Who Needs This
Any company processing EU customer or employee data — SaaS vendors with EU customers, outsourcing/BPO firms, and exporters handling EU personal data.
What's Included
Data flow mapping and Article 30 Record of Processing Activities (RoPA)
Lawful basis review for every processing activity
Data Processing Agreement (DPA) drafting for vendors and sub-processors
Consent mechanism and privacy notice review
Data Subject Access Request (DSAR) process design
Breach notification runbook (72-hour reporting readiness)
Frequently Asked Questions
Do we need a GDPR audit if we're not based in the EU?
Yes, if you process personal data of individuals located in the EU — GDPR applies extraterritorially regardless of where your company is headquartered.
What is an Article 30 register and do we need one?
It's a mandatory record of all personal data processing activities. Most organizations processing EU data at scale are required to maintain one, and we build it as part of the engagement.
How does GDPR readiness differ from DPDP readiness?
GDPR applies to EU data subjects and has stricter consent and cross-border transfer rules; DPDP is India's domestic law with its own consent and breach-notification requirements. Many clients need both if they serve EU and Indian users.