BY BUSINESS OBJECTIVE
ASSESS & VALIDATE — FIND WEAKNESSES
Digisecuritas logo

COMPLIANCE & FRAMEWORK

GDPR compliance and data protection assessment

GDPR accountability depends on being able to explain what personal data is used, why it is needed, who receives it, how it is protected, and how individual rights are handled.

Digisecuritas helps organisations assess these practices, identify gaps, strengthen technical and organisational measures, and build a practical GDPR improvement roadmap.

Processing visibility. Clear ownership. Defensible evidence.

PROCESSING VISIBILITY

Every privacy obligation connects to a processing activity

A privacy policy cannot explain the complete operating environment. Personal data may move through departments, applications, vendors, cloud platforms, analytics tools, support processes, and international locations.

A structured record of processing activities provides the context needed to assess lawful basis, transparency, individual rights, retention, security, and external transfers.

PROCESSING FIELDQUESTION TO ANSWER
PurposeWhy is personal data being used?
IndividualsWhose information is involved?
Data categoriesWhat personal data is processed?
Lawful basisWhat permits the processing?
RecipientsWho receives or accesses the data?
LocationsWhere is the data stored or accessed?
RetentionHow long is the information required?
SafeguardsHow is the information protected?

Output: A current view of processing that teams can use for privacy decisions.

DATA PROTECTION PRINCIPLES

The principles should be visible in everyday decisions

Lawfulness, fairness, and transparency

Process personal data through an appropriate lawful basis and explain the activity clearly to individuals.

Purpose limitation

Collect personal data for specified and legitimate purposes and review incompatible reuse.

Data minimisation

Limit collection and use to the information reasonably required for the defined purpose.

Accuracy

Keep personal data accurate and provide a process for correcting incomplete or incorrect information.

Storage limitation

Retain identifiable personal data only for as long as the purpose and relevant obligations require.

Integrity and confidentiality

Use appropriate technical and organisational measures to protect personal data.

Accountability

Maintain responsibility, documentation, evidence, and oversight that demonstrate how the principles are applied.

RESPONSIBILITY CHAIN

Privacy responsibility continues through the service chain

Controller

Determines the purposes and means of processing.

REVIEW AREAS

  • Processing purpose
  • Lawful basis
  • Transparency
  • Individual rights
  • Processor selection
  • Risk and impact decisions

Article 28 terms

Instructions

Confidentiality

Security

Assistance

Deletion or return

Audit information

Processor

Processes personal data on documented instructions from the controller.

REVIEW AREAS

  • Instruction management
  • Security measures
  • Breach notification
  • Rights request support
  • Processing records
  • Subprocessor oversight

Authorisation and flow down

Subprocessor

Provides downstream processing services on behalf of the processor.

REVIEW AREAS

  • Approved scope
  • Equivalent obligations
  • Data locations
  • Security evidence
  • Incident responsibilities
  • Service termination

A contract defines responsibilities. Evidence shows whether those responsibilities are being met.

LAWFUL PROCESSING

Choose the lawful basis before processing begins

DECISION QUESTIONS

1.What is the specific processing purpose?
2.Is the processing necessary for that purpose?
3.Does another less intrusive method exist?
4.Which lawful basis matches the activity?
5.Which evidence and information must be retained?

LAWFUL BASES

Consent

The individual has given valid consent for one or more specified purposes.

Contract

Processing is necessary for a contract with the individual or requested precontractual steps.

Legal obligation

Processing is necessary to comply with an applicable legal obligation.

Vital interests

Processing is necessary to protect someone's vital interests.

Public task

Processing is necessary for a public interest task or official authority.

Legitimate interests

Processing is necessary for a legitimate interest that is not overridden by individual rights and interests.

The selected basis should reflect the actual purpose and conditions of processing. Consent should not be used as a default.

Special category data requires a separate applicable condition where relevant.

INDIVIDUAL RIGHTS

A rights request must reach every relevant system

Responding to a request can require coordination across privacy, legal, customer service, HR, IT, security, records management, and external service providers.

