The world's most far-reaching data protection law. GDPR governs how you collect, process, and transfer the personal data of EU residents — and it applies wherever your company is based if you serve EU customers.
The General Data Protection Regulation is binding EU law, not a certification. It sets out principles for lawful processing, strengthens individual rights, and imposes obligations such as records of processing, data protection impact assessments, breach notification, and — in many cases — a Data Protection Officer.
Its reach is extraterritorial: any organisation offering goods or services to people in the EU must comply, regardless of where it operates. Penalties run to €20 million or 4% of global annual turnover, whichever is higher.
Compliance is an ongoing programme rather than a one-time event. ISO 27701 provides a certifiable privacy management system that maps directly onto GDPR obligations.
Applies regardless of where your company is registered.
Organisations whose model depends on collecting or processing personal data.
Both sides of a data relationship carry distinct GDPR obligations.
Delivered through our specialist network. We map your data flows, build the required documentation and processes, and — where you want certifiable proof — implement ISO 27701 on top, giving you an auditable privacy management system rather than a binder of policies.
We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.
A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.
We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.
The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.
We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.
Yes, if you offer goods or services to people in the EU or monitor their behaviour. The regulation is deliberately extraterritorial, which is why GCC and other non-EU companies routinely need a GDPR programme.
There's no single official GDPR certificate, but ISO 27701 gives you a certifiable privacy information management system that demonstrates systematic compliance — which is the closest auditable proof available and what we typically recommend.
Book a free advisory session and we'll map your fastest credible route to compliance.
Book a free advisory session