PDPL Gap-Analysis Checklist
Working aid to review your current position against common PDPL expectations. Not legal advice — use it to scope work and then confirm with qualified counsel.
Company: Date:
Lawful basis & transparency
| Check | Yes | Partly | No / N/A | Notes / Action |
| We have a lawful basis for the personal data we process. | | | | |
| We have a clear, current privacy policy. | | | | |
| Consent (where used) is freely given, specific, informed, and recorded. | | | | |
Data subject rights
| Check | Yes | Partly | No / N/A | Notes / Action |
| We can locate an individual's data on request (DSAR). | | | | |
| We can correct data on request. | | | | |
| We can honour deletion/erasure requests within limits. | | | | |
Security & breaches
| Check | Yes | Partly | No / N/A | Notes / Action |
| We apply appropriate technical + organisational security measures. | | | | |
| We have a breach-response / incident plan. | | | | |
| We can assess whether a breach requires notification. | | | | |
Records, transfers & accountability
| Check | Yes | Partly | No / N/A | Notes / Action |
| We keep a data-processing register. | | | | |
| We know where our data is stored and whether any crosses borders. | | | | |
| We have assessed whether a Data Protection Officer is required. | | | | |
| Key staff understand our data-protection responsibilities. | | | | |
Prioritise the “No” rows, begin with the highest-risk gaps, and validate with counsel.