Find the right data protection service for your business

European Union · Free product

EU Data Privacy
Check-Up

A free GDPR readiness snapshot for organisations that need a clear picture of their EU compliance position before appointing a DPO or Article 27 representative.

No setup feeGDPR gap snapshotPractical next steps
The Data Protection Officers team in a modern office

Practical support, clearly scoped

European Union · GDPR

Plans and inclusions

EU Data Privacy Check-Up: free readiness check-up

Free for every company size, with no setup fee or commitment to purchase another service.

  • GDPR readiness snapshot
  • Gap analysis summary
  • Practical recommendations
  • No commitment required

The check-up provides a readiness snapshot and recommendations. An ongoing appointment, implementation project, or incident engagement has its own scope.

Request your free check-up

Understand your GDPR position before you commit

Many companies know they need EU privacy coverage, but are unsure whether they require an external DPO, an Article 27 representative, or a broader compliance programme. The EU Data Privacy Check-Up gives you a structured starting point.

We review your current processing footprint against core GDPR obligations and return a practical summary of gaps, priorities, and the most appropriate product path for your business.

What you receive

The check-up is designed to be fast, useful, and free. You receive a concise readiness snapshot rather than a full legal audit, helping leadership teams decide what to do next without unnecessary cost.

Applicable legal framework

GDPR

  • GDPR accountability principle
    Article 5(2) requires controllers to demonstrate compliance. The check-up helps identify where that demonstration is currently weak.
  • Role assessment
    We help distinguish whether your situation points toward Article 37 DPO obligations, Article 27 representation, or broader governance work.

How the service works

The check-up follows a simple, low-friction workflow:

1

Scope intake

You share your markets, processing activities, and current privacy documentation.

2

Readiness review

We assess your position against core GDPR obligations relevant to your operations.

3

Gap summary

You receive a practical summary of the main compliance gaps and risk areas.

4

Product recommendation

We recommend the most appropriate paid product path if further support is needed.

Not sure which EU product you need?

Start with the free check-up and get a clear recommendation before selecting a DPO or representative service.

Book a free check-up

Product snapshot

RolePrivacy Readiness Check-Up
RegulationGDPR
Supervisory authorityEU data protection authorities
Setup feeNone
PricingFree

How we help

See how this service fits your organisation

Use the sections below to understand what we review, what you receive, what your team provides, and how you can keep the result useful after delivery.

01 · Fit

Is the EU GDPR Data Privacy Check-Up right for your organisation?

If your company knows European privacy matters but does not yet have a clean view of its exposure, this check-up gives you a practical starting point. It fits a founder-led business entering the EU, a product team preparing a launch, or an established organisation whose notices, vendors, and requests have grown without one current picture.

A useful example is a software company that has an EU customer base, a US parent, several cloud vendors, and a privacy notice written before the current product was launched. The business may not need a full programme immediately, but it does need to know whether the customer journey, support access, analytics, and vendor chain create a role or documentation decision. This check-up puts those facts in one view so the commercial owner can choose the next step with less guesswork.

02 · Decision

What you will be able to decide

The immediate decision is not whether to choose the largest privacy programme. It is whether your organisation needs a DPO, an EU representative, focused remediation, or simply a better account of its current position. A short, structured assessment gives that decision a factual starting point.

The review separates questions that are often bundled together: whether the EU GDPR applies, whether an EU representative may be relevant, whether a DPO assessment is needed, whether transfer work is urgent, and which operational records are missing. You can use that separation to approve a focused piece of work instead of buying a broad package because the original question was not framed clearly.

03 · Trigger

When to bring us in

Typical triggers include a new EU customer, a market launch, a security questionnaire, a vendor change, an unresolved data-subject request, or uncertainty about whether Article 27 and Article 37 point to different roles. The check-up is useful when the business needs direction before it commits budget.

04 · Evidence

What we need from your team

Useful evidence includes the markets served, product flows, categories of people, purposes, data locations, vendor relationships, privacy notices, request handling, incident history, and current ownership. Missing information is itself a finding; the review should identify where assumptions are carrying the programme.

We look for the link between what your public materials promise and what your teams can demonstrate. That can include sign-up and support flows, product analytics, identity and access records, processor terms, retention choices, rights-request handling, incident escalation, and the person who can explain each system. A short evidence map makes uncertainty visible rather than treating an empty field as proof that no processing exists.

05 · People

Who should join the work

Please include the person who understands the product, the person who controls security or engineering evidence, and the person who answers customer or legal questions. Leadership input matters because the right action depends on your appetite, deadlines, and available owners.

06 · Method

How we will work together

We move from a short intake to a focused review of your processing footprint, then to a gap summary that separates role questions from operational weaknesses. The recommendation is written for a decision-maker who was not in every interview and is practical enough for your operating team to act on.

The output is designed for a working meeting with product, security, customer, and leadership owners. We can mark items as supported, unclear, or needing a decision, then connect each material gap to a plausible next service. The point is to help you move from an EU privacy concern to an owned action list, not to create a report that only a specialist can interpret.

07 · Output

What you will receive

You receive more than a vague score: the main facts reviewed, important uncertainties, highest-value improvements, and product path that matches your situation. That gives your team a clear internal decision record instead of an unprioritised list.

08 · Friction

What can make this harder

Companies often lose time by treating every privacy issue as a legal question, or by assuming that a policy document proves the related process works. Another common shortcut is to select a DPO or representative before checking which role the processing actually calls for. The check-up creates a pause for those distinctions.

09 · Maintenance

How you keep it current

After the snapshot, keep a short change log for products, vendors, markets, data categories, and incidents. A check-up is a point-in-time product, so its value increases when your team records what changed and when a new review is needed.

