Introduction
What this self-check does
- Highlights potential governance gaps
- Surfaces readiness concerns
- Identifies areas requiring further review
- Supports management discussion and follow-up
What this self-check does not do
- Provide legal advice
- Certify compliance
- Replace an audit or assessment
- Guarantee regulatory readiness
Important: A higher score does not automatically mean compliance. A lower score does not automatically mean non-compliance.
Understanding Your Score
Your score provides an initial indication of governance readiness.
18–22
Strong Readiness
Most governance foundations appear to be present.
12–17
Moderate Readiness
Some governance gaps or follow-up areas may exist.
0–11
Needs Attention
Multiple governance indicators may require review.
What Your Result May Indicate
Governance Ownership
Responsibilities may be assigned, partially assigned, or unclear across the organisation. Unclear ownership can lead to delayed decisions, inconsistent practices, and accountability gaps when issues arise.
Data Visibility
The organisation may or may not have a reliable view of what personal data exists, where it is stored, and who can access it. Limited visibility can affect management’s ability to assess risk exposure, regulatory obligations, and incident impact.
Third-Party Exposure
Vendors, service providers, and external platforms may introduce governance, operational, contractual, and reputational risks that remain outside direct management control.
AI & Automation
AI, analytics, and automation activities may require additional oversight, review, and documentation. Decisions involving these technologies can create accountability and governance implications that extend beyond technology teams.
Why This Matters
Data protection issues rarely remain confined to a single department.
Questions relating to ownership, vendor oversight, AI use, incident readiness, and governance accountability may affect management decisions, organisational risk exposure, customer trust, regulatory obligations, and board reporting responsibilities.
Where governance responsibilities are unclear, organisations may find it difficult to make informed decisions, demonstrate accountability, or respond effectively when issues arise.
The Dbyt Readiness Self-Check is designed to help organisations identify areas that may benefit from further review, discussion, and management attention.
“`
Common Governance Gaps Identified by Dbyt
- Unclear ownership of personal data responsibilities
- Incomplete data inventories and processing records
- Third-party vendors without documented review
- Retention practices that are undefined or inconsistent
- Limited management visibility over data protection risks
- AI or analytics activities without documented oversight
- Follow-up actions that are identified but not tracked
Questions Leadership Teams Should Be Able To Answer
- Who owns accountability for personal data across the organisation?
- Can management confidently identify where personal data is stored, used, shared, and retained?
- Are third-party vendors subject to appropriate governance and review?
- How are AI, analytics, and automation activities monitored and approved?
- Would management receive timely and reliable information if a data incident occurred tomorrow?
- Are governance decisions documented and defensible if questioned by regulators, customers, auditors, or stakeholders?
Suggested Next Steps
Organisations may wish to consider the following actions:
- Review ownership and accountability for personal data activities.
- Validate data inventories, processing records, and retention practices.
- Review third-party vendors, service providers, and external platforms that handle personal data.
- Assess governance controls relating to AI, analytics, and automation activities.
- Prioritise follow-up actions and assign responsible owners.
- Establish a management review process to monitor governance risks and remediation efforts.
Where significant governance gaps are identified, a more structured review may be appropriate to support management decision-making, risk visibility, and accountability.
Beyond the Self-Check
The Dbyt Readiness Self-Check provides an initial indication of governance readiness.
As organisations grow, governance challenges often extend beyond policies and awareness. Management teams may require greater visibility over data ownership, third-party arrangements, AI and automation activities, incident readiness, accountability structures, and follow-up actions.
Dbyt is being developed as a broader governance framework that helps organisations move from isolated compliance activities toward more structured governance, management visibility, and defensible decision-making.
The Dbyt Journey
| 1. Readiness Self-Check | Identify potential governance gaps and areas requiring review. |
| 2. DIM-RR | Build visibility over personal data, ownership, vendors, retention, and risk indicators. |
| 3. Governance Review | Assess accountability, controls, decision readiness, and follow-up actions. |
| 4. Management Reporting | Provide clearer visibility to leadership teams and decision-makers. |
| 5. Incident Readiness | Improve preparedness, escalation, response discipline, and accountability. |
| 6. Dbyt Framework | Move toward structured governance, informed decision-making, and defensible accountability. |
What Dbyt Is Building Towards
Dbyt is a practical governance framework designed to help organisations improve visibility, accountability, and decision readiness relating to personal data.
The Dbyt Readiness Self-Check is an introductory diagnostic that highlights areas which may benefit from further review and management attention.
As organisations mature, Dbyt supports additional governance activities such as data inventory mapping, risk registers, vendor reviews, retention management, AI oversight, incident readiness, management reporting, and governance reviews.
Dbyt is intended to help organisations move from reactive compliance activities toward more structured governance, informed decision-making, and defensible accountability.