Skip to content
CISO Marketplace Services

GDPR Compliance Assessment

Comprehensive evaluation of your organization's compliance with the European Union's General Data Protection Regulation (GDPR). Our assessment examines data processing activities, privacy controls, and governance frameworks to identify compliance gaps and provide a detailed remediation roadmap for organizations handling EU resident data.

In scope

  • Data protection impact assessment review
  • Processing activities register evaluation
  • Lawful basis determination
  • Privacy notice evaluation
  • Data subject rights implementation assessment
  • Consent management review
  • Cross-border data transfer mechanisms
  • Data protection officer requirements
  • Privacy by design implementation
  • Data breach notification procedures
  • Processor agreement review
  • Record keeping assessment

You receive

  • GDPR compliance gap analysis report
  • Data processing inventory
  • Data protection enhancement plan
  • Privacy governance framework
  • Data subject rights procedures
  • Cross-border transfer recommendations
  • Breach notification process improvements
  • DPO requirement determination
  • Documentation framework
  • Implementation roadmap and timeline

Tiers

Choose the depth.

Essential GDPR Assessment

$38K

GDPR gap assessment for up to 250 employees, 1 country of establishment and up to 10 processor agreements: processing register, lawful basis, notices, data subject rights, consent, breach notification and DPO requirement. Gap report, data inventory and roadmap.

employees
250
Sites
1
vendors
10
  • Processing activities register evaluation
  • Lawful basis, privacy notice and consent review
  • Data subject rights and breach notification procedure review
  • Review of up to 10 processor agreements
  • Gap analysis report, data processing inventory and roadmap
  • DPO requirement determination
  • — Writing procedures, notices or DPIAs
  • — Cross-border transfer strategy
  • — Governance framework design
  • — Implementation support
Scope Essential GDPR Assessment

Comprehensive GDPR Compliance Program

$70K

For up to 1,000 employees, up to 3 countries and up to 30 processor agreements. Adds written data subject rights and breach procedures, a documentation framework, a privacy governance framework, transfer mechanism recommendations and step-by-step implementation guidance.

employees
1000
Sites
3
vendors
30
  • Everything in the Essential assessment
  • Data subject rights and breach notification procedures written
  • Documentation framework and record-keeping templates
  • Privacy governance framework
  • Cross-border transfer recommendations
  • Review of up to 30 processor agreements
  • — Hands-on implementation support
  • — Compliance maintenance after delivery
  • — Acting as the appointed DPO
  • — Legal opinions
Scope Comprehensive GDPR Compliance Program

Enterprise EU Privacy Framework

$120K

Advanced compliance program for complex multinational organizations with custom implementation support, cross-border strategies, and ongoing compliance maintenance

Sites
10
vendors
75
  • — Acting as the appointed DPO or EU representative
  • — Legal representation before supervisory authorities
  • — Licences for privacy management software
Scope Enterprise EU Privacy Framework

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a readiness & governance assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping & framework selection

    The standard or regulation, the systems and the business units in scope are fixed.

    You see · Your audit or regulatory driver.

  2. 02Evidence collection & interviews

    Policies, configurations and records reviewed; control owners interviewed.

    You see · Documents and time with control owners.

  3. 03Gap analysis

    Each requirement mapped to current state: met, partial or missing, with the evidence behind it.

    You see · A clear gap register.

  4. 04Roadmap & evidence plan

    Prioritized remediation with owners, and the evidence an auditor will ask for.

    You see · A plan you can execute or hand to us.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor