COMPLIANCE & FRAMEWORK
GDPR compliance and data protection assessment
GDPR accountability depends on being able to explain what personal data is used, why it is needed, who receives it, how it is protected, and how individual rights are handled.
Digisecuritas helps organisations assess these practices, identify gaps, strengthen technical and organisational measures, and build a practical GDPR improvement roadmap.
Processing visibility. Clear ownership. Defensible evidence.
PROCESSING VISIBILITY
Every privacy obligation connects to a processing activity
A privacy policy cannot explain the complete operating environment. Personal data may move through departments, applications, vendors, cloud platforms, analytics tools, support processes, and international locations.
A structured record of processing activities provides the context needed to assess lawful basis, transparency, individual rights, retention, security, and external transfers.
Output: A current view of processing that teams can use for privacy decisions.
DATA PROTECTION PRINCIPLES
The principles should be visible in everyday decisions
Process personal data through an appropriate lawful basis and explain the activity clearly to individuals.
Collect personal data for specified and legitimate purposes and review incompatible reuse.
Limit collection and use to the information reasonably required for the defined purpose.
Keep personal data accurate and provide a process for correcting incomplete or incorrect information.
Retain identifiable personal data only for as long as the purpose and relevant obligations require.
Use appropriate technical and organisational measures to protect personal data.
Maintain responsibility, documentation, evidence, and oversight that demonstrate how the principles are applied.
RESPONSIBILITY CHAIN
Privacy responsibility continues through the service chain
Controller
Determines the purposes and means of processing.
REVIEW AREAS
- —Processing purpose
- —Lawful basis
- —Transparency
- —Individual rights
- —Processor selection
- —Risk and impact decisions
Article 28 terms
Instructions
Confidentiality
Security
Assistance
Deletion or return
Audit information
Processor
Processes personal data on documented instructions from the controller.
REVIEW AREAS
- —Instruction management
- —Security measures
- —Breach notification
- —Rights request support
- —Processing records
- —Subprocessor oversight
Authorisation and flow down
Subprocessor
Provides downstream processing services on behalf of the processor.
REVIEW AREAS
- —Approved scope
- —Equivalent obligations
- —Data locations
- —Security evidence
- —Incident responsibilities
- —Service termination
A contract defines responsibilities. Evidence shows whether those responsibilities are being met.
LAWFUL PROCESSING
Choose the lawful basis before processing begins
DECISION QUESTIONS
LAWFUL BASES
Consent
The individual has given valid consent for one or more specified purposes.
Contract
Processing is necessary for a contract with the individual or requested precontractual steps.
Legal obligation
Processing is necessary to comply with an applicable legal obligation.
Vital interests
Processing is necessary to protect someone's vital interests.
Public task
Processing is necessary for a public interest task or official authority.
Legitimate interests
Processing is necessary for a legitimate interest that is not overridden by individual rights and interests.
The selected basis should reflect the actual purpose and conditions of processing. Consent should not be used as a default.
Special category data requires a separate applicable condition where relevant.
INDIVIDUAL RIGHTS
A rights request must reach every relevant system
Responding to a request can require coordination across privacy, legal, customer service, HR, IT, security, records management, and external service providers.
Receive
Provide accessible channels for individuals to submit requests.
GDPR INDIVIDUAL RIGHTS
HIGH RISK PROCESSING
Assess privacy impact before high risk processing begins
01Describe the processing
Document its nature, scope, context, purposes, data, technology, and involved parties.
02Assess necessity and proportionality
Examine whether the processing is suitable, limited, and proportionate to the purpose.
03Identify potential impacts
Consider how the activity could affect the rights and freedoms of individuals.
04Evaluate safeguards
Review measures intended to prevent, reduce, or respond to those impacts.
05Consult relevant stakeholders
Include the Data Protection Officer and other appropriate internal or external stakeholders where required.
06Record the outcome
Document residual risk, approvals, required actions, ownership, and review conditions.
ASSESSMENT OUTCOME
Proceed
Risks are addressed within approved tolerance and conditions.
Revise
The activity requires stronger controls or a different design.
Escalate
High residual risk may require prior consultation with the competent supervisory authority.
CROSS BORDER DATA
Every international transfer needs a defined route and safeguard
Identify the transfer
Determine whether personal data is disclosed or made available to a recipient in a third country or international organisation.
Identify the transfer mechanism
Confirm whether the transfer relies on an adequacy decision, appropriate safeguards, or a relevant derogation.
Assess the transfer context
Review the countries, recipients, access risks, contractual commitments, technical measures, and practical circumstances.
Maintain evidence
Record the transfer, selected mechanism, assessment, supplementary measures, approvals, and review schedule.
The correct transfer mechanism and assessment depend on the circumstances of the processing. Legal review may be required.
TECHNICAL AND ORGANISATIONAL MEASURES
Security measures should reflect the risk to individuals
Governance and people
Identity and data protection
Infrastructure and applications
Response and assurance
BREACH RESPONSE
The notification decision begins with a documented risk assessment
Detect and contain
Escalate the event, protect affected systems, preserve evidence, and limit further exposure.
Confirm personal data involvement
Identify affected information, systems, individuals, recipients, processors, and jurisdictions.
Assess risk to individuals
Consider the nature of the data, likely consequences, protective measures, affected people, and scale.
Where notification to the supervisory authority is required, it must be made without undue delay and, where feasible, within 72 hours after awareness.
