Evaluate compliance with EU General Data Protection Regulation requirements for processing personal data of EU residents
Article 6: Consent, contract, legal obligation, vital interests, public task, legitimate interests
Article 7: Valid consent must be granular and withdrawable
Article 9: Heightened consent requirements for sensitive personal data
Article 7(3): Withdrawal mechanisms must be straightforward
Article 15: Right of access with one-month response deadline
Article 16: Right to rectification of incorrect or incomplete data
Article 17: Deletion when data no longer necessary or consent withdrawn
Article 20: Right to data portability for automated processing
Article 21: Objection to direct marketing and legitimate interests processing
Article 35: DPIA required for large-scale sensitive data, profiling, systematic monitoring
Article 25: Data protection by design and by default
Article 32: Technical measures to ensure data security
Article 37: DPO required for public authorities and large-scale special category processing
Article 30: Detailed inventory of all processing activities
Articles 13-14: Transparent information about processing
Article 5(1)(e): Storage limitation principle
Chapter V: Standard Contractual Clauses, Binding Corporate Rules, adequacy decisions
Schrems II: Transfer impact assessments required
Article 28: Processor contracts with mandatory clauses
Article 33: Notification deadline from breach awareness
Article 34: Individual notification when likely to result in high risk
Article 33(5): Documentation of all breaches, including those not reported
Please answer all required questions to see your results