Tabletop exercise

EU GDPR tabletop exercise

Lawful processing, consent, data-subject rights, breach duties.

We can run the EU GDPR exercise for your team, or set you up as a facilitator to run it yourself.

What the room works through

EU General Data Protection Regulation (2016/679)

Controller and processor obligations. Use article refs such as Art.5, Art.30, Art.32, Art.33 and domains Principles, Rights, Accountability, Security, Transfers.

Clauses
30
Rounds
10 across two stages
Room size
Up to 20 participants

Stage 1 — assess

Tables rate control maturity, agree the risk that matters for the room, then face an audit round where a peer table challenges the call. Every decision is logged against a EU GDPR clause.

Stage 2 — survive

Incidents and complications hit the tables: crisis injects, budget cuts and a concealed insider. Controls bought in Stage 1 pay out — or the gap shows.

What you take away

  • Clause-by-clause coverage across EU GDPR
  • A gap list ranked by what the room could not defend
  • Per-table divergence, so you can see where opinion split
  • Word and CSV exports plus a drafted findings narrative

New to facilitating? Start with the facilitator manual or read the session walkthrough.

Other standards