Skip to content

Solutions / By mandate

GDPR

Evidence that your technical and organisational measures are appropriate — the thing a supervisory authority actually asks for after a breach.

What you receive

  • Article 32 measures assessment
  • Breach notification workflow
  • Data-flow and processor mapping
  • DPIA technical input

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    Ransomware hit and nothing was exfiltrated

    Article 4(12) defines a personal data breach to include accidental or unlawful destruction and loss, so an availability event qualifies with no data taken at all. The Article 33(5) record has to exist either way, and the notification decision still has to be made.

  • 02

    A controller is auditing you as a processor

    Article 28 obliges processors to implement Article 32 measures and to allow audits and inspections by the controller. What arrives is a long questionnaire, and answering it credibly needs technical evidence about your own systems rather than assertions.

  • 03

    Your DPIA identifies high risk and stops

    Article 35(7) requires the measures envisaged to address the risks, including the safeguards and security measures. A DPIA that names the risk but not the controls leaves you heading into Article 36 prior consultation with nothing to show.

How it runs

  1. 01

    Where you actually are

    A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.

  2. 02

    What the obligation really requires

    We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.

  3. 03

    A scoped programme

    The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.

  4. 04

    Evidence, not a gap report

    The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • Lawful basis, consent design, retention periods and data subject rights are work for your DPO or counsel, not for this engagement.

  • Notifying a supervisory authority or affected individuals is your decision and your filing; we supply the technical facts behind it.

  • Transfer mechanisms — adequacy, standard contractual clauses and transfer impact assessments — sit outside the technical scope here.

Measured against

GDPR Art. 32
Requires measures appropriate to the risk and a process for regularly testing and evaluating their effectiveness.
GDPR Art. 35
Requires a DPIA for high-risk processing, including the measures envisaged to address the risks it identifies.
EDPB Guidelines 9/2022
Set out how supervisory authorities expect breach awareness, assessment and notification to be handled, with worked examples.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Does encryption remove the duty to notify?

It can remove either duty, but they are tested separately. Article 33 notification falls away only where the breach is unlikely to result in a risk to people; Article 34 communication to individuals falls away where the data is unintelligible to anyone unauthorised. Both turn into a question about key management, and about whether you can show the keys were never exposed.

What makes technical measures appropriate?

Article 32 makes it relative to the state of the art, the cost of implementation and the risk to people, so there is no fixed list to certify against. It is judged comparatively, against what a similar organisation holding similar data was doing.

Does an ISO 27001 certificate satisfy Article 32?

It is not a certification mechanism under Article 42, and it evidences a management system within a stated scope rather than the measures around one processing operation. Article 32(1)(d) also requires regular testing of those measures.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.