Global Data Privacy Compliance Assessment Engine
Step 1 — Setup

Configure the assessment

Choose the regulation, what you're running, and the organisation's context. The control set, references and reporting adapt to the selected law; the core controls are sector-agnostic, while sector overlays and heightened-obligation mode add extra controls only where relevant.

Treat as a Significant Data Fiduciary (SDF) Adds the mandatory DPO, DPIA, audit and algorithmic-due-diligence checks under Section 10. Auto-suggested for BFSI and large processors.
Choose an assessment type to begin.
Step 2 — Assessment

Rate each control

Domain

—

Portfolio view

Multi-client comparison

Compare several organisations side by side. Add the current assessment, or import saved .json files for other clients. Comparisons stay on this device only.

Progress over time

Client trend & improvement

Re-assess the same client on different dates and add each one to the comparison — this view charts how their maturity changes over time. Add at least two assessments of one organisation to see a trend.

Scoring configuration

Control weighting editor

Adjust how heavily each control counts toward the score and how severe its gaps are. Standard = weight 1, Critical = weight 2, Mandatory = weight 3. Changes apply consistently across every client and re-assessment, on this device.

Analysis

Insights & analysis

A data-driven read of the current assessment — systemic themes, quick wins versus strategic priorities, and a sequenced 30 / 60 / 90-day plan.

Methodology

The assessment standard

The published method behind every score in this engine — domains, rating scales, evidence expectations, sampling, weighting and the conformity criteria. Share it with clients so results are transparent and repeatable.

Deep research

Privacy knowledge base

Per-domain research briefs: the statutory basis, what good looks like, the evidence to collect, and common pitfalls. Use these to brief clients, scope an audit, or justify findings.