Security & Compliance
GDPR & data-protection advisory
For EU customers and EU data, including the transfer mechanism question.
Who it is for
Anyone with EU customers or EU data.
Everything below is in the scope document, written and priced before anything starts. If something you need is not on this list, say so and it goes in the quote — or we tell you it does not belong in this engagement.
- Lawful basis and records of processing
- Transfer mechanism for India-based processing, with the assessment documented
- Data processing agreements and sub-processor register
- DPIA for high-risk processing, including AI systems
- Subject access request process that can actually be operated
Also in Security & Compliance
ISO 27001 implementationThe information-security certification European RFPs treat as table stakes.12–16 weeksSOC 2 readinessFor material US enterprise deals. Roughly 70–80% of the controls overlap with ISO 27001.9–14 months including observationDPDP Act complianceIndia's Digital Personal Data Protection Act, applied to systems you already run.3–8 weeksvCISO retainerPart-time security leadership for companies that need the function but not the salary.Monthly
Next step
Thirty minutes on whether this is the right engagement.
If a different service on this list fits better, or if you do not need us at all, that is what the call will conclude.