Meet the European Standard
GDPR Compliance and European Data Protection
The GDPR is Europe's data protection law and the benchmark much of the world follows. We help you find your lawful basis, honour data subject rights, and document it all.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
The General Data Protection Regulation governs how organisations handle the personal data of people in the European Union and beyond. It requires a lawful basis for processing, clear rights for data subjects, records of processing, and prompt breach reporting, backed by large fines. It matters because it reaches any business serving EU residents, and it shapes privacy laws elsewhere. We help you build a defensible GDPR programme: mapped data, documented decisions, and processes that respond to a data subject or a supervisory authority without panic.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the GDPR engagement, 6 phases in order, each one selectable. Phase 1, Data Mapping and Lawful Basis. We map your processing activities and confirm a lawful basis for each one. This is the backbone of GDPR compliance. Activities: Inventory processing activities across the business; Assign a lawful basis to each activity; Document legitimate interest assessments where used; Flag special category data and its conditions. Hands over Processing Inventory and Lawful Basis Register. Phase 2, Gap Assessment. We measure your practices against the GDPR articles and give you a prioritised action plan. Activities: Assess practices against the accountability articles; Review notices, consent, and rights handling; Check security measures against article 32; Rank gaps by fine exposure and effort. Hands over GDPR Gap Assessment and Action Plan. Phase 3, Rights and Consent Processes. We build workflows for data subject rights and, where needed, consent that meets the standard. Activities: Build workflows for access, erasure, and portability requests; Set the one-month response clock and tracking; Redesign consent capture where consent is the basis; Train frontline teams to recognise requests. Hands over Data Subject Rights Workflow. Phase 4, Records and Impact Assessments. We help you maintain records of processing and run data protection impact assessments for high-risk work. Activities: Build article 30 records of processing; Set DPIA screening criteria for new projects; Run DPIAs for existing high-risk processing; Embed the records into change management. Hands over Records of Processing and DPIA Templates. Phase 5, Transfers and Breach Readiness. We review international transfers and set up breach reporting within the 72-hour requirement. Activities: Map international transfers and their safeguards; Put Standard Contractual Clauses in place where needed; Run transfer impact assessments for key routes; Write and test the 72-hour breach procedure. Hands over Transfer Register and Breach Response Procedure. Phase 6, Readiness Review. We run a final review so you can demonstrate accountability to a customer or a supervisory authority. Activities: Test the rights workflow with sample requests; Verify remediation of gap assessment findings; Compile the accountability evidence pack; Brief leadership on residual risk. Hands over GDPR Readiness Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Data Mapping and Lawful Basis
We map your processing activities and confirm a lawful basis for each one. This is the backbone of GDPR compliance.
What Happens In This Phase
- Inventory processing activities across the business
- Assign a lawful basis to each activity
- Document legitimate interest assessments where used
- Flag special category data and its conditions
The Handover
Processing Inventory and Lawful Basis Register
The next phase starts from this.
Phase 01 Data Mapping and Lawful Basis
We map your processing activities and confirm a lawful basis for each one. This is the backbone of GDPR compliance.
What Happens In This Phase
- Inventory processing activities across the business
- Assign a lawful basis to each activity
- Document legitimate interest assessments where used
- Flag special category data and its conditions
The Handover
Processing Inventory and Lawful Basis Register
The next phase starts from this.
- 01
Data Mapping and Lawful Basis
We map your processing activities and confirm a lawful basis for each one. This is the backbone of GDPR compliance.
OutputProcessing Inventory and Lawful Basis RegisterActivities
- Inventory processing activities across the business
- Assign a lawful basis to each activity
- Document legitimate interest assessments where used
- Flag special category data and its conditions
- 02
Gap Assessment
We measure your practices against the GDPR articles and give you a prioritised action plan.
OutputGDPR Gap Assessment and Action PlanActivities
- Assess practices against the accountability articles
- Review notices, consent, and rights handling
- Check security measures against article 32
- Rank gaps by fine exposure and effort
- 03
Rights and Consent Processes
We build workflows for data subject rights and, where needed, consent that meets the standard.
OutputData Subject Rights WorkflowActivities
- Build workflows for access, erasure, and portability requests
- Set the one-month response clock and tracking
- Redesign consent capture where consent is the basis
- Train frontline teams to recognise requests
- 04
Records and Impact Assessments
We help you maintain records of processing and run data protection impact assessments for high-risk work.
OutputRecords of Processing and DPIA TemplatesActivities
- Build article 30 records of processing
- Set DPIA screening criteria for new projects
- Run DPIAs for existing high-risk processing
- Embed the records into change management
- 05
Transfers and Breach Readiness
We review international transfers and set up breach reporting within the 72-hour requirement.
OutputTransfer Register and Breach Response ProcedureActivities
- Map international transfers and their safeguards
- Put Standard Contractual Clauses in place where needed
- Run transfer impact assessments for key routes
- Write and test the 72-hour breach procedure
- 06
Readiness Review
We run a final review so you can demonstrate accountability to a customer or a supervisory authority.
OutputGDPR Readiness ReportActivities
- Test the rights workflow with sample requests
- Verify remediation of gap assessment findings
- Compile the accountability evidence pack
- Brief leadership on residual risk
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
DPDPA Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the GDPR scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Microsoft Purview, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: GDPR, EDPB Guidelines, ISO/IEC 27701:2019, Standard Contractual Clauses, NIST Privacy Framework.
What We Run
7 tools
- Securiti
- Microsoft Purview
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- EDPB
- SCCsEuropean Union
Deliverables
What You Receive
- Records of processing activities
- Lawful basis register
- Data subject rights workflow
- Data protection impact assessment templates
- Breach response procedure
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Does the GDPR apply to non-EU companies?
Yes, if you offer goods or services to people in the EU or monitor their behaviour. Where you are based does not remove the obligation.
When do we need a data protection impact assessment?
When processing is likely to be high risk, such as large-scale profiling or sensitive data. We help you screen for this and run the assessment when it is needed.
How fast must we report a breach?
You must notify the supervisory authority within 72 hours of becoming aware, where the breach poses a risk. We build a process so you can meet that deadline.
Keep Moving Through Compliance
Service 10 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.