SECOMPSSECOMPS
CMP 03

GDPR compliance.

If you process the personal data of people in the EU or UK, GDPR applies whether or not you have an office there. We build the data map, the assessments and the processes that make that defensible.

At a glance

Applies to
Any organisation processing EU or UK personal data
Timeline
2 to 4 months for readiness
Key artefacts
Data map, RoPA, DPIAs, processor agreements
Breach obligation
72 hours to notify the supervisory authority
Penalties
Up to 4 percent of global annual turnover
01Overview

What this actually is.

Most GDPR programmes fail on the first step. You cannot protect, minimise or delete data you have not mapped, and almost every organisation is processing more personal data in more places than its privacy notice claims. We start with the inventory because everything else depends on it.

02Scope

What we cover.

Data mapping and inventoryEvery system, every category of personal data, every purpose, every recipient and every retention period, including the systems nobody mentioned.
Record of Processing ActivitiesThe Article 30 record, built from the data map and maintained rather than written once.
Lawful basis assessmentA defensible basis for each processing activity, including legitimate interest assessments where relied upon.
Data Protection Impact AssessmentsFor high-risk processing, including profiling, large-scale special category data and systematic monitoring.
Processor and sub-processor agreementsArticle 28 terms with your vendors, plus transfer mechanisms for data leaving the EEA or UK.
Data subject rightsWorking processes for access, rectification, erasure, portability and objection, tested against your real systems.
Breach responseDetection, assessment and notification within 72 hours, rehearsed rather than documented and forgotten.
Privacy by designPractical controls in your development lifecycle so new features do not create new exposure.
03Fit

Who needs this.

  • SaaS and technology companies with any EU or UK users
  • Businesses expanding into European markets
  • Organisations acting as processors for EU-based controllers
  • Companies whose customers are sending them Article 28 questionnaires
04Questions

Frequently asked.

We are based in India. Does GDPR apply to us?

If you offer goods or services to people in the EU or UK, or monitor their behaviour, then yes, regardless of where you are established. Being a processor for an EU controller also brings direct obligations under Article 28.

Do we need a Data Protection Officer?

A DPO is mandatory for public authorities, for large-scale systematic monitoring, and for large-scale special category processing. Many organisations do not require one but benefit from a named privacy owner. We will tell you plainly which applies.

How does this relate to India's DPDP Act?

The obligations rhyme: notice, consent, purpose limitation, security safeguards and breach notification. A well-built GDPR programme covers most of the DPDP Act's requirements, and we map both together where you are subject to each.

What about international transfers?

Transfers outside the EEA or UK need a valid mechanism, most commonly Standard Contractual Clauses supported by a transfer impact assessment. We put those in place and document the assessment.

Find out what stands between you and certification.

Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.