info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST

GDPR

Article 30 records, lawful basis, data subject rights and Chapter V transfers — assessed against the specific articles, with a route to ISO/IEC 27701 if you want a certifiable outcome.

The General Data Protection Regulation (GDPR) is the European Union regulation governing the protection and free movement of personal data. It applies to any organization that processes the personal data of individuals in the EU.

GDPR applies extraterritorially: a US company with no EU establishment is still in scope if it offers goods or services to people in the EU or monitors their behavior.

A note on terminology: GDPR is a regulation, not a certifiable management system. Article 42 provides for certification schemes, but those must be approved by a supervisory authority or the European Data Protection Board and issued by a body accredited under Article 43, and no scheme covers "GDPR compliance" as a whole. What organizations can demonstrate is documented accountability under Article 5(2) — which is what this assessment produces. Where a certifiable outcome is wanted, ISO/IEC 27701 is the privacy information management system that maps to GDPR, and we can arrange certification to it through an accredited CAB in our network.

What the assessment covers

  • Article 30 records of processing, and data mapping across systems and third parties
  • Article 6 lawful basis for each processing activity, and Article 9 conditions where special category data is involved
  • Articles 13 and 14 transparency and privacy notices
  • Articles 15–22 data subject rights — and whether you can actually meet the one-month deadline
  • Article 35 data protection impact assessments
  • Chapter V international transfers: standard contractual clauses, transfer impact assessments, adequacy
  • Article 28 processor and sub-processor contracts
  • Articles 33 and 34 breach detection and the 72-hour notification obligation
  • Article 32 security of processing, including technical testing where in scope

What you receive

  • An Article 30 record of processing activities you can hand to a supervisory authority
  • A gap register against the specific articles, rated and prioritized
  • A remediation roadmap, and a route to ISO/IEC 27701 certification if you want a certifiable outcome

Who it is for

US companies selling into the EU, SaaS platforms processing EU personal data on behalf of customers, and any organization whose EU customers have started sending data processing agreements and transfer impact assessments.

Talk to us about certification or a penetration test

Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.