review-gdpr-readiness
Installation
SKILL.md
GDPR Readiness Review
Structured assessment of an organization's compliance with the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 — across the 10 core compliance areas. Applicable to any organization that processes the personal data of EU data subjects, regardless of where the organization is located. For MENA companies, GDPR triggers when EU-based employees, customers, or data subjects are involved.
When to use this
- Pre-audit preparation: before an internal or external GDPR audit
- Gap assessment: a new business activity is being launched and needs a data-protection review
- Incident post-mortem: a personal data incident has occurred and the organization needs to assess its GDPR position
- M&A due diligence: acquiring a company with EU personal data processing
- Regulatory examination preparation: a supervisory authority (DPA) has initiated an inquiry
- For MENA companies: when processing EU employee data, EU customer data, or data subject to EU adequacy mechanisms
GDPR applicability to MENA organizations
GDPR applies (Article 3) to:
- Any organization established in the EU
- Any organization not in the EU that: (a) offers goods or services to EU data subjects, or (b) monitors the behavior of EU data subjects