GDPR INDIVIDUAL RIGHTS

AccessRectificationErasureRestrictionPortabilityObjectionRights related to certain automated decisions

HIGH RISK PROCESSING

Assess privacy impact before high risk processing begins

01Describe the processing

Document its nature, scope, context, purposes, data, technology, and involved parties.

02Assess necessity and proportionality

Examine whether the processing is suitable, limited, and proportionate to the purpose.

03Identify potential impacts

Consider how the activity could affect the rights and freedoms of individuals.

04Evaluate safeguards

Review measures intended to prevent, reduce, or respond to those impacts.

05Consult relevant stakeholders

Include the Data Protection Officer and other appropriate internal or external stakeholders where required.

06Record the outcome

Document residual risk, approvals, required actions, ownership, and review conditions.

ASSESSMENT OUTCOME

Proceed

Risks are addressed within approved tolerance and conditions.

Revise

The activity requires stronger controls or a different design.

Escalate

High residual risk may require prior consultation with the competent supervisory authority.

CROSS BORDER DATA

Every international transfer needs a defined route and safeguard

Checkpoint 01

Identify the transfer

Determine whether personal data is disclosed or made available to a recipient in a third country or international organisation.

Checkpoint 02

Identify the transfer mechanism

Confirm whether the transfer relies on an adequacy decision, appropriate safeguards, or a relevant derogation.

Checkpoint 03

Assess the transfer context

Review the countries, recipients, access risks, contractual commitments, technical measures, and practical circumstances.

Checkpoint 04

Maintain evidence

Record the transfer, selected mechanism, assessment, supplementary measures, approvals, and review schedule.

Adequacy decision
Standard Contractual Clauses
Binding Corporate Rules
Applicable derogation

The correct transfer mechanism and assessment depend on the circumstances of the processing. Legal review may be required.

TECHNICAL AND ORGANISATIONAL MEASURES

Security measures should reflect the risk to individuals

01

Governance and people

PoliciesResponsibilitiesAwarenessTrainingAccess approvalConfidentialitySupplier oversight
02

Identity and data protection

Access controlAuthenticationEncryptionPseudonymisationData minimisationSecure sharing
03

Infrastructure and applications

Secure configurationVulnerability managementLoggingMonitoringApplication securityBackupResilience
04

Response and assurance

Incident responseBreach assessmentTestingAuditControl reviewCorrective actionEvidence

BREACH RESPONSE

The notification decision begins with a documented risk assessment

Stage 01

Detect and contain

Escalate the event, protect affected systems, preserve evidence, and limit further exposure.

Stage 02

Confirm personal data involvement

Identify affected information, systems, individuals, recipients, processors, and jurisdictions.

Stage 03

Assess risk to individuals

Consider the nature of the data, likely consequences, protective measures, affected people, and scale.

Where notification to the supervisory authority is required, it must be made without undue delay and, where feasible, within 72 hours after awareness.

Stage 04

Decide notification duties

Determine whether notification to the competent supervisory authority is required and record the rationale.

Stage 05

Communicate where required

Prepare accurate communication for regulators, affected individuals, controllers, or other relevant parties.

Stage 06

Document the breach

Record the facts, effects, decisions, mitigation, notifications, and corrective actions.

OUR SERVICES

GDPR assessment and advisory services

GDPR readiness and gap assessment

Assess governance, processing activities, documentation, privacy operations, security measures, and supporting evidence.

Data inventory and processing records

Identify personal data flows and develop or improve records of processing activities.

Controller and processor assessment

Clarify organisational roles, contractual responsibilities, evidence, and processor oversight.

Privacy notice and lawful basis review

Compare notices, purposes, lawful bases, data practices, and consent processes.

Individual rights readiness

Assess request intake, verification, searches, decisions, response workflows, and records.

DPIA process development

Establish screening, assessment, approval, risk treatment, and review processes for high risk processing.

International transfer assessment

Identify transfers, review mechanisms, organise evidence, and assess required safeguards.

Security and breach readiness

Evaluate technical and organisational measures, incident coordination, breach assessment, and notification procedures.

Need help defining the right GDPR assessment scope?

