A GDPR audit gives enterprise buyers the evidence they ask for
GDPR reaches you if you offer goods or services to people in the EU or monitor their behaviour, wherever you are based. SIS tests lawful basis, processing records, rights handling, processor contracts and international transfers against what your systems really do.
- !A prospect’s data processing agreement includes an audit right and your legal team cannot sign it with confidence.
- !Enterprise procurement has asked for your record of processing activities and your transfer impact assessment.
- !Data subject access requests arrive faster than the one-month deadline allows you to answer them.
- !You are established outside the EU and have never appointed an Article 27 representative.
- !A vendor breach exposed EU customer data and the 72-hour notification clock started with nobody owning it.
- !Marketing consent, cookie banners and legitimate interests are being run on assumptions nobody has documented.
A European Union regulation governing personal data. It sets principles for lawful processing, gives individuals enforceable rights, requires accountability documentation, and controls how personal data leaves the European Economic Area.
GDPR is law, not a certification scheme. SIS conducts an independent compliance audit and issues a report and statement; formal Article 42 certification requires a body accredited under Article 43.
The report covers the scope and date of the audit. Reassess annually and after any material change to processing, vendors or transfer arrangements.
Controllers and processors of any size with EU customers, users, employees or subjects, and non-EU firms selling into Europe or serving European clients.
Industries that require ISO 22000 Certification
GDPR is applicable across 5 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What GDPR Actually Requires
An organisation must understand the requirements for ISO 22000 certification to implement it effectively.
Establish where Article 3 bites, which entities act as controller or processor for each activity, and whether an EU representative must be appointed under Article 27.
An Article 30 record covering purposes, categories of data and recipients, retention periods and transfers, maintained as processing changes rather than written once.
A stated basis for every processing activity, special category conditions where relevant, evidenced consent where relied on, and privacy notices that match reality.
A working route for access, rectification, erasure, portability and objection, with identity verification, redaction practice and responses inside the one-month deadline.
Article 28 terms with every processor, a maintained subprocessor list, and transfers outside the EEA covered by adequacy, standard contractual clauses or binding corporate rules.
Security appropriate to the risk, impact assessments before high-risk processing, a breach register, and a procedure meeting the 72-hour supervisory authority deadline.
How GDPR Compliance Assessment Works
A clear, step-by-step process from your first call to a completed engagement.
Scope & Applicability Review
We confirm where the Regulation applies to you, which entities are controllers and which processors, whether an Article 27 representative is needed, and which supervisory authority leads.
3–5 daysRecords & Data Flow Review
Article 30 records are read against how data actually moves, and the transfer inventory is where it falls apart: a subprocessor a product team added two years ago and never recorded.
2–4 weeksIndependent Compliance Audit
Evidence testing: notices and consent logs, response times on subject requests, impact assessments, Article 28 contracts, breach register, transfer impact assessments and security controls.
3–6 audit daysAudit Report & Statement
Non-conformities come with evidence references rather than a grade. If a supervisory authority later tests your accountability, what matters is that the gaps were identified and closed, and the report dates both.
Report in 10 working daysIndustries That Need GDPR
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
One report closes most of the questionnaire
Name the deal that is stuck, and the article your buyer keeps returning to. We will tell you whether a narrowed audit clears it before the quarter ends.
Get My Free Quote →What GDPR Changes for Your Business
More than a certificate — a testimony that you have raised the bar and built customer confidence.
Deals stop stalling
Enterprise security and privacy reviews are where mid-size vendors lose weeks. An independent report answers most of the questionnaire before the call is booked.
Fine exposure managed
The upper tier reaches €20 million or four per cent of worldwide annual turnover, whichever is higher. Documented accountability is what supervisory authorities weigh when deciding.
Transfers put right
Standard contractual clauses signed years ago and never revisited, and transfer impact assessments never done, are the most common finding and the easiest to fix once identified.
Requests handled on time
A working process for access and erasure requests keeps you inside the one-month deadline. Most complaints reaching a supervisory authority start with a request that went unanswered.
Contracts that hold
Article 28 terms and a maintained subprocessor list mean the data processing agreement your customer sends can be signed without a fortnight of legal negotiation.
A route to certification
The same records, controls and contracts support ISO/IEC 27701 certification. A buyer who does not want to read an audit report will accept a certificate instead.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to GDPR.
Can we be certified to GDPR?
Does GDPR apply if we have no office in Europe?
What happens if we miss the 72-hour breach deadline?
How does GDPR interact with ISO/IEC 27701?
Do we need a data protection officer?
What is usually wrong when we audit?
GDPR certification across the United Kingdom
Pick your region to see the industries concentrated there and the standards their buyers and regulators ask for most.
Book an independent GDPR compliance audit
Independent testing against the Regulation itself, mapped article by article, so your privacy counsel can answer a buyer’s question by page reference instead of by assurance.
Get My Free Quote → WhatsApp Us