Data Protection

Data Protection Assessment

An independent read on where your privacy program stands. We map your data processing activities, assess privacy risk and data protection risks, measure your posture against GDPR and the data protection regulations that apply to you, and deliver a prioritised roadmap so you know exactly where to focus. DPIA advisory and privacy impact assessment support included where needed.

Overview

A data protection assessment is the diagnostic you run before you commit effort to a remediation program. It tells you what personal data you hold, how it flows, where your documentation and governance fall short, and which compliance gaps carry the most regulatory or reputational risk. For organisations introducing new data processing activities or new data collection practices, it also identifies whether a formal DPIA (Data Protection Impact Assessment) is required under GDPR Article 35.

We map your data processing activities, review your existing privacy policies and records of processing, score your privacy maturity against GDPR and any other applicable data protection regulations, and rank the findings by risk. A privacy impact assessment looks at the impact on individuals, including their rights and freedoms, and flags where processing personal data could result in a high risk to data subjects. The output is a prioritised remediation roadmap you can act on directly or that forms the basis of a fuller readiness engagement.

Data protection risks vary by sector and by the type of data you hold. Processing sensitive data, such as health or biometric data, typically carries a higher risk profile and is more likely to require you to conduct a DPIA or carry out a DPIA before processing begins. Special categories of data attract stricter rules under GDPR, and our assessment identifies where those rules apply to you. The data controller owns the final decision on risk acceptance. Our assessment gives you the evidence to make that decision on a defensible basis.

A data protection assessment is also the right starting point if you have acquired a business, introduced new data processing activities, or simply do not have a clear picture of your current compliance with data protection law. It establishes a factual baseline: what you hold, how you hold it, and what data protection law requires you to do about it.

What’s included

  • Personal data mapping and processing inventory
  • Review of existing privacy policies, notices, and records of processing
  • Gap analysis against GDPR and applicable privacy and data protection regulations
  • Privacy maturity scoring across key compliance domains
  • Identification of high-risk processing activities and data protection risks
  • DPIA screening: assessment of which processing activities require a formal Data Protection Impact Assessment
  • DPIA template and advisory framework for activities that result in a high risk to data subjects
  • Risk-prioritised findings covering rights and freedoms impacts
  • Remediation roadmap with clear ownership and sequencing
  • Guidance on data transfers, data processors, and special categories of data

How we work

  1. 01
    Map

    We inventory the personal data you process, the systems it moves through, and the parties you share it with, including data transfers to third-party data processors. This gives you a factual baseline to work from, covering new data flows as well as legacy processing activities.

  2. 02
    Assess

    We measure your current posture against the applicable data protection regulations and review your existing documentation for coverage and accuracy. We identify compliance gaps and assess which processing activities are high-risk or require a formal privacy impact assessment or DPIA.

  3. 03
    Score and prioritise

    We score your privacy maturity across key domains and rank the gaps by regulatory risk and remediation effort. Processing personal data in ways that affect the rights and freedoms of data subjects gets prioritised. We flag activities where you need to conduct a DPIA before proceeding.

  4. 04
    Roadmap

    We deliver a prioritised remediation roadmap with clear ownership. You can act on it internally or continue into a GDPR readiness or DPO engagement with us. The DPIA template we provide gives you a reusable framework for assessing new processing activities going forward.

What you get

  • Data mapping and processing inventory
  • Privacy gap analysis and maturity score
  • DPIA screening report and DPIA template
  • Risk-prioritised findings report covering data protection risks and rights and freedoms impacts
  • Remediation roadmap with ownership and sequencing

Frequently asked questions

Is a data protection assessment the same as a DPIA?

No. A Data Protection Impact Assessment (DPIA) evaluates a specific high-risk processing activity before it begins, as required by GDPR Article 35 where the processing is likely to result in a high risk to the rights and freedoms of data subjects. A data protection assessment is a broader health check of your overall privacy program. The two serve different purposes. Our assessment includes a DPIA screening step that identifies which of your processing activities require a formal DPIA and provides a DPIA template to carry it out.

When do we need to conduct a DPIA?

GDPR requires you to carry out a DPIA before beginning any new data processing activity that is likely to result in a high risk to data subjects. Data protection impact assessments are mandatory for activities such as large-scale processing of sensitive data, systematic monitoring of individuals in public spaces, and new data processing involving special categories of data. Our privacy impact assessments and DPIA screening tell you which of your current and planned activities fall into that category. The data controller decides whether one is required, with advice from the DPO if one is in place.

What do we get at the end of the engagement?

A clear picture of where your privacy program stands against applicable data protection law, a maturity score, a ranked list of compliance gaps and data protection risks, a DPIA template, and a roadmap that tells you what to fix first and why. It is the natural starting point for a GDPR readiness engagement or an ongoing DPO arrangement.

How long does a data protection assessment take?

That depends on the size of your organisation, the complexity of your data processing activities, and the number of data processors and data transfers involved. We scope it on a call and give you a clear timeline before the engagement starts.

We already have a privacy policy. Does that mean we pass?

A privacy notice is one requirement among many. A data protection assessment looks at whether you have the underlying records of processing, lawful basis analysis, data subject rights procedures, and technical controls to back it up. It also checks whether any of your processing personal data activities are high-risk and require a DPIA. A published privacy policy with nothing behind it is not a compliance position under data protection law.

What is a data controller and what does it mean for our obligations?

A data controller is the organisation that determines the purposes and means of processing personal data. As a controller, you are responsible for the protection of personal data you collect and process, including compliance with data protection regulations, handling data subject access requests, and ensuring that any data processors you use are covered by appropriate agreements. Our assessment maps your controller obligations and identifies where you fall short.

Credentials held by our team

ISO/IEC 27001 Lead Auditor
CISM
CISA
COBIT 2019
CEH
CRTP
eCPPT
CSA
CCNA
ITIL
Free tool · about 3 minutes · instant score

How ready is your security and compliance?

Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.

Start the free assessment

Ready to simplify security and compliance?

Pick a service, book a scope call, or ask a question. Whatever order works.