0 / 10 blocks complete
§ GDPR Audit · From €3,500

Tell us about your data.

Ten short blocks. Skip what doesn't apply, paste what you have. Hexy prepares the gap analysis and Migle finalises the audit. You'll have a written report within 7 business days.

About you

Or your own full name, if you are instructing for yourself.

§ 01

Business overview

A short paragraph about what your business does. A link to your website is fine if it tells the story.

  • What does the business do?
  • Where are you incorporated, and where do you operate?
  • How many employees and contractors?
  • Approximate annual revenue band
§ 02

HR & employee data

What data you hold about employees, contractors and applicants, and how it flows.

  • Recruitment: where do you store CVs, interview notes?
  • Payroll provider, social insurance handling
  • Personnel records: tool used, retention period
  • Background checks: when and how
  • Monitoring (email, screen, productivity tools)
§ 03

IT systems & infrastructure

The systems your data lives in and any cross-border data flows.

  • Where does production data live (clouds, regions)?
  • Backups, where and for how long?
  • Major SaaS systems handling personal data
  • Any data leaving the EEA? Where to?
  • Encryption at rest and in transit?
§ 04

Products & services

For each product or service: what personal data do you process and why?

  • List each product/service
  • Categories of personal data per product
  • Lawful basis you rely on
  • Volume of data subjects
  • Any profiling or automated decision-making?
§ 05

Marketing

Your marketing data sources, segmentation, ad-tech and email programmes.

  • Email marketing platform and how lists are built
  • Ad-tech (Meta Pixel, Google Ads, LinkedIn), what data flows
  • Profiling / scoring / segmentation
  • Consent capture mechanism
  • Cookies and tracking pixels on site
§ 06

Sales

How sales data is collected and enriched.

  • CRM in use
  • Data enrichment services (e.g. Apollo, ZoomInfo, Clearbit)
  • Call recording / transcription tools
  • Lawful basis for processing prospect data
  • Retention period for inactive prospects
§ 07

CCTV & workplace monitoring

Cameras, access control, network monitoring, productivity tools.

  • CCTV: locations, signage, retention
  • Access control / badge logs
  • Network / email monitoring
  • Productivity / time-tracking tools
  • BYOD policy?
§ 08

Websites & apps

Public-facing websites and apps, what they collect and how consent is managed.

  • List of websites and apps
  • Cookie banner / consent management tool
  • Analytics tools
  • Tracking pixels (advertising)
  • Embedded third-party widgets (chat, recaptcha, etc.)
  • Mobile app permissions and SDKs
§ 09

Vendor & sub-processor management

Vendors that handle personal data on your behalf, and whether DPAs are signed.

  • List your top 10 processors
  • DPA in place for each? (yes / no / unsure)
  • Sub-processor list maintained?
  • Any vendors outside the EEA?
  • Vendor onboarding process, is security review part of it?
§ 10

Record of Processing Activities (RoPA)

Do you maintain a RoPA (Article 30 GDPR)? If yes, upload it. If no, describe what you wish you had and we'll draft a starter from this audit.

  • Existing RoPA? If yes, when last updated?
  • If no, what made it not happen yet?
  • Specific processing activities you definitely want covered

At least 4 blocks need substantive answers before we can run the audit.

We keep your answers for 30 days after your last save, then delete them. Nothing reaches HEXLaw for review until you submit.