Skip to main content
Compliance Readiness

GDPR
Readiness

GDPR is not certified, it is enforced - and what a regulator asks for after an incident is documentation you either have or you do not. We run GDPR readiness so your lawful bases, records, transfer mechanisms and breach process exist before anyone asks.

Readiness Assessment Third-Party Audit Annual Review
readiness log GDPR assessing
09:14:02scopeGDPRconfirmed
09:14:17assessPrinciples and Lawfulnesswalked
09:15:18assessData Subject Rightswalked
09:16:19assessAccountability and Governancewalked
09:18:40gapmarked complete, no evidence attachedblocker
09:19:05gapcontrol has no named owneropen
09:22:31evidencefiled against control · expiry trackedaccepted
09:24:12handoffrequirement → control → evidencemapped
your team assesses evidence vetted tracked in Talon
6
control areas walked
3
assessment paths
14
frameworks on one programme
0
methodology slides
Fit

Who this is for

Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.

Companies processing personal data of people in the EU or UK, wherever the company is based

SaaS providers acting as processors whose customers are asking for Article 28 terms and transfer assurances

Teams who have a privacy policy but no record of processing activities

Organisations relying on international transfers without a documented transfer risk assessment

Scope of work

What the engagement does

Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.

  • Map what personal data you actually hold, where it flows, and who it is shared with
  • Establish and record the lawful basis for every processing activity
  • Build the Record of Processing Activities the regulation requires
  • Assess data subject rights handling end to end - can you actually locate and erase what somebody asks about
  • Review processor contracts, sub-processors, and international transfer mechanisms
  • Stand up the breach assessment and 72-hour notification process before it is needed

What you walk away with

A data map that reflects reality, a lawful basis per activity, a maintainable RoPA, a rights process that works, and a breach process rehearsed rather than theoretical. The 72-hour clock is not a documentation problem when it starts - it is an operational one, and this is where that is solved.

Sequence

How it runs

Four phases. You always know which one you are in and what is outstanding.

01

Scoping call

We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.

no charge
02

Assessment

We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.

Lorikeet assessor
03

Remediate and evidence

We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.

joint
04

Hand off to your assessor

You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.

with your assessor
Coverage

What the assessment covers

The control areas we walk for GDPR. Each breaks down into individual controls carrying status, owner and evidence in Talon.

01 Principles and Lawfulness
02 Data Subject Rights
03 Accountability and Governance
04 Security of Processing
05 Breach Notification
06 International Transfers
Who performs the assessment

GDPR has no certificate. Supervisory authorities enforce it, generally after a complaint or a breach. Readiness prepares you for that scrutiny and for the diligence enterprise customers now run before signing.

Where it lives

It runs in Talon, not in a spreadsheet

Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.

  • Control-by-control status, kept current by the people doing the work
  • Evidence filed against the control it satisfies, with expiry dates tracked
  • The auditor request list, so nothing is chased over email
  • A readiness view that shows what an assessor would see
Already running a compliance platform?

Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.

Our partners
Questions

Asked on almost every GDPR call

If you offer goods or services to people in the EU or UK, or monitor their behaviour, yes. Location of the company is not the test.

Only in defined circumstances - public authorities, large-scale systematic monitoring, or large-scale processing of special category data. Many companies appoint a privacy lead without the formal DPO obligation, which is fine as long as the distinction is deliberate.

Transfers outside the EEA need an adequacy decision, Standard Contractual Clauses, or another Chapter V mechanism - plus a transfer risk assessment. SCCs signed without the assessment behind them are a common finding.

Not in the way buyers often mean. Article 42 provides for certification schemes, but there is no general certificate. What you can have is a documented, defensible compliance position.

Alongside

Rarely run alone

Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.

Next

GDPR readiness, on your timeline

A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!