Regulation (EU) 2016/679
GDPR readiness assessment
Turn scattered privacy records into an evidence-backed view of readiness.
A catalogue of GDPR obligations (48) across Articles 5–49, versioned with provenance.
48 obligation entries · versioned & change-controlled
Who it’s for
Data protection officers, privacy and legal teams, and any organisation processing EU personal data.
What readiness means for GDPR
For GDPR, readiness means each applicable obligation (Articles 5–49) is substantiated by current evidence — a maintained ROPA, completed DPIAs, lawful bases, and processor terms — not a one-off policy.
How Netallion handles it
Your GDPR readiness journey
- 1
Scope processing & lawful basis
Build from your record of processing activities: each processing activity is anchored to a lawful basis and the applicable obligations across Articles 5–49 for your role as controller or processor.
- 2
Map evidence to obligations
Attach the RoPA, DPIAs, privacy notices, processor terms and retention schedules to the obligations they substantiate, with ownership and review dates.
- 3
Assess substantiation
Each obligation is assessed for whether the evidence actually substantiates it — a lawful basis recorded, a DPIA completed where required, a processor bound by Article 28 terms — not merely a policy on file.
- 4
Surface blockers
Obligations with missing or stale evidence — an activity with no lawful basis, a transfer with no safeguard — become explicit, ranked blockers.
- 5
Review & finalise
An authorised assessor reviews the determinations and finalises a readiness conclusion pinned to your processing at a point in time; where certification is sought it is issued by an accredited body, not by Netallion.
The control library
What the GDPR library gives you
A catalogue of GDPR obligations (48) across Articles 5–49, versioned with provenance.
A curated, versioned catalogue of this framework’s 48 obligation entries — with provenance — to collect, own, organise and track the currency of your evidence against.
From the field
Common GDPR blockers we find
Where evidence most often falls short — surfaced explicitly, not averaged away.
- The RoPA exists but one processing activity has no lawful basis recorded against it.
- A DSAR procedure is documented but there is no log evidencing requests were fulfilled within the statutory month.
- A processor is engaged but no Article 28 data-processing agreement is on file, or it predates the current processing.
- A retention schedule is published but there is no deletion evidence showing it is actually applied.
Evidence
The evidence you'll bring
You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:
Records & lawful basis
- record of processing activities (RoPA)
- lawful-basis register
- consent records
- legitimate-interest assessments
Rights & requests
- DSAR handling procedure & logs
- erasure/rectification records
- privacy notices
- children's-data handling
Processors & transfers
- Article 28 data-processing agreements
- sub-processor list
- transfer mechanisms (SCCs/adequacy)
- transfer impact assessments
Breach & retention
- breach register & 72-hour notification records
- retention schedule & deletion evidence
- DPIAs
- records of DPO engagement
Start now — free
Prepare your GDPR evidence
Free — generate now
GDPR Readiness Kit
Netallion-authored templates and registers to prepare your GDPR evidence — generated instantly, no sign-up. Then organise that evidence in Netallion and assess whether it’s sufficient.
- DPIA template
- Privacy notice template
- GDPR reference guide
- RoPA, DSR, breach, processor & retention registers (CSV)
No email required. Free to download and use.
From evidence to a conclusion
How readiness is reached
The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.
- 1Scope
The applicable requirement set for your framework and scope.
- 2Applicable requirements
A fixed denominator — every in-scope requirement counts.
- 3Evidence
You attach and own evidence; ownership and expiry are tracked.
- 4Evidence assessment
The evidence is read against each requirement for sufficiency.
- 5Determination
A requirement-level verdict with byte-verified citations.
- 6Blocker
Negative findings surface as explicit blockers, not averages.
- 7Remediation
Track the fix; reassessment — not a checkbox — resolves it.
- 8Review (R0–R3)
Controlled human review with recorded provenance.
- 9Finalisation
A signed, scope-pinned readiness conclusion.
- 10Report / export
Readiness report, evidence index, SoA, audit ZIP + SHA-256.
- 11Lifecycle & reassessment
Evidence expires/changes → affected requirements reopen.
Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.
What you get out
- Requirement-level readiness across all 48 GDPR obligations (Articles 5–49)
- RoPA-anchored lawful-basis view
- explicit blocker list with reasons
- evidence index + audit ZIP with SHA-256 manifest
FAQ
GDPR readiness — common questions
Does Netallion make us GDPR compliant?
No tool can declare an organisation compliant. Netallion assesses whether your evidence substantiates each GDPR obligation and surfaces where it falls short. Where certification is sought, it is issued by an accredited body under Articles 42–43.
What GDPR evidence does Netallion assess?
Records of processing (ROPA), DPIAs, consent and lawful-basis records, data-processing agreements, and breach records, among others — against 48 obligation-level criteria.
Does readiness stay current as our processing changes?
On assessed engagements, when tracked evidence expires, is withdrawn or superseded, the affected requirements reopen so a stale conclusion is never presented as current.
Related
Cross-framework leverage
Evidence you assemble for one framework often supports another. Commonly paired with:
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. GDPR certification, where sought, is issued by an accredited body under Articles 42–43; supervisory authority rests with the relevant DPA. Where the boundary sits.
See what your GDPR evidence proves
See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.