GDPR Compliance Consulting
The EU's data protection regulation carries real penalties for getting it wrong. We help you build - and prove - lawful, defensible data handling.
What is GDPR?
The EU General Data Protection Regulation (GDPR) governs how organisations collect, process, store and transfer the personal data of individuals in the EU - regardless of where the organisation itself is based.
It requires a lawful basis for every processing activity, honours data subject rights (access, rectification, erasure, portability), mandates breach notification within 72 hours, and often requires a Data Protection Officer and a documented Record of Processing Activities.
What's included
Data Mapping & RoPA
Data mapping and Records of Processing Activities (RoPA).
Lawful Basis Assessment
Lawful basis assessment for each processing activity.
DPIAs
Data Protection Impact Assessments (DPIAs) for high-risk processing.
Data Subject Rights
Data subject rights request process design.
Breach Notification Readiness
Breach notification procedures and incident response readiness.
DPO as a Service
Data Protection Officer (DPO) as a service.
Our approach - Plan, Do, Check, Act
The same continuous-improvement cycle behind every compliance programme we run.
Plan
Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.
Do
Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.
Check
Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.
Act
Run the audit, then keep improving through continual, corrective and preventive action.
Other compliance frameworks
ISO 27701
Privacy Information Management System, extending ISO 27001 for GDPR/DPDPA alignment.
Learn more →Questions we get asked first
Does GDPR apply to us if we're not based in the EU?
It can - GDPR applies to any organisation that processes personal data of individuals in the EU, regardless of where the organisation itself is located.
Do we need a Data Protection Officer?
It depends on your processing activities and scale - public authorities and organisations doing large-scale monitoring or processing of sensitive data typically need one. We can assess your obligation and act as your DPO.
What happens if we have a data breach?
GDPR requires notifying the relevant supervisory authority within 72 hours of becoming aware of a breach, and affected individuals in certain cases. We help build and rehearse that incident response process before you need it.
Ready to get audit-ready for GDPR?
Tell us where you're starting from and we'll come back with a scoped proposal within two working days.
