Free ISO 27001 Assessment

GDPR

Someone asked for your GDPR programme. Here is how it gets built.

Records, notices, assessments, contracts and procedures written for your data flows, for teams of 10 to 300, inside the platform that keeps them current after we hand over.

Records of processingExample, Article 30 register

25 processing activities, each with a lawful basis, a retention period and its processors

Customers and product
11 activities
11 / 11
Marketing and website
6 activities, 2 on consent
6 / 6
People and recruiting
8 activities
8 / 8
Processors and transfers
14 processors, 3 outside the EU with transfer tools
14 DPAs
Signed off by the programme owner, week 7Export · CSV, PDF

Who this is for

Teams that have outgrown a privacy policy template.

  • A fit

    • An EU SaaS company of 10 to 300 people whose enterprise customers send data protection questionnaires and processor agreements to sign.
    • A US or other non-EU company that sells to EU customers or employs people in the EU and needs the representative decision and transfer tools.
    • A company that has grown from a privacy policy to real data flows, vendors and employee data, and needs records and assessments to match.
  • Also a fit

    • A company preparing for a funding round or acquisition where privacy due diligence is on the list.
    • A team that received a data subject request or a complaint and discovered there was no procedure for it.
    • A company that already holds ISO 27001 or SOC 2 and needs the privacy half of the programme.
  • Not a fit

    • Organisations that need a Data Protection Officer or an EU representative appointed. We help you decide and appoint; we do not take the role.
    • Public bodies and large-scale health or surveillance processing. Those need a DPO and legal counsel from day one; we name partners in the quote.
    • Companies looking for a formal legal opinion only. The practising privacy lawyer on your project gives the opinion; the implementation is the service.

What you walk away with

The documents the regulation names, written for your data flows.

Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.

GDPR implementation

10 deliverables, 6 to 8 weeks
  • Data inventory and data flow map

    Register of systems, flows and recipients

    • CSV
    • PDF
  • Records of processing activities (Art. 30)

    Purposes and lawful basis reasoning per activity

    • CSV
    • PDF
  • Privacy notices

    Customers, website visitors, candidates, staff

    • DOCX
    • HTML
  • Data protection impact assessments

    For the processing that needs one

    • PDF
  • Processor agreement template and vendor register

    With DPA status per vendor

    • DOCX
    • CSV
  • International transfer assessment and transfer tools

    Assessment and clauses

    • DOCX
    • PDF
  • Data subject request and breach response procedures

    With request tracking and deadlines

    • Procedure
  • Retention schedule and data protection policy

    Versioned

    • DOCX
    • PDF
  • Evidence that each document is in use

    Linked to the record it supports

    • Platform
  • Recorded hand-over and readiness sign-off

    With whoever owns the programme afterwards

    • Video
    • PDF

How it works

Eight weeks to hand-over. Then the programme runs without us.

There is no certification audit for GDPR. The test is a customer's DPA review, a request from a data subject, or a question from the authority.

  • GRCTrail
  • Hand-over
  • Without us
  1. Week 0

    Scoping call

    Where your customers and staff are, what data you hold, what exists. Written fixed price within 3 business days.

  2. Weeks 1 to 2

    Assessment

    Data inventory, role analysis (controller, processor or both), gap analysis against the articles that apply. Implementation price confirmed.

  3. Weeks 3 to 7

    Implementation

    Records, notices, lawful bases, DPIAs, processor agreements, transfer tools, procedures, policies. Two review sittings with your team.

  4. Week 8

    Hand-over

    Notices published, DPAs sent, recorded hand-over, readiness sign-off.

  5. When a customer asks

    DPA review or questionnaire

    Answered from the records, with the evidence attached. Your team, or the questionnaire service if you want us.

  6. Every year

    Reviews and new processing

    Notices reviewed, DPIAs for new processing, requests answered within one month. Tracked in GRCTrail or in your export.

How we price

What moves the price

Three things we ask about on the call.

  • Your role in the data and the categories you process.

    Controllers need more notices, assessments and arrangements than processors; health, financial or children's data add DPIAs and consent design.

  • Countries and transfers.

    Customers or staff outside the EU add transfer tools; a non-EU company adds the representative decision.

  • Systems and vendors.

    Each one is mapped, reviewed and contracted. A current vendor list shortens the work.

Never in our price, named in the quote so you can budget

  • Acting as your Data Protection Officer or your EU representative
  • Formal legal opinions; the practising privacy lawyer on your project is named in the quote
  • Penetration testing
  • Audits by a certification scheme or a supervisory authority; we prepare the evidence and can attend

Questions before the call

Do we need a Data Protection Officer?

Only in the cases in Article 37: public bodies, large-scale regular monitoring, or large-scale special-category data. Most SaaS companies do not. The assessment gives you a written answer with reasoning.

Does GDPR apply to a US company?

Yes, if it offers goods or services to people in the EU or monitors their behaviour (Article 3). A US company then needs an EU representative unless an exemption applies, plus transfer tools for data leaving the EU.

Is this legal advice?

The implementation is compliance work. Questions that need a formal legal position go to the practising privacy lawyer engaged on your project. Outside the EU, local counsel gives the opinion and is named in the quote.

We already have a privacy policy and some DPAs. Does that count?

It shortens the assessment. We review what exists, keep what is accurate and rewrite what is not. Most teams find the policy describes a company they were two years ago.

What do we do after hand-over?

Keep the records current, run DPIAs for new processing, answer requests within one month and review notices when products change. GRCTrail tracks those tasks if you keep the platform. The documents stay yours either way.

Tell us what data you hold and where your customers are.

You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.