GDPR · UK GDPR

Show your data protection is more than a policy

We assess the technical and organisational measures behind your GDPR obligations, focusing on security of processing, breach readiness and the evidence you need for accountability.

Book a GDPR / UK GDPR assessmentSee a sample report
RegulationEU GDPR and UK GDPR
Enforced byEU supervisory authorities and the ICO
Structure7 principles · Article 32 security
Suited toAny organisation processing EU or UK personal data
01 · The framework

The seven principles

Article 5 sets the principles every processing activity must meet. Our assessment focuses on the measures that prove them. We work alongside your DPO and legal counsel, not in place of them.

1Lawfulness, fairness and transparency
2Purpose limitation
3Data minimisation
4Accuracy
5Storage limitation
6Integrity and confidentiality
7Accountability
02 · Focus areas

Where we focus

The parts of GDPR where security evidence decides the outcome.

Article 32Security of processingMeasures appropriate to the risk, including encryption, resilience and regular testing.
Articles 33–34Breach notificationReporting to the regulator within 72 hours, and to individuals where risk is high.
Article 35DPIAsRisk assessment for high-risk processing, informed by real control data.
03 · How we assess

Evidence first, interviews second

Every rating is backed by evidence from your environment, so the result reflects what is running, not what the policy says. A baseline typically takes two weeks.

  1. 01ScopeAgree the target, the systems in scope and who we need to speak to.
  2. 02CollectInterviews, document review and live data from Pulse and Trace.
  3. 03ScoreRate every requirement against your target, with evidence for each rating.
  4. 04ReportA prioritised roadmap and a short board briefing.
04 · What you receive

A result you can act on

Findings map across frameworks, so work done for GDPR / UK GDPR counts towards the others you hold.

✓Scored gap analysisStatus for every requirement against your target, backed by evidence.
✓Prioritised roadmapP1 to P3 work packages with owners, dates and exit criteria.
✓Board briefingA short summary of where you stand and the decisions needed.
✓Evidence kept currentResults live in Attest and update as your environment changes.
Often assessed together
ISO/IEC 27001:2022 NIS2 Directive SOC 2

Know where you stand against GDPR / UK GDPR in two weeks

A baseline assessment with a prioritised roadmap and a board-ready summary.

Book a GDPR / UK GDPR assessment