Is your privacy policy GDPR-ready? Find out article by article.

Upload your privacy or security policy and PolicyPilot checks it against every key GDPR article — lawful basis, notices, data subject rights, processors, breaches, DPIAs, transfers — telling you for each whether the text covers it, half covers it, contradicts it, or says nothing, and quoting the sentence it based that on.

The same engine covers 305 controls across 10 frameworks — US privacy law (CCPA/CPRA, COPPA, GLBA), PCI DSS for card payments, SOC 2, ISO 27001, HIPAA, NIST CSF 2.0 and Nigeria's Data Protection Act — so one policy review answers several audits.

The scoring is deterministic and explainable. A language model, when one is configured, reviews the harder calls and writes remediation language, but it can only move a verdict one step and only with a supporting quote. Without a model, the product still works.

Create a free account

Paste or upload a policy (PDF, Word or text) and get a control-by-control report in seconds — or browse the framework library first.

How the scoring works

Each control declares its required elements as groups of synonyms. A control counts as covered only when every group is satisfied — so "we encrypt data" does not satisfy an encryption control that also needs a statement about at-rest versus in-transit. It comes back partial, and the report names the missing half.

Two coverage numbers are reported: a plain count, and one weighted by severity. Eleven low-severity controls covered and one critical control missing is not 92% compliant in any sense an auditor would accept.

One artefact, many frameworks

Controls share a topic vocabulary, so the crosswalk is computed rather than hand-maintained. These topics each appear in three or more frameworks — evidence gathered once answers all of them.

access-control 9 frameworks incident-response 8 frameworks policy-governance 9 frameworks data-subject-rights 4 frameworks consent 5 frameworks risk-assessment 10 frameworks
What this is not. A documentary gap analysis is not an audit and not legal advice. It tells you what your documents say; it cannot tell you what your organisation does. Every control marked covered still needs evidence that it operates — which is why the evidence tracker exists alongside it.