All frameworks

Regulation (EU) 2016/679

GDPR readiness assessment

Turn scattered privacy records into an evidence-backed view of readiness.

A catalogue of GDPR obligations (48) across Articles 5–49, versioned with provenance.

48 obligation entries · versioned & change-controlled

Who it’s for

Data protection officers, privacy and legal teams, and any organisation processing EU personal data.

What readiness means for GDPR

For GDPR, readiness means each applicable obligation (Articles 5–49) is substantiated by current evidence — a maintained ROPA, completed DPIAs, lawful bases, and processor terms — not a one-off policy.

How Netallion handles it

Your GDPR readiness journey

  1. 1

    Scope processing & lawful basis

    Build from your record of processing activities: each processing activity is anchored to a lawful basis and the applicable obligations across Articles 5–49 for your role as controller or processor.

  2. 2

    Map evidence to obligations

    Attach the RoPA, DPIAs, privacy notices, processor terms and retention schedules to the obligations they substantiate, with ownership and review dates.

  3. 3

    Assess substantiation

    Each obligation is assessed for whether the evidence actually substantiates it — a lawful basis recorded, a DPIA completed where required, a processor bound by Article 28 terms — not merely a policy on file.

  4. 4

    Surface blockers

    Obligations with missing or stale evidence — an activity with no lawful basis, a transfer with no safeguard — become explicit, ranked blockers.

  5. 5

    Review & finalise

    An authorised assessor reviews the determinations and finalises a readiness conclusion pinned to your processing at a point in time; where certification is sought it is issued by an accredited body, not by Netallion.

The control library

What the GDPR library gives you

A catalogue of GDPR obligations (48) across Articles 5–49, versioned with provenance.

A curated, versioned catalogue of this framework’s 48 obligation entries — with provenance — to collect, own, organise and track the currency of your evidence against.

From the field

Common GDPR blockers we find

Where evidence most often falls short — surfaced explicitly, not averaged away.

  • The RoPA exists but one processing activity has no lawful basis recorded against it.
  • A DSAR procedure is documented but there is no log evidencing requests were fulfilled within the statutory month.
  • A processor is engaged but no Article 28 data-processing agreement is on file, or it predates the current processing.
  • A retention schedule is published but there is no deletion evidence showing it is actually applied.

Evidence

The evidence you'll bring

You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:

Records & lawful basis

  • record of processing activities (RoPA)
  • lawful-basis register
  • consent records
  • legitimate-interest assessments

Rights & requests

  • DSAR handling procedure & logs
  • erasure/rectification records
  • privacy notices
  • children's-data handling

Processors & transfers

  • Article 28 data-processing agreements
  • sub-processor list
  • transfer mechanisms (SCCs/adequacy)
  • transfer impact assessments

Breach & retention

  • breach register & 72-hour notification records
  • retention schedule & deletion evidence
  • DPIAs
  • records of DPO engagement

Start now — free

Prepare your GDPR evidence

Free — generate now

GDPR Readiness Kit

Netallion-authored templates and registers to prepare your GDPR evidence — generated instantly, no sign-up. Then organise that evidence in Netallion and assess whether it’s sufficient.

  • DPIA template
  • Privacy notice template
  • GDPR reference guide
  • RoPA, DSR, breach, processor & retention registers (CSV)

No email required. Free to download and use.

From evidence to a conclusion

How readiness is reached

The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.

  1. 1Scope

    The applicable requirement set for your framework and scope.

  2. 2Applicable requirements

    A fixed denominator — every in-scope requirement counts.

  3. 3Evidence

    You attach and own evidence; ownership and expiry are tracked.

  4. 4Evidence assessment

    The evidence is read against each requirement for sufficiency.

  5. 5Determination

    A requirement-level verdict with byte-verified citations.

  6. 6Blocker

    Negative findings surface as explicit blockers, not averages.

  7. 7Remediation

    Track the fix; reassessment — not a checkbox — resolves it.

  8. 8Review (R0–R3)

    Controlled human review with recorded provenance.

  9. 9Finalisation

    A signed, scope-pinned readiness conclusion.

  10. 10Report / export

    Readiness report, evidence index, SoA, audit ZIP + SHA-256.

  11. 11Lifecycle & reassessment

    Evidence expires/changes → affected requirements reopen.

Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.

What you get out

  • Requirement-level readiness across all 48 GDPR obligations (Articles 5–49)
  • RoPA-anchored lawful-basis view
  • explicit blocker list with reasons
  • evidence index + audit ZIP with SHA-256 manifest

FAQ

GDPR readiness — common questions

Does Netallion make us GDPR compliant?

No tool can declare an organisation compliant. Netallion assesses whether your evidence substantiates each GDPR obligation and surfaces where it falls short. Where certification is sought, it is issued by an accredited body under Articles 42–43.

What GDPR evidence does Netallion assess?

Records of processing (ROPA), DPIAs, consent and lawful-basis records, data-processing agreements, and breach records, among others — against 48 obligation-level criteria.

Does readiness stay current as our processing changes?

On assessed engagements, when tracked evidence expires, is withdrawn or superseded, the affected requirements reopen so a stale conclusion is never presented as current.

Related

Cross-framework leverage

Evidence you assemble for one framework often supports another. Commonly paired with:

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. GDPR certification, where sought, is issued by an accredited body under Articles 42–43; supervisory authority rests with the relevant DPA. Where the boundary sits.

See what your GDPR evidence proves

See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.