GDPR Readiness Assessments
Establish where GDPR actually reaches you, then evidence it. Article 3(2) catches organizations outside the Union that offer goods or services to people there or monitor their behavior; processing carried out on an EU customer's instructions is bound instead through Article 28. We fix the lawful basis for each purpose and build the records, notices, and transfer safeguards that demonstrate accountability under Article 5(2).
Engagement brief
- Frameworks
- GDPRISO/IEC 27001ISO/IEC 27002
Coverage that maps to real risk.
How the engagement runs.
A disciplined, repeatable arc — so results are comparable and defensible.
- 01
Applicability analysis and Article 27 representative check
- 02
Data mapping across systems, purposes, recipients, and retention
- 03
Gap assessment against the obligations that apply to you
- 04
Remediation build: records, notices, DPIAs, clause requirements
- 05
Rights and breach drills, then handover to your privacy owner
What you walk away with.
Every finding is rated on the CVSS severity scale:
- CRITICAL9.0–10.0
- HIGH7.0–8.9
- MEDIUM4.0–6.9
- LOW0.1–3.9
- INFO0.0
Questions we hear a lot.
It can. Article 3(2) catches organizations outside the Union that offer goods or services to people there or monitor their behavior. Where it reaches you only through an EU customer's contract, the obligation is the Article 28 terms you signed.
Tell us about your environment and we'll come back with a fixed scope, timeline, and price.