GDPR · ARTICLE-MAPPED RISK ASSESSMENT

GDPR Risk Assessment That Produces Audit-Ready Evidence

You’re not here because you need GDPR explained. You’re here because you need documented proof that your organisation has assessed and addressed risk, and you need it in a format that holds up when a supervisory authority, an enterprise customer’s privacy team, or your DPO asks for it.

Our GDPR risk assessment produces that documentation. RoPA, DPIA, gap analysis, and a prioritised remediation roadmap – structured as evidence, not just a report.

Assessments from $4,500+. Scope confirmed before work begins.

gap-report-excerpt.md SAMPLE
## Gap Report Excerpt — GDPR Assessment
# Scope: processing inventory · DPIA triggers · vendor DPAs

CRITICAL No DPIA on File for Automated Decisioning Feature
Art. 35 Art. 22
HIGH RoPA Missing Three Active Processing Activities
Art. 30
HIGH Sub-Processor Operating Without Executed DPA
Art. 28
MEDIUM Consent Mechanism Lacks Granular Withdrawal Path
Art. 7
LOW DSR Log Not Time-Stamped Against 30-Day Window
Art. 12

What GDPR actually requires from your security program

Article 32 of the GDPR requires controllers and processors to implement “appropriate technical and organisational measures” – and to be able to demonstrate they’ve done so. That word, demonstrate, is doing a lot of work.

A supervisory authority or enterprise customer won’t take your word for it. They want to see evidence: a documented assessment of what personal data you process, where the risks are, what controls you’ve applied, and how you determined those controls were proportionate to the risk.

Article 32 specifically references the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems. That means your technical controls – access management, encryption, logging, incident response – need to have been reviewed and tested, not just listed in a policy.

Three things regulators look for beyond a policy document:

  • A current, accurate Record of Processing Activities (RoPA)
  • A completed Data Protection Impact Assessment for any high-risk processing activity
  • Evidence that security controls were assessed, not assumed

If your organisation has any of the following, special category data, systematic profiling, large-scale processing, or automated decision-making, a DPIA isn’t optional under Article 35. It’s required before processing begins.

Why a scanner won’t satisfy Article 32, or a DPA auditor

Automated vulnerability scanners produce a list of CVEs. They don’t produce data flow diagrams. They don’t identify which systems touch personal data, whether your processors have adequate DPAs in place, or whether your consent mechanism actually meets the standards in Articles 6 and 7.

A scanner gives you a technical snapshot of your attack surface. A GDPR risk assessment gives you an evidence trail that maps processing activities to legal bases, identifies gaps against specific Articles and Recitals, documents your DPIA reasoning, and tells you in writing what your residual risk is and how you’re managing it.

Those are different documents. Only one of them is useful when a supervisory authority asks for your compliance file.

How our assessment works

We run GDPR risk assessments as structured, scoped engagements, not open-ended retainers. Here’s what the process looks like in practice.

01 · D1–3

Discovery and scoping. We review your products, data categories, processing purposes, user regions, and existing privacy controls. This produces an agreed scope document so you know exactly what’s covered before we start.

02 · D3–8

Data mapping and RoPA build. We conduct structured interviews with your product, engineering, and ops teams to trace personal data through your systems. Inputs, outputs, storage locations, processors, retention periods, transfer mechanisms, all documented in a workbook that becomes your RoPA.

03 · D8–14

Control review against GDPR Articles. We review your consent flows, DSR (data subject request) handling, security controls, vendor DPA coverage, SCCs, and breach notification readiness against the specific Articles that apply to your processing activities.

04 · D10–18

DPIA, where required. If your processing triggers Article 35, we scope and document the DPIA, identifying the necessity and proportionality of the processing, the risks to data subjects, and the mitigating measures. This is produced as a standalone document suitable for DPA consultation if required.

05 · D14–21

Remediation roadmap. All findings are translated into a prioritised backlog: critical gaps, medium-risk items, and lower-priority hygiene fixes. Each item includes a description of the gap, the applicable Article, recommended remediation, and an effort estimate. See our Remediation Services if you need hands-on help implementing fixes.

06 · D21–28

Executive readout. We present findings to your DPO, legal team, or leadership. The session is recorded and can be shared with your board or with enterprise customers who request evidence of your compliance posture.

What you get: the evidence pack

This is what you’ll have at the end of the engagement, and what you’d hand to a DPA auditor or enterprise procurement team.

DeliverableWhat it isWhy it matters to an auditor
GDPR gap reportArticle-by-Article gap analysis with risk ratingsShows documented assessment against the regulation
RoPA workbookComplete Record of Processing ActivitiesRequired by Article 30; first thing a DPA requests
Data flow diagramsVisual maps of personal data movementDemonstrates you know what you process and where
DPIA report(s)Completed assessments for high-risk processingMandatory under Article 35; must precede processing
Vendor DPA registerProcessor inventory with DPA status and gap flagsDemonstrates processor due diligence (Article 28)
Remediation backlogPrioritised fix list with effort and ownershipEvidence of a response plan, not just gap awareness
Executive summary deckBoard-ready summaryFor DPO, legal, and senior stakeholder briefings

All documents are formatted for DPA review, not internal housekeeping. If a supervisory authority opened an inquiry into your organisation tomorrow, this is the file you’d submit.

