Tell us about your data.
Ten short blocks. Skip what doesn't apply, paste what you have. Hexy prepares the gap analysis and Migle finalises the audit. You'll have a written report within 7 business days.
Or your own full name, if you are instructing for yourself.
Business overview
A short paragraph about what your business does. A link to your website is fine if it tells the story.
- What does the business do?
- Where are you incorporated, and where do you operate?
- How many employees and contractors?
- Approximate annual revenue band
HR & employee data
What data you hold about employees, contractors and applicants, and how it flows.
- Recruitment: where do you store CVs, interview notes?
- Payroll provider, social insurance handling
- Personnel records: tool used, retention period
- Background checks: when and how
- Monitoring (email, screen, productivity tools)
IT systems & infrastructure
The systems your data lives in and any cross-border data flows.
- Where does production data live (clouds, regions)?
- Backups, where and for how long?
- Major SaaS systems handling personal data
- Any data leaving the EEA? Where to?
- Encryption at rest and in transit?
Products & services
For each product or service: what personal data do you process and why?
- List each product/service
- Categories of personal data per product
- Lawful basis you rely on
- Volume of data subjects
- Any profiling or automated decision-making?
Marketing
Your marketing data sources, segmentation, ad-tech and email programmes.
- Email marketing platform and how lists are built
- Ad-tech (Meta Pixel, Google Ads, LinkedIn), what data flows
- Profiling / scoring / segmentation
- Consent capture mechanism
- Cookies and tracking pixels on site
Sales
How sales data is collected and enriched.
- CRM in use
- Data enrichment services (e.g. Apollo, ZoomInfo, Clearbit)
- Call recording / transcription tools
- Lawful basis for processing prospect data
- Retention period for inactive prospects
CCTV & workplace monitoring
Cameras, access control, network monitoring, productivity tools.
- CCTV: locations, signage, retention
- Access control / badge logs
- Network / email monitoring
- Productivity / time-tracking tools
- BYOD policy?
Websites & apps
Public-facing websites and apps, what they collect and how consent is managed.
- List of websites and apps
- Cookie banner / consent management tool
- Analytics tools
- Tracking pixels (advertising)
- Embedded third-party widgets (chat, recaptcha, etc.)
- Mobile app permissions and SDKs
Vendor & sub-processor management
Vendors that handle personal data on your behalf, and whether DPAs are signed.
- List your top 10 processors
- DPA in place for each? (yes / no / unsure)
- Sub-processor list maintained?
- Any vendors outside the EEA?
- Vendor onboarding process, is security review part of it?
Record of Processing Activities (RoPA)
Do you maintain a RoPA (Article 30 GDPR)? If yes, upload it. If no, describe what you wish you had and we'll draft a starter from this audit.
- Existing RoPA? If yes, when last updated?
- If no, what made it not happen yet?
- Specific processing activities you definitely want covered
At least 4 blocks need substantive answers before we can run the audit.
We keep your answers for 30 days after your last save, then delete them. Nothing reaches HEXLaw for review until you submit.