Full GDPR Compliance Check
Our GDPR compliance check analyses how your company collects, uses, stores, and manages personal data to ensure compliance with GDPR requirements.
Included in the GDPR Compliance Check:
Data Mapping and Inventory: We'll help you to identify and document all types of personal data the company collects and help you understand where this data comes from, how it is processed, and where it is stored.
Policies and Procedures Review: We will examine your company's privacy policies, data protection policies, and other relevant documentation to ensure they are up-to-date and compliant with GDPR.
Legal Basis for Processing: We will ensure there is a legal basis for all types of data processing activities, for example, consent from customers to use their personal data for marketing purposes.
Data Protection Impact Assessment (DPIA): We'll conduct DPIAs for processing activities that pose a high risk to individuals' rights and freedoms, such as extensive data processing or profiling.
Data Subject Rights: We'll verify processes are in place to handle data subject requests, such as requests for data access, correction, deletion, or data portability, within the timeframes stipulated by GDPR.
Data Breach Response and Notification Procedures: We'll ensure there are procedures to detect, report, and investigate personal data breaches.
Data Transfer / Location: If data is transferred outside the European Economic Area (EEA), we'll check that appropriate safeguards are in place.
Training and Awareness: We'll assess whether staff members are trained and aware of their GDPR obligations, especially those handling personal data.
Vendor and Third-Party Management: We'll review contracts and processes involving third parties and vendors who process personal data on the company's behalf to ensure they are GDPR compliant.
Security: We'll evaluate the technical and organisational security measures to protect personal data from unauthorised access, alteration, or destruction.
Record Keeping: We'll check if records of processing activities are being maintained as required by GDPR.
Ongoing Monitoring and Compliance: We'll assess the mechanisms for regularly reviewing and updating data protection measures.