[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeStandardsGDPR

Get Your GDPR Quote

Takes 30 seconds · a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
GDPR
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS · IAFAccredited
Regulation (EU) 2016/679 · EU General Data Protection RegulationEuropean Union

GDPR Compliance Audit the evidence enterprise buyers demand

GDPR reaches any organisation that offers goods or services to people in the EU or monitors their behaviour, wherever it is established. An independent audit tests lawful basis, records of processing, rights handling, processor contracts and international transfers against what your systems really do, and gives sales and legal something to send when the questionnaire arrives.

You need GDPR if…

  • !A prospect’s data processing agreement includes an audit right and your legal team cannot sign it with confidence.
  • !Enterprise procurement has asked for your record of processing activities and your transfer impact assessment.
  • !Data subject access requests arrive faster than the one-month deadline allows you to answer them.
  • !You are established outside the EU and have never appointed an Article 27 representative.
  • !A vendor breach exposed EU customer data and the 72-hour notification clock started with nobody owning it.
  • !Marketing consent, cookie banners and legitimate interests are being run on assumptions nobody has documented.
What it is

A European Union regulation governing personal data. It sets principles for lawful processing, gives individuals enforceable rights, requires accountability documentation, and controls how personal data leaves the European Economic Area.

Who issues it

GDPR is law, not a certification scheme. SIS conducts an independent compliance audit and issues a report and statement; formal Article 42 certification requires a body accredited under Article 43.

Validity

The report covers the scope and date of the audit. Reassess annually and after any material change to processing, vendors or transfer arrangements.

Who gets asked for it

Controllers and processors of any size with EU customers, users, employees or subjects, and non-EU firms selling into Europe or serving European clients.

5of 25 industries

Where this certification is demanded

GDPR is applicable across 5 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Hospitality IndustryTelecommunication IndustryEducation IndustryInformation Technology IndustryBanking and Finance

What GDPR Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
Scope & Role Mapping

Establish where Article 3 bites, which entities act as controller or processor for each activity, and whether an EU representative must be appointed under Article 27.

2
Records of Processing

An Article 30 record covering purposes, categories of data and recipients, retention periods and transfers, maintained as processing changes rather than written once.

3
Lawful Basis & Notices

A stated basis for every processing activity, special category conditions where relevant, evidenced consent where relied on, and privacy notices that match reality.

4
Data Subject Rights

A working route for access, rectification, erasure, portability and objection, with identity verification, redaction practice and responses inside the one-month deadline.

5
Processor Contracts & Transfers

Article 28 terms with every processor, a maintained subprocessor list, and transfers outside the EEA covered by adequacy, standard contractual clauses or binding corporate rules.

6
Security, DPIA & Breach

Security appropriate to the risk, impact assessments before high-risk processing, a breach register, and a procedure meeting the 72-hour supervisory authority deadline.

How GDPR Compliance Assessment Works

No black box. A defined, time-bound route from first call to assessment report.

Scope & Applicability Review

We confirm where the Regulation applies to you, which entities are controllers and which processors, whether an Article 27 representative is needed, and which supervisory authority leads.

3–5 days

Records & Data Flow Review

Article 30 records are read against how data actually moves, and the transfer inventory is where it falls apart: a subprocessor a product team added two years ago and never recorded.

2–4 weeks

Independent Compliance Audit

Evidence testing: notices and consent logs, response times on subject requests, impact assessments, Article 28 contracts, breach register, transfer impact assessments and security controls.

3–6 audit days

Audit Report & Statement

Non-conformities come with evidence references rather than a grade. If a supervisory authority later tests your accountability, what matters is that the gaps were identified and closed, and the report dates both.

Report in 10 working days
Four to eight weeks is normal for a first audit, driven mainly by how long it takes to assemble processor contracts and an honest data flow map; where a deal is blocked on it, the scope can be narrowed and the audit pulled forward.

Industries That Need GDPR

🏨
Hospitality Industry
Open full page →
Why it applies hereProperties marketing to or hosting European guests process EU personal data. GDPR requires lawful basis, transparent notices, honoured data subject rights, records of processing and controlled international transfers. It applies to booking engines, loyalty programmes and email marketing lists, and non-compliance surfaces fastest through OTA and corporate travel contract clauses.Typical trigger: European guests; OTA contracts
📡
Telecommunication Industry
Open full page →
Why it applies hereOperators with European subscribers, roaming arrangements or European enterprise customers process EU personal data. GDPR requires lawful basis, records of processing, honoured data subject rights and controlled international transfers, and appears directly in enterprise contract clauses and wholesale agreements.Typical trigger: European subscribers; enterprise contracts
🎓
Education Industry
Open full page →
Why it applies hereInstitutions recruiting international students, running exchange programmes or delivering courses to European learners process EU personal data. GDPR requires lawful basis, transparent notices, honoured data subject rights and controlled transfers, and partner universities examine compliance before entering collaboration agreements.Typical trigger: International recruitment; university partnerships
💻
Information Technology Industry
Open full page →
Why it applies hereServing European users or customers brings GDPR obligations on lawful basis, records of processing, data subject rights, subprocessor control and international transfers. It appears directly in data processing agreements, and gaps stall enterprise sales cycles more often than they trigger enforcement.Typical trigger: Data processing agreements; EU sales
🏦
Banking and Finance
Open full page →
Why it applies hereInstitutions with European customers, branches or processing arrangements face GDPR obligations on lawful basis, records of processing, data subject rights and international transfers. These appear directly in correspondent, outsourcing and technology contracts.Typical trigger: European operations; outsourcing contracts

