The General Data Protection Regulation (GDPR) is the European Union regulation governing the protection and free movement of personal data. It applies to any organization that processes the personal data of individuals in the EU.
GDPR applies extraterritorially: a US company with no EU establishment is still in scope if it offers goods or services to people in the EU or monitors their behavior.
A note on terminology: GDPR is a regulation, not a certifiable management system. Article 42 provides for certification schemes, but those must be approved by a supervisory authority or the European Data Protection Board and issued by a body accredited under Article 43, and no scheme covers "GDPR compliance" as a whole. What organizations can demonstrate is documented accountability under Article 5(2) — which is what this assessment produces. Where a certifiable outcome is wanted, ISO/IEC 27701 is the privacy information management system that maps to GDPR, and we can arrange certification to it through an accredited CAB in our network.
US companies selling into the EU, SaaS platforms processing EU personal data on behalf of customers, and any organization whose EU customers have started sending data processing agreements and transfer impact assessments.
Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.