Having a Privacy Policy Isn’t GDPR Compliance.
We help organisations understand their GDPR obligations, map how personal data is collected and processed, strengthen privacy controls, manage data subject rights, and reduce regulatory risk — so privacy becomes an operational capability, not just a document.
Does GDPR apply to you?
GDPR reaches any company processing EU/UK personal data, regardless of where the company itself is based. A few quick questions, one clear answer.
Which best describes your business?
- Sector—
- EU/UK targeting—
- EU/UK establishment—
- Special-category data—
- Existing program—
What GDPR non-compliance can actually cost.
GDPR gives data protection authorities significant enforcement powers, including substantial administrative fines and strict breach-notification requirements. The level of exposure depends on the nature and severity of the infringement, as well as the organisation’s circumstances.
For the most serious infringements, administrative fines can reach €20 million or 4% of global annual turnover, whichever is higher.
- 72 Hours notify the relevant supervisory authority of a personal data breach where the breach is likely to result in a risk to individuals
- Without undue delay — breach notifications must be made within the applicable GDPR requirements
- If delayed the notification must explain the reasons for the delay to the supervisory authority
GDPR administrative fines are imposed on the organisation responsible for the infringement. GDPR itself does not create a NIS2-style named-management-body personal-liability regime. The financial exposure is therefore primarily at the company level, although other legal consequences may apply depending on the jurisdiction and circumstances.
Most companies don’t fail GDPR because they ignore privacy. They fail because “we have a cookie banner” was never the same as being compliant.
GDPR reaches any company processing EU personal data, regardless of where the company itself is based.
Most companies already have some privacy controls in place. The gap is proving that those controls actually work across the entire personal-data lifecycle — from collection and processing to third parties, data-subject requests, retention and breach response. That’s where we help: turning GDPR requirements into a privacy program your teams can actually operate and evidence.
A Structured Approach to GDPR Readiness.
We begin by assessing your current data-processing activities against GDPR’s requirements, identifying lawful-basis and processor gaps, and prioritizing remediation. From implementing technical safeguards and documenting policies to preparing breach-notification evidence, we help you build an environment that is organized, defensible, and ready for regulatory scrutiny.
Everything You Need for GDPR Readiness.
Every engagement produces practical, usable deliverables mapped to GDPR requirements — from data mapping and lawful-basis documentation to data subject rights, consent, breach response and ongoing privacy governance.
GDPR Gap Assessment Report
Current processing activities assessed and mapped against GDPR requirements, with clear gaps and prioritized remediation actions.
Records of Processing Activities (RoPA)
A structured record of processing activities covering personal data, purposes, recipients, retention, transfers and applicable safeguards.
Lawful Basis Documentation
Each processing activity mapped to its appropriate GDPR lawful basis rather than relying on assumed or undocumented justification.
Data Processing Agreements
Vendor and processor relationships involving EU personal data reviewed for appropriate GDPR contractual requirements and responsibilities.
Data Subject Rights Process
Structured workflows for access, rectification, erasure, portability and other data subject requests, with response tracking and statutory timelines.
Consent & Tracking Audit
Website and application tracking reviewed to ensure non-essential trackers are appropriately gated behind real, informed consent.
Breach Response Playbook
A practical breach-response workflow built around GDPR’s 72-hour supervisory-authority notification requirement.
DPIA Template & Process
A practical Data Protection Impact Assessment process for identifying, assessing and mitigating risks from high-risk processing activities.
Ongoing Compliance Monitoring
Continuous monitoring of new processing activities, vendors and privacy changes so emerging gaps are identified before they become compliance issues.
Security work that shows up in the numbers.
Every engagement is measured, not just delivered.
