GDPR current state and gap analysis
Where do you stand against the GDPR today? A documented current state, identified gaps and a prioritised action plan management can decide on.
Who it is for and when
Suits organisations that process personal data and need to know where they stand, either because nobody has gone through it systematically or because a customer, owner or supervisory authority has asked.
- Nobody has gone through data protection systematically since the GDPR came into force.
- A customer or procurement requires you to show how you meet the requirements.
- You are not sure where all personal data is held or how long it is kept.
- An incident or a question from the supervisory authority has put data protection in the spotlight.
What we do
- Scope and processing activities. We agree which parts of the business and which processing of personal data are included, and review what documentation exists today.
- Review against the GDPR requirements. Legal basis, information to data subjects, records of processing, retention, processors, security and incident handling are reviewed with those who own the questions.
- Gap per requirement. Each requirement is assessed as in place, partly in place or missing, with a short rationale and evidence.
- Risk assessment. The gaps are weighed by the risk to data subjects and to the business, not just by how easy they are to close.
- Action plan and management walkthrough. A prioritised plan with proposed ownership and sequence, presented so that decisions can be taken straight away.
What you get
- A documented current state per requirement
- Identified gaps with rationale and evidence
- A prioritised action plan with proposed ownership and sequence
- A walkthrough with management
- Documentation you can show a customer, owner or supervisory authority
Scope and price
A defined engagement that normally takes a few days to about a week, depending on the size of the organisation, how many processing activities are included and how much documentation exists.
The price varies from engagement to engagement and depends on the scope above. You get an estimated cost proposal and, where possible, a fixed price. Implementing the actions is quoted separately.
How it works
- A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.
Frequently asked questions
How does this differ from a gap analysis against ISO 27001?
The GDPR is law governing the processing of personal data. ISO 27001 is a standard for an information security management system. They overlap on security but answer different questions, and many organisations do both.
Do we need records of processing before you start?
No. If records exist the work goes faster, but if they are missing that absence becomes one of the gaps and we propose how to build them.
Is implementing the actions included?
No, the analysis delivers the plan. Implementation is quoted separately and can be done by you or together with us.
Would you like to know where you stand against the GDPR?
Contact us