GDPR
By lawEU & UK
Applies ifYou have any users, customers or staff in the EU or UK.
07 · Compliance
The obligations you have whether or not anyone asks.
ISO 27001 and SOC 2 are chosen. GDPR, HIPAA, COPPA and PCI DSS are not. They apply by law the moment you handle certain data or certain users. We work out which actually bind you, then build the evidence to show it.
The context
Certification frameworks are commercial decisions: a customer asks, you comply, a deal unblocks. Privacy regulation is different. It applies because of the data you hold and the people you hold it about, and it applied from the day you started, whether or not anyone has raised it.
That asymmetry is why we see the same pattern repeatedly, a company gets ISO 27001 certified, then discovers during an enterprise data protection review that it has no Record of Processing Activities, no lawful basis analysis, and no tested process for a data subject request. Certified, and still exposed.
We start by working out which regulations actually bind you, because the honest answer is often fewer than a vendor questionnaire implies. Then we build the specific artefacts each one demands, and map them onto your ISMS so the same evidence serves both.
Regulations we cover
And which don’t. That answer usually saves more money than any control we implement.
EU & UK
Applies ifYou have any users, customers or staff in the EU or UK.
United States
Applies ifYou touch protected health information for a US covered entity.
United States
Applies ifYour service is directed at under-13s, or you know they use it.
California, US
Applies ifYou do business with California residents above the revenue or data thresholds.
Global
Applies ifYou store, process or transmit cardholder data, including via an embedded payment form.
United States
Applies ifYou handle student education records for US schools or districts.
European Union
Applies ifYou are an EU cloud, managed service or other in-scope essential entity.
What is covered
Which regulations genuinely apply, based on your users, data, markets and contracts. We will tell you when something does not apply. That answer saves more money than any control we implement.
What personal data you hold, where it came from, why you hold it, who you share it with, where it goes, and how long you keep it. This underpins nearly every regulation on the list.
Data subject access, deletion, correction and opt-out, built as a process your team can actually run inside the statutory deadline, then tested with a live request.
Processor agreements, Business Associate Agreements, Standard Contractual Clauses, sub-processor registers, and a vendor review process proportionate to risk.
Each regulation has its own clock, 24 hours for NIS2, 72 for GDPR, 60 days for HIPAA. One runbook that satisfies all of the ones that bind you.
Mapping every obligation onto your ISO 27001 or SOC 2 control set so one body of evidence serves the certification and the regulator.
What you receive
Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.
Questions
If you process personal data of people in the EU or UK while offering them goods or services, yes, the regulation is extraterritorial and your own location is irrelevant. That said, scope is often narrower than teams fear. The applicability assessment exists precisely to establish what genuinely binds you rather than defaulting to everything.
You can, but understand what you are signing. A Business Associate Agreement makes you directly liable under HIPAA, including for the Security Rule's documented risk analysis. Sign it after you can meet it, not before. We regularly help teams get there in weeks rather than turn the deal down.
Your scope is dramatically reduced, but not eliminated. Which Self-Assessment Questionnaire applies depends on exactly how the payment form interacts with your page, a fully hosted redirect, an iframe, and a JavaScript element that touches your DOM are three different answers. Getting this wrong invalidates the assessment.
No. We are security and compliance consultants, not a law firm, and we do not give legal advice. We build the technical and organisational measures, the evidence and the processes these regulations require, and we work alongside your counsel on the legal interpretation. Where a statutory DPO is required, we help you appoint one.
It should. The overlap is substantial, data mapping, vendor review, access control, incident response and retention all serve both. Running them together typically adds 3 to 5 weeks rather than doubling the work.
End-to-end ISO 27001 implementation: gap analysis, ISMS build, evidence and audit support, right through Stage 2.
Read more02Type I and Type II readiness: control design, evidence discipline and auditor coordination, without the busywork.
Read more03Manual testing of web apps, APIs, mobile clients and authentication flows, with a report your engineers can act on.
Read moreTell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.
No sales sequence. A scoping call and a written proposal cost nothing.