Contact Us

Compliance assessment

We measure the organisation’s level of compliance with personal data protection legislation, giving back a clear picture of its strengths and of the areas for improvement. The service is tailored to the Client’s operational needs and organisational complexity and may cover the whole organisation, individual processes or specific projects. The added value is that we do not stop at the diagnosis: we set out the improvement actions and put together a concrete strategy for implementing them, with priorities defined based on risk.
The service is delivered through:

  • A review of the processing activities carried out and of the data protection documentation already adopted;
  • Verification of compliance against the requirements of the GDPR and of the applicable national legislation;
  • Analysis of the technical and organisational security measures in place;
  • Assessment of the roles and responsibilities of the parties (internal and external) involved in the processing;
  • Identification of improvement actions, ranked by risk priority;
  • Preparation of a strategy and an operational plan for implementing the actions identified.

The service ends with an assessment report setting out the level of compliance found, the improvement actions suggested and the roadmap for implementing them.
The aim of the service is to give the organisation full awareness of its own level of compliance and an operational tool for planning action, in line with business priorities.