GDPR Compliance
Support for organisations that handle personal data of people in the European Union, from scoping to day-to-day privacy operations.
The EU General Data Protection Regulation (GDPR) can apply to organisations outside Europe when they offer services to, or monitor, individuals in the EU.
The EU General Data Protection Regulation (GDPR) can apply to organisations outside Europe when they offer services to, or monitor, individuals in the EU. Customers and partners increasingly ask for evidence of GDPR-aligned practice, and the requirements reach contracts, systems and incident handling.
What the engagement covers
- GDPR applicability assessment, including establishment and targeting analysis
- Gap assessment against the regulation
- Records of processing and data mapping
- Lawful basis, consent and transparency review
- Individual rights handling, such as access, correction and erasure requests
- Controller and processor agreements and supplier oversight
- International transfer review and safeguards
- Data protection impact assessment triggers and process
- Personal data breach handling, including the 72-hour supervisory authority notification requirement where it applies
- Governance: accountability documentation, training and role definitions, including whether a data protection officer is required
Understand. Prioritize. Enable.
How we deliver GDPR compliance, step by step.
- 01
Scope the exposure
We establish whether and how GDPR applies, which processing is in scope and which regulators and customers care about it.
- 02
Assess current practice
Existing policies, records, contracts and processes are reviewed against GDPR requirements and rated by risk.
- 03
Close the gaps
A prioritised plan with owners, covering documentation, process changes and contract updates.
- 04
Sustain the programme
Training, review cycles and evidence routines so accountability is demonstrable over time.


