GDPR
EU & UKBy lawGeneral Data Protection Regulation
- Who it binds
- Any company processing personal data of people in the EU or UK, regardless of where your company is based.
- What teams get wrong
- Most teams write a privacy policy and stop. The regulation asks for a Record of Processing Activities, a lawful basis per purpose, a DPIA for high-risk processing, and a documented process for answering a data subject request in 30 days.
- What we do
- Data mapping and Record of Processing Activities (Article 30)
- Lawful basis assessment and consent mechanics
- DPIAs for high-risk processing
- Data subject request workflow, tested end to end
- International transfer assessments and Standard Contractual Clauses
- Processor agreements and sub-processor register
- 72-hour breach notification runbook