Decide notification duties
Determine whether notification to the competent supervisory authority is required and record the rationale.
Communicate where required
Prepare accurate communication for regulators, affected individuals, controllers, or other relevant parties.
Document the breach
Record the facts, effects, decisions, mitigation, notifications, and corrective actions.
OUR SERVICES
GDPR assessment and advisory services
GDPR readiness and gap assessment
Assess governance, processing activities, documentation, privacy operations, security measures, and supporting evidence.
Data inventory and processing records
Identify personal data flows and develop or improve records of processing activities.
Controller and processor assessment
Clarify organisational roles, contractual responsibilities, evidence, and processor oversight.
Privacy notice and lawful basis review
Compare notices, purposes, lawful bases, data practices, and consent processes.
Individual rights readiness
Assess request intake, verification, searches, decisions, response workflows, and records.
DPIA process development
Establish screening, assessment, approval, risk treatment, and review processes for high risk processing.
International transfer assessment
Identify transfers, review mechanisms, organise evidence, and assess required safeguards.
Security and breach readiness
Evaluate technical and organisational measures, incident coordination, breach assessment, and notification procedures.
Need help defining the right GDPR assessment scope?
Discuss your processing environmentACCOUNTABILITY EVIDENCE
Evidence behind GDPR accountability
ACCOUNTABILITY AREA
Processing visibility
WHAT WE EXAMINE
Purposes, data, individuals, recipients, and retention
EXAMPLE EVIDENCE
Records of processing and data flow records
ACCOUNTABILITY AREA
Lawful basis
WHAT WE EXAMINE
Reason for processing and required conditions
EXAMPLE EVIDENCE
Basis records, consent evidence, assessments
ACCOUNTABILITY AREA
Transparency
WHAT WE EXAMINE
Accuracy and clarity of information provided
EXAMPLE EVIDENCE
Privacy notices and revision records
ACCOUNTABILITY AREA
Individual rights
WHAT WE EXAMINE
Intake, searches, decisions, timing, and response
EXAMPLE EVIDENCE
Request register and response evidence
ACCOUNTABILITY AREA
Processor governance
WHAT WE EXAMINE
Selection, contracts, instructions, and monitoring
EXAMPLE EVIDENCE
Agreements, assessments, review records
ACCOUNTABILITY AREA
DPIAs
WHAT WE EXAMINE
Screening, impact assessment, approval, and treatment
EXAMPLE EVIDENCE
DPIA records and action plans
ACCOUNTABILITY AREA
International transfers
WHAT WE EXAMINE
Transfer mechanism and safeguards
EXAMPLE EVIDENCE
Clauses, assessments, approvals
ACCOUNTABILITY AREA
Security
WHAT WE EXAMINE
Technical and organisational protections
EXAMPLE EVIDENCE
Policies, configurations, test records
ACCOUNTABILITY AREA
Breach readiness
WHAT WE EXAMINE
Assessment, escalation, notification, and correction
EXAMPLE EVIDENCE
Incident records and decision logs
HOW WE WORK
How the GDPR engagement works
Define the scope
Confirm entities, jurisdictions, business functions, processing roles, systems, and external providers.
Discover processing
Review documentation, interview stakeholders, trace personal data, and identify important processing activities.
Assess obligations
Examine principles, lawful bases, transparency, rights, processors, transfers, DPIAs, security, and breach readiness.
Validate controls
Review policies, procedures, system settings, records, contracts, training, and operational evidence.
Prioritise gaps
Rank findings based on risk to individuals, legal relevance, business impact, and implementation effort.
Build the roadmap
Define recommended actions, owners, dependencies, timeframes, and evidence expectations.
Outcome: A practical GDPR improvement plan connected to real processing activities.
WHEN TO ENGAGE
When organisations need GDPR support
Expanding into Europe
The organisation plans to offer products or services to individuals in the EEA or monitor relevant behaviour and needs to evaluate GDPR applicability.
Launching a new product or technology
A new application, platform, AI system, analytics capability, or customer process changes how personal data is used.
Responding to customer due diligence
Enterprise customers require clearer evidence of privacy governance, security, processing roles, and international transfer safeguards.
Replacing outdated privacy documentation
Existing notices, processing records, agreements, and assessments no longer reflect current systems or operations.
Preparing after an incident
The organisation needs to strengthen breach assessment, processor coordination, notification readiness, and corrective action.
Privacy decisions need legal context and operational evidence
Digisecuritas examines how personal data moves through technology, teams, service providers, and business processes.
Our work focuses on privacy governance, cybersecurity, controls, risk, and evidence. Where formal legal interpretation is required, the organisation should involve qualified privacy counsel.
Independent assessment
Receive an objective view without privacy technology or implementation bias.
Privacy and cybersecurity perspective
Connect processing obligations with access, data protection, cloud services, monitoring, and incident response.
Evidence based findings
Assess what teams do in practice and the records that support those activities.
Clear ownership
Define responsibilities across business, privacy, security, technology, and external providers.
Practical remediation
Turn identified gaps into sequenced actions and evidence expectations.
Executive visibility
Give leadership a clear view of exposure, priorities, and unresolved decisions.
FREQUENTLY ASKED QUESTIONS
Common questions about GDPR
Make GDPR accountability visible
Understand how personal data is processed, identify material gaps, and build a clear roadmap for stronger privacy governance.
