GDPR Gap Analysis Service

The General Data Protection Regulation (GDPR) was introduced in May 2018 as a response to the UK’s General Data Protection Regulation (GDPR). The GDPR applies to all organizations who process the personal data of UK/EU Citizens.

The GDPR replaces the 1995 Data Protection Act and sets out specific regulations surrounding data protection. The GDPR requires organizations to take steps to protect user data from accidental or unauthorized access, destruction, alteration, or unauthorized use.

Organizations that fail to comply with the GDPR can be fined up to 4% of their annual global turnover or £17.5 million (whichever is greater). To help organizations comply with the GDPR, a number of services have emerged, including GDPR Gap Analysis Services.

Our GDPR Gap Analysis Service is designed to help organizations identify areas of their data protection practices that may be non-compliant with the GDPR. This service involves reviewing an organization’s policies and procedures related to data protection, conducting interviews with key personnel, and conducting audits of data protection practices.

What is the GDPR Gap Analysis Service

The GDPR Gap Analysis Service is a service that helps organisations identify and understand the gaps in their compliance with the General Data Protection Regulation (GDPR). The service provides a comprehensive report that outlines the specific areas where an organization needs to take action in order to become compliant with GDPR.

Why do you need to conduct a GDPR Gap Analysis?

There are a number of reasons why an organization may need to conduct a GDPR Gap Analysis. Perhaps the most obvious reason is to identify and understand the gaps in an organization’s compliance with GDPR.

However, there are other reasons why an organisation may need to conduct a gap analysis. For example, an organization may need to identify the specific areas where it needs to take action in order to improve its compliance with GDPR.

Additionally, an organisation may need to use a gap analysis to assess the effectiveness of its current compliance measures. This can help the organization identify areas for improvement, and make sure that it is taking the necessary steps to protect sensitive data and meet the requirements of GDPR.

Whether you are a large enterprise or a small business, conducting a GDPR Gap Analysis can be an important step in ensuring that your organization is ready for the new data privacy regulations.

What are the benefits of using the GDPR Gap Analysis Service

  • Provides an accurate snapshot of organisational readiness to comply with GDPR.
  • Highlights current risks and necessary steps in executive-level terms.
  • Provides a clear high-level plan and roadmap for achieving full compliance.
  • Identifies areas requiring immediate attention, and cost-effective remediation solutions, in prioritised terms.
  • Delivers a detailed strategy for achieving GDPR compliance.

How does the GDPR Gap Analysis Service work

Our Methodology

Our GDPR Gap Analysis Service includes a GDPR Health Check of the IT infrastructure for Data Security and a Gap Analysis of the processes and procedures currently in place for compliance with Data Privacy requirements. The assessment is designed to deliver GDPR help by providing organisations with a clear understanding of the changes that will be required to achieve GDPR compliance.

Step 1: Pre-Assessment Phase (Off-Site)

Carry out a telephone conversation/email questionnaire with a key staff member to establish the following:

  • The structure of the organisation. 
  • Identify the information required for the on-site review.  
  • Obtain an understanding of any existing Information Security Management System. 

Step 2: (Optional) – Education Phase (On-Site Workshop) – This can be a separate presentation

  • A presentation to senior management to explain what GDPR is and what their responsibilities are.    
  • Hold an Information Security scoping workshop with senior representatives at the decision-maker level.
  • Assess and understand current organisational culture and current Data Protection procedures.
  • Discuss the extent of current personal data holding knowledge and usage for business purposes.
  • Review of existing Information Security Management System with respect to GDPR requirements.
  • Identify contacts for more accurate information on data holding and change process (as needed).

Step 3: Gap Analysis (On-Site)

Data Privacy Assessment:

  • Completion of detailed EU GDPR Questionnaire led by EU GDPR Consultant.
  • Establishing where EU citizens’ personal information is currently being held for data mapping.
  • Identifying the Processes, Policies and Procedures currently in place and what might need changing for GDPR.
  • Establish Data Life cycles.
  • Data Protection Impact Assessments requirements.

Step 4: Reporting Phase (Off-Site)

  • Creation of the EU GDPR Executive Summary Report.
  • Definition of work to resolve gaps in logical projects.
  • Details of the objectives, resources involved, complexity and high-level costs.

Step 5: Executive Presentation Phase (On-Site or Remote)

  • Presentation of the plan for endorsement by the company executive.
  • Walkthrough of gaps between current practice and requirements for EU GDPR compliance.
  • Identify Senior Information Responsible Owner (SIRO) and key roles.
  • Nominate Project Managers for individual projects by departments.

Deliverables

UK GDPR Readiness Assessment Workshop

The purpose of the workshop is to provide an overview of the GDPR and its requirements, to identify areas where your organisation needs to take action in order to become compliant with the GDPR and develop a plan of action.

UK GDPR Readiness Assessment Executive Report with Risks Assessment, remediation activity and resources.

The Executive Report will provide a comprehensive overview of the findings of the GDPR Readiness Assessment, including an assessment of the risks associated with non-compliance and recommended remediation activities. The report will also identify the resources required to achieve compliance with UK GDPR.

UK GDPR Detailed Strategy – detailing the steps with delivery timelines to achieving GDPR compliance.

The following is a detailed strategy for achieving GDPR compliance:

1. Review and update the information security management system (ISMS) to meet GDPR requirements.

2. Conduct data privacy impact assessments (DPIAs) for high-risk processes and activities.

3. Review and update data protection policies, processes, and procedures to meet GDPR requirements.

4. Conduct staff training on GDPR compliance and privacy best practices.

5. Develop a plan for dealing with data breaches and other incidents that may occur in the course of business operations.

6. Engage a third-party consultant or provider to assist with the assessment and implementation of GDPR requirements.

This strategy will be tailored to the specific needs and resources of your organisation, and implementation should be overseen by a project manager or specialist team.

Timelines and milestones should be established in order to ensure that progress is made in a timely and efficient manner. Regular reviews should be conducted to assess compliance and identify any areas where further action is needed for GDPR compliance.

GDPR Gap Analysis Service

Get Started

Pricing depends upon the organisation’s size, number of computers and locations.

Call us today to book your

GDPR – READINESS ASSESSMENT – 0330 165 8900

The ICO GDPR Recommendations

The ICO has published a document outlining the 12 steps to GDPR

Getting ready for GDPR from the ICO