Skip to main content

Security Consulting & Compliance

GDPR Consulting & Compliance

Lawful-basis mapping, DPIAs, cross-border transfer mechanics and DPO support.

Every engagement includes manual validation, a two audience report and free re-testing.

Get a scoped quote+91 96682 00222

What this actually is

GDPR reaches you if you offer goods or services to people in the EU, or monitor their behaviour, regardless of where you are incorporated. Plenty of Indian companies are in scope and have never been told so by anyone.

The work splits cleanly in two. There is the paperwork a supervisory authority would ask for, and there is whether your systems actually behave the way the paperwork claims. We do both, because only doing the first is how organisations get caught out.

Where you are a processor rather than a controller, your obligations come through Article 28 and through your customer contracts at the same time. Those two sets rarely match, and reconciling them is usually the first useful thing we do.

What we go after

  • Records of processing under Article 30, built from what systems actually do
  • Lawful basis established per processing activity, not per company
  • Data subject rights: access, erasure, portability and objection, tested end to end
  • International transfer mechanisms, including SCCs and transfer impact assessments
  • Data protection impact assessments where processing is high risk
  • Processor and sub-processor chain, with contracts checked against practice
  • Breach detection and the 72 hour notification route
  • Privacy by design in the product development process

How we run it

  1. 01

    Gap assessment

    We measure you against the standard as it is actually audited, not as it reads on paper.

  2. 02

    Remediation plan

    Every gap gets an owner, an effort estimate and a date. You decide what lands this quarter.

  3. 03

    Implement and evidence

    We write the policy, build the control and collect the artefact that proves it is working.

  4. 04

    Internal audit

    A dry run under audit conditions, so nothing in the real one is a surprise.

  5. 05

    Certify and maintain

    We sit on your side of the table for the audit, then keep the evidence current between cycles.

What you receive

  • Gap assessment against every applicable article, with severity
  • Records of processing you can hand to a supervisory authority
  • Remediation plan sequenced by risk and effort
  • Reviewed DPA and sub-processor templates
  • DPIA templates with one worked example from your own processing
  • Evidence pack for customer due diligence

Who needs this

Any organisation with EU customers or users, and any processor serving a controller who has them.

How long it takes

Four to six weeks for the assessment. Remediation depends almost entirely on how much of your data map already exists.

Standards this satisfies

  • GDPR
  • ISO 27701
  • ISO 27001
  • DPDP Act 2023

Why it matters

Almost nobody starts a certification because they want one. It starts because a customer will not sign without it, a regulator has asked, or a deal is sitting still while procurement waits for evidence. The commercial driver is real and it is worth being honest that it, rather than security, is usually what pays for the programme.

The security benefit is real too, but it comes from a specific place: the discipline of having to evidence that a control operated over a period, rather than that it was configured once. That is the part that changes behaviour, and it is also the part organisations consistently underestimate.

Choose how you want this delivered

Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.

Gap assessment, then we work alongside your team through remediation, internal audit and the certification audit itself. Your people do the work and own the outcome, which is what makes the management system survive after we leave. This is what most organisations should choose.

Choose this when

  • You have a team who can absorb the work alongside their day job
  • You want the capability to remain in-house afterwards
  • First certification where documentation is the main gap

Effort and cost

Moderate. The calendar is longer than a managed programme because the work competes with everyone's existing responsibilities.

Scope it yourself, before you call anyone

Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.

1/8

Do you have a current record of what personal data you hold and why?

Covering every system, including analytics copies, exports and test environments.

What we look for, and keep finding

These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.

  • Controls that exist on paper only

    The policy says quarterly access reviews. The evidence shows one, eighteen months ago, and it was not completed. This is the single most common audit finding across every framework.

  • Scope drawn too narrowly

    A certificate covering a subset of the business that customers assume covers all of it. Auditors check the boundary; buyers rarely do. Getting scope right is the most consequential early decision.

  • Evidence that cannot be reproduced

    A screenshot proves a control was configured on the day someone took it. A framework wants proof it operated throughout the period. Those are very different, and the gap only appears at the audit.

  • Exceptions with no expiry

    Risk accepted once, recorded, and never revisited. Over a few years these accumulate into an undocumented second control framework nobody is managing.

  • Third parties outside the boundary

    Processing carried out by a supplier who was assessed at onboarding and never since, while your obligation for their handling of your data continues regardless.

Who runs your engagement

A lead assessor who has sat on the other side of the table

Compliance work is led by an assessor who has taken organisations through certification, not by a consultant reading the standard for the first time with you. They know which findings a certification body will actually raise, which is a different list from what the standard technically says.

Questions we get asked

We are an Indian company with no EU office. Does GDPR apply?

It can. Article 3 turns on whether you target people in the EU or monitor their behaviour, not on where you are established. If you take euros, ship to the EU or run analytics on EU visitors, assume you are in scope until someone establishes otherwise.

Does DPDP compliance mean we are GDPR compliant?

No, and the gap is bigger than it looks. DPDP has no equivalent of the lawful basis framework, data portability, or the transfer impact assessment. There is real overlap on security and breach handling, so doing them together saves work, but one does not deliver the other.

What actually happens if we ignore it?

For most Indian companies the practical risk is not a fine from a supervisory authority. It is an EU customer's procurement team refusing to sign, or an existing customer terminating because they cannot evidence their own compliance through you.

Do we need a Data Protection Officer?

Only if you meet the Article 37 conditions: public authority, large scale regular monitoring, or large scale special category processing. Many organisations appoint one anyway because customers ask. That is a commercial decision rather than a legal one, and we will say so.

Ready to scope your gdpr consulting & compliance?

Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.