GDPR (General Data Protection Regulation)

Get compliant with the EU’s data protection law — and stay that way

The General Data Protection Regulation (GDPR) governs how organisations collect, store, process, and transfer personal data of individuals in the European Union and European Economic Area. It applies regardless of where your company is headquartered — if you handle EU residents’ data, GDPR applies to you.

We help you assess exposure, close gaps, and put documentation and processes in place that hold up under scrutiny.

Do you need this?

 Applies to you if…
Established in the EUYou have an office, subsidiary, or establishment in the EU/EEA
Offering goods/services to the EUYou sell, market, or offer services to individuals in the EU, even without a local presence
Monitoring EU individualsYou track behaviour of people in the EU — e.g. through cookies, analytics, or profiling
Processing on behalf of othersYou’re a data processor handling EU personal data for a client (data controller)

Key roles under GDPR

  • Data Controller — decides why and how personal data is processed
  • Data Processor — processes data on the controller’s instructions (e.g. a vendor, SaaS provider)
  • Data Protection Officer (DPO) — mandatory for public authorities, and for organisations whose core activity involves large-scale or systematic monitoring, or large-scale processing of special category data

Penalties for non-compliance: up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements — plus reputational and contractual fallout with EU customers and partners.

Typical engagement timeline: 4–8 weeks for a full compliance program, depending on data mapping complexity and existing documentation.

Process

Step 1 — Scoping and applicability assessment
We confirm whether and how GDPR applies to your organisation — territorial scope, controller vs. processor status, and whether a DPO appointment is required.

Step 2 — Data mapping and audit
We inventory what personal data you collect, where it’s stored, who has access, how long it’s retained, and where it flows — including any transfers outside the EU/EEA.

Step 3 — Gap analysis
Current practices are benchmarked against GDPR’s core principles — lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

Step 4 — Legal basis and consent framework
We identify the correct lawful basis for each processing activity (consent, contract, legal obligation, vital interests, public task, or legitimate interests) and design consent flows where consent is the chosen basis.

Step 5 — Documentation drafting

  • Privacy policy and cookie policy
  • Record of Processing Activities (ROPA)
  • Data Processing Agreements (DPAs) with vendors and sub-processors
  • Data Protection Impact Assessment (DPIA), where processing is high-risk
  • Data breach response and notification procedure

Step 6 — Technical and organisational measures
Recommendations on encryption, access controls, pseudonymisation, retention schedules, and staff training to demonstrate accountability.

Step 7 — Ongoing compliance support
DPO services (in-house guidance or outsourced), breach response support, periodic audits, and updates as regulatory guidance evolves.

Documents & Information Required

About your organisation

  • Company registration details and structure
  • List of jurisdictions where you operate or have customers
  • Organisational chart showing who handles data (IT, HR, marketing, customer support)

About your data processing

  • List of personal data categories collected (names, emails, IP addresses, health data, financial data, etc.)
  • Sources of data collection — website forms, apps, third-party lists, cookies
  • Current privacy policy, cookie policy, and consent mechanisms, if any
  • List of third-party vendors/processors with access to personal data (cloud hosting, analytics, email marketing, payment processors)
  • Existing contracts with vendors handling EU personal data
  • Data retention practices — how long data is kept and why

About data transfers

  • Details of any data stored or processed outside the EU/EEA
  • Existing Standard Contractual Clauses (SCCs) or transfer mechanisms in place, if any

About security practices

  • Current access control and encryption practices
  • Any prior data breach incidents and how they were handled
  • Employee data protection training records, if any

Notes

  • If you’re a data processor (not controller), your client’s instructions and existing DPA (if any) should be shared.
  • Special category data — health, biometric, religious, political opinions — requires additional safeguards; flag if this applies.

Benefits

Avoid significant financial exposure
Fines under GDPR scale with turnover and can be severe. A compliant framework substantially reduces this risk and gives you a documented defence if regulators inquire.

Unlocks EU business
Enterprise customers and partners in the EU increasingly require GDPR compliance — often via a signed DPA — before they’ll contract with you at all.

Builds customer trust
Transparent data practices and clear consent mechanisms are a differentiator, particularly for consumer-facing products and B2B SaaS.

Stronger data governance overall
The mapping and documentation process typically surfaces data sprawl, unused access rights, and redundant vendor relationships — benefits that extend beyond EU compliance.

Breach-readiness
GDPR requires notifying the relevant supervisory authority within 72 hours of becoming aware of certain breaches. Having a response plan in place before an incident happens is far cheaper than building one during a crisis.

Interoperability with other privacy laws
A solid GDPR framework substantially overlaps with UK GDPR, and gives you a head start on other regimes such as India’s DPDP Act or California’s CCPA, since core principles (transparency, minimisation, accountability) are broadly shared.

Competitive positioning
“GDPR compliant” on your website and in sales conversations removes a common objection and shortens enterprise sales cycles with EU-facing prospects.