Free Tool

GDPR Readiness Assessment

Evaluate your organisation’s GDPR compliance across data handling, consent management, subject rights, breach response, and governance. Get a compliance score with prioritised remediation steps.

Your GDPR Controls

Lawful Basis & Consent

Data Subject Rights

Data Protection

Breach Management

Governance

GDPR Key Requirements Summary

RequirementGDPR ArticleKey Obligation
Lawful Basis for ProcessingArticle 6Must have a valid legal basis (consent, contract, legal obligation, etc.) for all data processing
ConsentArticle 7Consent must be freely given, specific, informed, unambiguous, and easy to withdraw
Right of AccessArticle 15Individuals can request a copy of their personal data, responded to within 30 days
Right to ErasureArticle 17Individuals can request deletion of their data when no longer necessary
Data Protection by DesignArticle 25Privacy must be built into systems and processes from the start
Record of ProcessingArticle 30Maintain written records of all processing activities
Data Breach NotificationArticle 33Notify the ICO within 72 hours of becoming aware of a qualifying breach
Data Protection Impact AssessmentArticle 35Conduct DPIAs for processing likely to result in high risk to individuals
Data Protection OfficerArticle 37Appoint a DPO where core activities involve large-scale monitoring or special category data
International TransfersArticle 46Appropriate safeguards required for transfers outside the UK

Based on the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018. This is not legal advice. Contact Cloudswitched for IT compliance support or consult a data protection specialist for legal guidance.

More Free Tools

Try our other free security assessments and IT planning tools.

Frequently asked questions

Core requirements include a lawful basis for processing personal data, a clear privacy policy, documented data retention periods, the ability to fulfil subject access requests, and appropriate technical security measures. Most UK SMEs also need to register with the ICO and maintain a record of processing activities.

UK GDPR fines can reach up to £17.5 million or 4% of global annual turnover for the most serious breaches, though ICO enforcement against SMEs typically starts with warnings and improvement notices rather than maximum fines. The bigger practical risk for most businesses is reputational damage after a data breach.

Most UK SMEs are not legally required to appoint a formal Data Protection Officer unless they process personal data at large scale or handle special category data as a core activity. Even without a mandatory DPO, someone should still own data protection responsibility internally.

A subject access request (SAR) is when someone asks what personal data you hold about them. UK GDPR requires a response within one calendar month, extendable by up to two further months for complex requests. This assessment checks whether your processes could meet that deadline.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

20
  • SEO

Local SEO for UK Businesses: A Practical Guide to Ranking in Google's Local Pack in 2026

20 Aug, 2026

Local SEO is the practice of making a business visible to the people searching for its services nearby the plumber a homeowner in Leeds needs today, the...

Read more
19
  • Web Development

Core Web Vitals and Conversion: A UK Business Guide to Faster, More Profitable Websites in 2026

19 Aug, 2026

Core Web Vitals are the three field-measured metrics Largest Contentful Paint, Interaction to Next Paint and Cumulative Layout Shift that Google uses to score...

Read more
18
  • Virtual CIO

When Does a UK SME Need a Virtual CIO? A Practical Guide to IT Strategy Without a Full-Time Hire in 2026

18 Aug, 2026

Virtual CIO services give a growing UK SME the board-level technology judgement of a chief information officer the roadmap, the governance, the vendor...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.