: ☐ 2021 version ☐ 2010 version (must update)
Transfer Impact Assessment (TIA) Conducted: ☐ Yes ☐ No (required for high-risk countries)
Score: __/10
8. Technical & Organizational Measures (Article 32)
| Security Control | Implemented | Evidence |
|---|---|---|
| Encryption at rest | ☐ Yes ☐ Partial ☐ No | [Algorithm: AES-256 / other] |
| Encryption in transit | ☐ Yes ☐ Partial ☐ No | [TLS 1.2+ / other] |
| Access control (least privilege) | ☐ Yes ☐ Partial ☐ No | [IAM tool] |
| Multi-factor authentication | ☐ Yes ☐ Partial ☐ No | [X% of users] |
| Audit logging | ☐ Yes ☐ Partial ☐ No | [Retention: X months] |
| Pseudonymization | ☐ Yes ☐ Partial ☐ No ☐ N/A | [Where implemented] |
| Backup and recovery | ☐ Yes ☐ Partial ☐ No | [RPO: __ / RTO: __] |
| Vulnerability scanning | ☐ Yes ☐ Partial ☐ No | [Frequency: quarterly / monthly] |
| Penetration testing | ☐ Yes ☐ No | [Last conducted: date] |
| Security awareness training | ☐ Yes ☐ Partial ☐ No | [X% of staff trained] |
Score: __/10
9. Processor Management (Article 28)
| Requirement | Status | Notes |
|---|---|---|
| List of all processors maintained | ☐ Yes ☐ Partial ☐ No | [X processors identified] |
| Data Processing Agreements (DPAs) signed | ☐ Yes ☐ Partial ☐ No | [__% coverage] |
| DPAs contain all Article 28(3) requirements | ☐ Yes ☐ Partial ☐ No | |
| Sub-processor list disclosed | ☐ Yes ☐ Partial ☐ No | |
| Sub-processor approval mechanism | ☐ Yes ☐ No | |
| Processor audits conducted | ☐ Yes ☐ No | [Last audit: date] |
Score: __/6
10. Data Protection Officer (Articles 37-39)
| Check | Status | Notes |
|---|---|---|
| DPO designation required? | ☐ Yes ☐ No | [Public authority / large-scale / special categories] |
| DPO designated | ☐ Yes ☐ No ☐ N/A | [Name: / Contact:] |
| DPO contact published | ☐ Yes ☐ No ☐ N/A | [Privacy policy / website] |
| DPO independence ensured | ☐ Yes ☐ No ☐ N/A | [No conflict of interest] |
| DPO involved in compliance matters | ☐ Yes ☐ No ☐ N/A |
Score: __/5 (or N/A if not required)
Overall Compliance Score
| Category | Weight | Score | Weighted Score |
|---|---|---|---|
| Article 30 RoPA | 20% | __% | __ |
| Lawful Basis | 15% | __% | __ |
| Data Subject Rights | 15% | __% | __ |
| DPIAs | 10% | __% | __ |
| Breach Procedures | 10% | __% | __ |
| International Transfers | 10% | __% | __ |
| Security Measures (Art 32) | 10% | __% | __ |
| Processor Management | 5% | __% | __ |
| DPO (if required) | 5% | __% | __ |
| TOTAL | 100% | - | __/100 |
Overall Assessment: 🔴 / 🟡 / 🟢
Priority Action Items
🔴 Critical (Immediate - 0-30 days)
- [Item]
- [Item]
🟡 High Priority (1-3 months)
- [Item]
- [Item]
🟠 Medium Priority (3-6 months)
- [Item]
- [Item]
Recommendations
-
Short-term (0-3 months):
- [Recommendation]
-
Medium-term (3-6 months):
- [Recommendation]
-
Long-term (6-12 months):
- [Recommendation]
Sign-off
Assessed by: ________________________ Date: __________
Reviewed by (DPO): ________________________ Date: __________
Approved by (Senior Management): ________________________ Date: __________
This scorecard provides a snapshot of GDPR compliance status. It should be reviewed and updated at least annually or when significant changes occur in data processing activities.