Commonly taken alongside

ISO/IEC 27001 supplies the security controls GDPR requires and ISO/IEC 27701 extends them into a certifiable privacy management system, so one data map and one control set answers the audit, both certifications and most customer questionnaires.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

One report closes most of the questionnaire

Name the deal that is stuck, and the article your buyer keeps returning to. We will tell you whether a narrowed audit clears it before the quarter ends.

Get My Free Quote →

What GDPR Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

🔓

Deals stop stalling

Enterprise security and privacy reviews are where mid-size vendors lose weeks. An independent report answers most of the questionnaire before the call is booked.

⚖️

Fine exposure managed

The upper tier reaches €20 million or four per cent of worldwide annual turnover, whichever is higher. Documented accountability is what supervisory authorities weigh when deciding.

🌐

Transfers put right

Standard contractual clauses signed years ago and never revisited, and transfer impact assessments never done, are the most common finding and the easiest to fix once identified.

⏱️

Requests handled on time

A working process for access and erasure requests keeps you inside the one-month deadline. Most complaints reaching a supervisory authority start with a request that went unanswered.

🧾

Contracts that hold

Article 28 terms and a maintained subprocessor list mean the data processing agreement your customer sends can be signed without a fortnight of legal negotiation.

🧩

A route to certification

The same records, controls and contracts support ISO/IEC 27701 certification. A buyer who does not want to read an audit report will accept a certificate instead.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

TEMPLATE

Article 30 record of processing activities

A record structure covering purpose, lawful basis, data categories, recipients, retention and transfer mechanism for each processing activity.

CHECKLIST

Data processing agreement review points

The Article 28 terms to check before signing, including subprocessor consent, audit rights, breach timelines and deletion at contract end.

PDF GUIDE

Transfer impact assessments after Schrems II

How to assess a destination country’s regime, document supplementary measures and record the decision to transfer or stop.

WHITEPAPER

Answering enterprise privacy questionnaires without delay

What EU buyers examine in a vendor privacy review, and which missing artefacts most often stall a deal at legal review.

🔒 Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to GDPR.

Can we be certified to GDPR?
Not in the way you can be certified to an ISO standard. The Regulation does provide for certification mechanisms under Article 42, but those schemes must be approved by a supervisory authority or the European Data Protection Board, and only bodies accredited under Article 43 can issue them. Article 42 also states plainly that certification does not reduce the controller’s responsibility. An independent audit report is what most buyers actually ask for.
Does GDPR apply if we have no office in Europe?
Yes, where you offer goods or services to people in the EU or monitor their behaviour there. Selling in euros, shipping to EU addresses or running analytics on EU visitors all point that way. If Article 3(2) applies, you also need a representative in the Union under Article 27, which is one of the most frequently missed obligations among non-EU companies.
What happens if we miss the 72-hour breach deadline?
The clock runs from awareness, not from full understanding, and a partial notification followed by updates is expected rather than penalised. Missing it entirely is treated seriously, because supervisory authorities read late notification as weak governance. What matters in practice is a breach register, a named decision-maker and a documented assessment of risk to individuals for every incident, including the ones you decide not to report.
How does GDPR interact with ISO/IEC 27701?
ISO/IEC 27701 is a privacy extension to ISO/IEC 27001 and includes mapping to GDPR articles, so a certified privacy information management system covers a large part of the Regulation’s accountability, security and processor obligations. It is not a compliance ruling under the Regulation, but it is the most widely accepted certified evidence of a privacy management system, and it certifies in a form buyers recognise.
Do we need a data protection officer?
Article 37 requires one where you are a public authority, where core activities involve regular and systematic monitoring of individuals at scale, or where you process special category or criminal conviction data at scale. Many organisations outside those triggers appoint a privacy lead voluntarily. If you do appoint a DPO, the role has to be genuinely independent and free of conflicting duties, which rules out the head of marketing.
What is usually wrong when we audit?
Records of processing that stopped being updated after the first year, subprocessors added by engineering without a contract, standard contractual clauses on a superseded version, transfer impact assessments never carried out, subject access requests handled ad hoc by whoever picked up the email, and retention periods documented in policy but not implemented in any system.
Email Us
✉ EmailGet Quote