The Right GDPR Partner Makes All the Difference.
| Criteria |
// Recommended
BPDoxS
|
// In-house In-house team | // Vendor Typical vendor |
|---|---|---|---|
| GDPR Expertise |
GDPR-focused expertise across privacy governance, data protection, rights, consent and compliance operations
|
Strong understanding of the organisation, but specialist GDPR knowledge may depend on internal resources
|
Specialist privacy expertise may be strong, but coverage depends on the vendor's specific scope
|
| Data Visibility |
Maps personal-data flows, processing activities, vendors, retention and international data movement
|
Best access to internal systems, applications, processes and existing data-handling practices
|
Visibility is usually limited to the systems, processes or privacy scope included in the engagement
|
| Privacy Controls |
Connects lawful basis, consent, retention, access controls and privacy requirements into one operating framework
|
Direct control over internal policies, processes and technical implementation
|
Privacy specialists can provide strong policy, assessment and control-design capabilities
|
| Data Subject Rights |
Designs structured workflows for access, rectification, erasure, portability and request tracking
|
Has direct access to customer records and internal teams needed to fulfil requests
|
Can design rights processes, but execution still depends on the client's internal systems and teams
|
| Third-Party Privacy Risk |
Reviews processors, DPAs, data sharing, subprocessors and privacy obligations across the vendor ecosystem
|
Best knowledge of existing vendors, contracts and operational data-sharing relationships
|
Typically focuses on its own service or defined engagement scope rather than the client's complete processor ecosystem
|
| Breach & Compliance Readiness |
Connects breach response, supervisory-authority notification, remediation and ongoing compliance monitoring
|
Deepest knowledge of internal incident procedures, systems and organisational responsibilities
|
Can provide specialist privacy or security support, but broader operational readiness remains with the client
|
Independently recognized.
Rated by clients on Clutch · GoodFirms · Sortlist · DesignRush · RightFirms
Questions Worth Asking.
Everything you need to know before becoming GDPR-ready with confidence.
GDPR can apply even if your organisation is not based in the EU. It generally applies where an organisation established in the EU processes personal data, or where an organisation outside the EU offers goods or services to individuals in the EU or monitors their behaviour. Applicability depends on what data you process, who you process it about and what your activities involve, so we first determine your GDPR exposure rather than assuming it applies — or does not apply — based on company location alone.
No. Consent is only one of the lawful bases under GDPR. Depending on the processing activity, an organisation may rely on bases such as contract, legal obligation, legitimate interests or other applicable grounds. The important requirement is being able to identify and document the appropriate lawful basis for each processing activity. We help map your actual data processing to the correct legal basis rather than treating consent as a universal solution.
GDPR gives individuals a range of data subject rights, including rights relating to access, rectification, erasure, restriction of processing, data portability and objection, subject to applicable conditions and exceptions. Organisations need a process for receiving, verifying, routing and responding to requests within the applicable statutory timeframe. We help build practical workflows so requests can be handled consistently and evidenced across the teams and systems involved.
If a vendor acts as a processor processing personal data on your behalf, GDPR requires the relationship to be governed by an appropriate contract or other legal act meeting the requirements of Article 28. The agreement should address matters such as processing instructions, confidentiality, security, subprocessors, assistance with data subject rights and breach obligations. We help identify relevant processors and review whether the contractual arrangements properly reflect the processing relationship.
GDPR requires organisations to assess personal data breaches and determine whether notification is necessary. Where a breach is likely to result in a risk to individuals' rights and freedoms, the relevant supervisory authority generally needs to be notified without undue delay and, where feasible, within 72 hours of becoming aware of it. Higher-risk breaches may also require communication to affected individuals. We help establish classification, escalation, documentation and notification workflows before a breach occurs.
No. A privacy policy is only one part of a GDPR compliance program. Organisations also need to understand their processing activities, document appropriate lawful bases, manage processors, handle data subject rights, maintain appropriate security measures, assess high-risk processing where required, and respond properly to breaches. We help turn these requirements into documented, operational controls that your teams can actually follow and evidence.
Know how your data is handled. Know what needs to change.
Start with a practical assessment of your personal-data processing, privacy controls and third-party relationships — then get a clear roadmap to close GDPR gaps and build a privacy program your organisation can actually operate.