Revisit the snapshot when you add an EU market, change a tracking or support tool, introduce sensitive data, alter the controller structure, sign a major customer contract, or experience an incident. If none of those events occur, an annual check can still confirm that the original assumptions remain true. Keep the date and owner beside the decision so the snapshot does not become a forgotten launch document.

10 · Boundaries

What stays with your organisation

The check-up does not certify compliance, replace a formal audit, or transfer accountability from the controller or processor. It gives general direction based on the information supplied. Your organisation still owns decisions about lawful bases, contracts, security, and role appointments.

11 · Scope

What to prepare before you start

To start, send the main markets, products, processing categories, current privacy contact, and any deadline that makes the assessment urgent. Tell us which decision is blocked so the recommendation answers your real question.

  • EU markets, entities, and customer groups in scope
  • Product, support, analytics, and identity data flows
  • Current notices, vendor terms, and request channels
  • Open decision, owner, deadline, and risk tolerance
  • Clear boundary between a snapshot and ongoing advice

12 · Buyer brief

What your first working brief should contain

Before you buy, write down the European decision that is currently blocked. It may be a launch date, a customer contract, a representative question, a DPO question, or uncertainty about whether existing controls are enough. Add the entity selling the product, the markets reached, the main customer and support journeys, and the person who can explain how analytics, identity, and vendor access work. That short brief gives the review a real boundary. It also prevents a readiness product from becoming a general request to inspect every privacy document your organisation has ever produced.

The most useful follow-through is a decision meeting with the commercial owner, product or operations owner, and someone who can confirm security and supplier facts. Use the result to choose one next action with an owner and date. If a representative or DPO route is recommended, make the role distinction explicit before publishing anything. If documentation or transfer work is the priority, connect it to the release, procurement, or customer process that can close it. Keep open assumptions visible; they are a reason to verify, not a reason to claim that the organisation is already compliant.

13 · First test

What we will test first

The first review normally tests the customer journey, support access, analytics, identity, vendor chain, privacy contact, and the decision that triggered the request. We look for the difference between a process that is described in a policy and one that an owner can demonstrate from a system, contract, ticket, or public page. If the organisation serves more than one EU market, we note whether the same route is genuinely shared or whether a local contact, language, entity, or regulator question changes the answer. You should leave knowing which uncertainty matters commercially, which gap can be closed internally, and which next service would provide the right depth. Keep the source list with the snapshot and record the date of the business facts, not only the date the document was written. That makes later review faster when a vendor, product, or market changes.

14 · Working record

How the result stays usable

A useful result has a home after delivery. Keep the source evidence, decision, owner, scope, open actions, and next review together in a register, project record, contract file, or management routine that your team already uses. The format can be short; it just needs to make the next action and the reason for reopening the question visible. That is how professional input stays connected to the business instead of becoming a document that no one can find when the facts change.

15 · Progress

How you can judge progress

Judge progress by what your team can use and explain. Look for a supported decision, an owner who understands the action, a route that works in practice, and evidence that the agreed output reached the right system, notice, contract, ticket, or meeting. A large document or a high-level score is not enough on its own. The stronger signal is fewer repeated questions, clearer escalation, and a review date that responds to actual change.

16 · Proportion

What a proportionate scope looks like

A proportionate scope should leave you with enough detail to act and enough clarity to know what remains outside the work. We will ask for the facts that can change the answer, explain material uncertainty, and keep specialist dependencies visible. You should be able to tell a manager what was reviewed, an operating owner what to do next, and a future reviewer what event would reopen the question. That balance protects your budget and makes the result more likely to stay useful after delivery.

17 · Handoff

What remains with your organisation

Your organisation remains responsible for the processing, resources, implementation, and final business decision. We can review the supplied facts, provide professional direction, prepare agreed outputs, and make open issues easier to act on. Bring in security, technical, employment, communications, or specialist legal expertise when the question needs it. Before you buy, name the decision, evidence, owner, deadline, and boundary so the selected scope is proportionate and easy to judge.

In practice

See what you can expect

Each view shows a different part of the buyer journey: the evidence, decision, working route, safeguards, and review point behind the service.

Editorial still life showing an EU privacy readiness review with a paper map, notebook, assessment cards, and magnifying glass
Editorial still life showing an EU privacy readiness review with a paper map, notebook, assessment cards, and magnifying glass; evidence view for this page
Editorial still life showing an EU privacy readiness review with a paper map, notebook, assessment cards, and magnifying glass; decision view for this page
Editorial still life showing an EU privacy readiness review with a paper map, notebook, assessment cards, and magnifying glass; workflow view for this page
Editorial still life showing an EU privacy readiness review with a paper map, notebook, assessment cards, and magnifying glass; safeguard view for this page
Editorial still life showing an EU privacy readiness review with a paper map, notebook, assessment cards, and magnifying glass; review view for this page

Frequently Asked Questions

Common questions about the EU Data Privacy Check-Up.

Is the EU Data Privacy Check-Up really free?

Yes. The product is free across all company size tiers and includes no setup fee.

Does the check-up replace a full GDPR audit?

No. It is a readiness snapshot designed to help you understand your position and choose the right next step.

Can I move from the check-up to a paid EU product?

Yes. Many clients use the check-up to decide whether to appoint an external DPO or an Article 27 representative.

EU Data Privacy Check-Up by location

Explore practical business scenarios, preparation steps, and the relevant jurisdiction for your location.

Start with a free EU readiness snapshot

Get clarity on your GDPR obligations before appointing a DPO or representative.

Get the free check-up

Disclaimer: This content is for informational purposes only and does not constitute legal advice or create a solicitor-client relationship. Data protection regulations are subject to change and specific application depends on the context of your processing activities. Please consult directly with our legal team for advice tailored to your organization.

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services