Discuss your processing environment

ACCOUNTABILITY EVIDENCE

Evidence behind GDPR accountability

ACCOUNTABILITY AREA

Processing visibility

WHAT WE EXAMINE

Purposes, data, individuals, recipients, and retention

EXAMPLE EVIDENCE

Records of processing and data flow records

ACCOUNTABILITY AREA

Lawful basis

WHAT WE EXAMINE

Reason for processing and required conditions

EXAMPLE EVIDENCE

Basis records, consent evidence, assessments

ACCOUNTABILITY AREA

Transparency

WHAT WE EXAMINE

Accuracy and clarity of information provided

EXAMPLE EVIDENCE

Privacy notices and revision records

ACCOUNTABILITY AREA

Individual rights

WHAT WE EXAMINE

Intake, searches, decisions, timing, and response

EXAMPLE EVIDENCE

Request register and response evidence

ACCOUNTABILITY AREA

Processor governance

WHAT WE EXAMINE

Selection, contracts, instructions, and monitoring

EXAMPLE EVIDENCE

Agreements, assessments, review records

ACCOUNTABILITY AREA

DPIAs

WHAT WE EXAMINE

Screening, impact assessment, approval, and treatment

EXAMPLE EVIDENCE

DPIA records and action plans

ACCOUNTABILITY AREA

International transfers

WHAT WE EXAMINE

Transfer mechanism and safeguards

EXAMPLE EVIDENCE

Clauses, assessments, approvals

ACCOUNTABILITY AREA

Security

WHAT WE EXAMINE

Technical and organisational protections

EXAMPLE EVIDENCE

Policies, configurations, test records

ACCOUNTABILITY AREA

Breach readiness

WHAT WE EXAMINE

Assessment, escalation, notification, and correction

EXAMPLE EVIDENCE

Incident records and decision logs

HOW WE WORK

How the GDPR engagement works

01

Define the scope

Confirm entities, jurisdictions, business functions, processing roles, systems, and external providers.

02

Discover processing

Review documentation, interview stakeholders, trace personal data, and identify important processing activities.

03

Assess obligations

Examine principles, lawful bases, transparency, rights, processors, transfers, DPIAs, security, and breach readiness.

04

Validate controls

Review policies, procedures, system settings, records, contracts, training, and operational evidence.

05

Prioritise gaps

Rank findings based on risk to individuals, legal relevance, business impact, and implementation effort.

06

Build the roadmap

Define recommended actions, owners, dependencies, timeframes, and evidence expectations.

Outcome: A practical GDPR improvement plan connected to real processing activities.

WHEN TO ENGAGE

When organisations need GDPR support

Expanding into Europe

The organisation plans to offer products or services to individuals in the EEA or monitor relevant behaviour and needs to evaluate GDPR applicability.

Launching a new product or technology

A new application, platform, AI system, analytics capability, or customer process changes how personal data is used.

Responding to customer due diligence

Enterprise customers require clearer evidence of privacy governance, security, processing roles, and international transfer safeguards.

Replacing outdated privacy documentation

Existing notices, processing records, agreements, and assessments no longer reflect current systems or operations.

Preparing after an incident

The organisation needs to strengthen breach assessment, processor coordination, notification readiness, and corrective action.

Privacy decisions need legal context and operational evidence

Digisecuritas examines how personal data moves through technology, teams, service providers, and business processes.

Our work focuses on privacy governance, cybersecurity, controls, risk, and evidence. Where formal legal interpretation is required, the organisation should involve qualified privacy counsel.

01

Independent assessment

Receive an objective view without privacy technology or implementation bias.

02

Privacy and cybersecurity perspective

Connect processing obligations with access, data protection, cloud services, monitoring, and incident response.

03

Evidence based findings

Assess what teams do in practice and the records that support those activities.

04

Clear ownership

Define responsibilities across business, privacy, security, technology, and external providers.

05

Practical remediation

Turn identified gaps into sequenced actions and evidence expectations.

06

Executive visibility

Give leadership a clear view of exposure, priorities, and unresolved decisions.

FREQUENTLY ASKED QUESTIONS

Common questions about GDPR

Make GDPR accountability visible

Understand how personal data is processed, identify material gaps, and build a clear roadmap for stronger privacy governance.