Compliance · Regulation
It applies to you based on whose data you touch — not where you're incorporated.
The GDPR governs personal data of people in the EU and UK, regardless of where your company sits. It's a law, not a certification — so the goal isn't a certificate, it's being able to demonstrate accountability when a customer, partner, or regulator asks.
72 hrs
Breach notification
4% / €20M
Max penalty
Extra-territorial
Reach
Accountability is the theme — you must not only comply, but be able to show it.
Every processing activity needs a lawful basis and a defined purpose. 'We might need it later' is not one, and consent is not always the right choice.
Access, rectification, erasure, portability, restriction, and objection — each with statutory deadlines you have to meet operationally, not theoretically.
ROPAs, DPIAs for high-risk processing, processor contracts, and a lawful mechanism for moving data outside the EEA.
Far more organizations than realize it.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We find the personal data, map the flows, and build the records of processing everything else depends on.
We assign and document a defensible basis per activity, and fix the ones relying on consent that shouldn't.
We make access and erasure requests a repeatable process that completes inside the deadline.
We run impact assessments for high-risk processing and implement transfer mechanisms like SCCs.
We get Article 28 terms in place and bring your sub-processors under control.
We build the detection, assessment, and notification path that makes 72 hours achievable.
Discover personal data, flows, and purposes; build the ROPA.
Gap the current state against the regulation.
Fix lawful basis, notices, contracts, retention, and security.
Stand up rights handling, DPIAs, and breach response.
Keep the evidence that proves accountability on demand.
Not in the way you certify to ISO 27001. The GDPR anticipates certification mechanisms under Article 42, but approved schemes are limited and none is a general 'GDPR certificate'. Anyone selling you one is overstating it. In practice, ISO 27701 is the strongest certifiable evidence of a privacy program.
If you offer goods or services to people in the EU/UK, or monitor their behavior, then yes — the regulation reaches you regardless of where you're incorporated. Having EU-based users or employees is usually enough to bring you in scope.
A DPO is mandatory for public authorities, for large-scale systematic monitoring, and for large-scale processing of special category data. Many other organizations appoint one voluntarily or use an outsourced DPO. We'll assess whether you're required to and support the role either way.
It starts when you become aware of a personal data breach, and you notify the supervisory authority unless the breach is unlikely to result in risk to individuals. The practical problem is rarely the notice — it's being able to assess scope and risk fast enough to make the decision. That's a detection and response problem.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.