What an auditor or DPA inspector looks for

Most organisations reach the end of a compliance engagement with a gap report and little else. That’s a problem when an auditor arrives expecting an evidence trail.

Supervisory authorities conducting investigations under Article 58 typically ask for:

  • Your RoPA (produced, current, and role-assigned)
  • Evidence that DPIAs were completed before high-risk processing was started
  • Your processor agreements (DPAs) and evidence they cover the required Article 28 elements
  • Documented DSR procedures and evidence they’ve been followed
  • Your breach notification log and response procedure
  • Evidence that security controls were assessed, not just policy statements

We build our deliverables around this list. Every document we produce is designed to answer a specific question an auditor might ask, not to describe your privacy program in general terms.

For organisations under active DPA inquiry or facing a customer-mandated audit, we can prioritise delivery of specific artifacts. Tell us your timeline when you scope.

Pricing

PackageStarting priceBest for
Starter — Gap AnalysisFrom $4,500+Baseline assessment, gap report, remediation roadmap
Professional — RoPA + VendorsFrom $8,500+Full data mapping, vendor DPA review, security control review
Enterprise — DPIA SupportFrom $14,000High-risk processing, DPIA documentation, stakeholder reporting

Pricing depends on the number of products in scope, data mapping depth, processor count, and whether DPIAs are required. All engagements are fixed-price with scope confirmed before work begins. See our Pricing page for a full breakdown.

Early-stage teams with a simpler processing footprint can request the GDPR Risk Snapshot from $3,500+. See Pricing for full scope details.

Timeline expectations

A standard engagement runs 2–4 weeks from kickoff to final deliverables. Enterprise engagements with multiple DPIAs or large processor registers may run 4–6 weeks.

If you’re working toward a specific audit date or customer review deadline, tell us at scoping. We can prioritise the RoPA and gap report in the first two weeks, with DPIA documentation and the remediation backlog following.

We don’t offer accelerated timelines that compress the work, but we can sequence deliverables so the most audit-critical documents land first.

Frequently asked questions

How long does a GDPR risk assessment take?

Typically 2–4 weeks for a standard engagement. That includes discovery, data mapping, control review, and final reporting. If you’re working toward a specific deadline, a contract renewal, a customer audit, or a DPA investigation timeline, flag it during scoping. We can sequence deliverables so the documents you need first arrive first.

What format are the deliverables in, and can I show them to a DPA?

All deliverables are produced as structured documents: the gap report and DPIA in PDF with an appendix index, the RoPA as a version-controlled spreadsheet workbook, and data flow diagrams as editable files. These are designed to be submitted directly to supervisory authorities or shared with enterprise customer procurement teams. They’re not slide decks repackaged as compliance evidence.

Do I need a DPIA, and what does it include?

A DPIA is mandatory under Article 35 if your processing is likely to result in a high risk to individuals, systematic monitoring, large-scale processing of sensitive data, automated decision-making with legal effects, and several other triggers. If your processing meets any of those criteria, we scope and document the DPIA as part of the engagement. The output covers the necessity and proportionality of the processing, the risk assessment, the mitigations applied, and your residual risk determination. It’s a document you’d need to submit to your supervisory authority if they asked for it.

Can we start the assessment if our documentation is incomplete or disorganised?

Yes, that’s the normal starting point. Most organisations coming to a GDPR assessment don’t have a clean RoPA or consistent DPA coverage. The discovery and data mapping phase is designed to build that picture from scratch. We’ll tell you what we need upfront: product/system inventory, a list of your key vendors, and access to whoever owns privacy within your engineering and ops teams.

What’s the difference between a GDPR risk assessment and a penetration test?

They answer different questions. A penetration test identifies exploitable vulnerabilities in your technical systems, it’s directly relevant to your Article 32 obligations around security of processing, and we’d recommend it alongside or after this assessment. The GDPR risk assessment covers the full compliance picture: lawful bases, RoPA, DPIAs, vendor oversight, DSR procedures, and the organisational measures GDPR requires. Many clients run both as part of a single compliance cycle. If that’s your situation, we can scope them together.

Tell us where you are in your GDPR compliance cycle

We’ll confirm what’s in scope and quote it with a fixed price. If you’re 6–8 weeks from a customer audit, a DPA inquiry deadline, or a contract renewal that requires compliance evidence, that’s the right time to start. A standard engagement produces your RoPA, gap report, and primary deliverables within two weeks of kickoff.

Already know you have gaps to fix? Visit our GDPR Remediation Services page.

Scroll to Top
Pentest_Testing_Corp_Logo
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.