GDPR · EU 2016/679 · INDEPENDENT REVIEW

Compliant is not enough. You have to be able to show it.

GDPR follows the person, not your head office - and accountability means proving it article by article, rather than asserting it.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Personal data is somebody else's, held on trust
Article 30 records Lawful basis Data subject rights DPIAs 72-hour breach clock

Our promise

“Compliance is a claim. Article 30 is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

GDPR, in three chapters

The Regulation

Regulation (EU) 2016/679 has applied since 25 May 2018, and it is the instrument every privacy law written since has been measured against. It reaches any organisation processing the personal data of people in the Union, whatever address that organisation keeps, wherever it sits.

The Gap

Six principles sit in Article 5(1), accountability in Article 5(2), and data protection by design in Article 25. Most teams can recite them. Far fewer can produce the record, the basis, the notice and the assessment that show one was actually applied to a real system, not asserted.

The Review

We are the independent reader the accountability principle assumes. iDharma works from your systems rather than your questionnaire, tests each obligation against the article it comes from, and hands back the records, procedures and assessments that evidence it — dated.

What is personal data?

Anything that points back to a person.

Any information relating to an identified or identifiable living person - however indirectly.

Who owes these duties № 01
  • Controllers, who decide why and how data is used
  • Processors, acting on a controller’s instructions
  • Employers and HR platforms holding staff records
  • Anyone running solely automated decisions
GDPR · iDharma · Presented for review
When the duty triggers № 02
  • You offer goods or services to people in the EU or UK
  • You track, profile or analyse how they behave
  • Data leaves the EEA - a US cloud region counts
  • You reuse data collected for one purpose to train a model
GDPR · iDharma · Presented for review
Whose duty is it

The duty is yours. The systems are theirs.

You

The controller of the processing

You decide why and how personal data is processed, so almost every duty in the Regulation lands on you first - whoever actually runs the systems. Article 5(2) then adds the one that governs the rest: you must be able to demonstrate compliance, not merely achieve it and assert that you have.

Your processor

The people who run it for you

Acts on your documented instructions, and the label follows the facts rather than the contract. A processor is not a place to put your duties: Article 28 binds it by contract, while Articles 30, 32 and 33 and Chapter V bind it directly - and none of that discharges a single one of yours, in either direction.

The catch

Outside the EU is not outside GDPR

Article 3(2) reaches you if you offer goods or services to people in the Union, or monitor their behaviour. Payment is not required and an English-language site alone is not the test - but ordinary analytics and ad pixels sit squarely inside the monitoring limb, which is how most teams arrive in scope.

What most teams assume

“We’re not established in the EU, so this isn’t ours.”

What the Regulation says

GDPR follows the person, not the letterhead.

It is the most common finding we write up.

  • Who it is for
  • SaaS & cloud platforms
  • E-commerce & marketplaces
  • Marketing & AdTech
  • HR & employer platforms
  • AI and model builders
Why this matters in 2026
A thick black-bound volume on a dark desk under a low lamp, a printed sheet of tabulated figures and charts resting across its cover, a red ribbon marker hanging from the page block, and a fountain pen laid beside it: the text itself, with the working papers on top.
01 Two tiers, and the higher one covers the principles, the rights and transfers: €10 million or 2% of global annual turnover, €20 million or 4% - whichever is greater.
02

Article 5(2) puts the burden of proof on you. Being compliant and being able to demonstrate it are two separate obligations, not one.

03

A supervisory authority can open on one person’s complaint. It does not need a programme of inspections to reach you.

04

Your notices, your consent banner and your sub-processor list are all checkable from outside, by anyone, before a letter is ever written.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

People in the EU or UK -

The person, not the head office. Article 3(2) turns on where the individual is. Customers, prospects, employees and job applicants all count, and so does a visitor your analytics measured.

It is personal data -

Anonymous is a much higher bar than pseudonymised. If any key, join or extra dataset can put a name back on a row, Recital 26 says it is still personal data.

Article 30 record -

It is the first thing asked for. Article 30 is where a supervisory authority starts, because every other obligation is checked against what the record says you do.

The calendar

Four clocks, and not one of them is yours to set.

Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.

  1. Notify

    72 hours

    The breach clock runs from when you become aware, not from when the investigation closes or the cause is known.

  2. Respond

    One month

    Every data subject request, extendable by two months for complexity - if you say so within the first one.

  3. Assess

    Before you start

    A DPIA runs before high-risk processing starts. After launch it is a record of what happened, not a forecast.

  4. Re-record

    On every change

    The Article 30 record tracks the estate. A new system, a new purpose or a new processor dates it on arrival.

The trap

Teams book the DPIA and forget that it has to be finished before the processing starts. Run after launch it is a description of what you already did - a record rather than an assessment, and the wrong document to hand over.

Requirement & coverage

What the Regulation says, what we ship

12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.

Records of processing Article 30
A completed ROPA for each role you hold, with purposes, categories, recipients, transfers and retention filled in rather than left as headings.
Lawful basis register Articles 6 and 9
A basis recorded per purpose, the Article 9 condition where special category data is involved, and a legitimate interests assessment where you rely on one.
Privacy notices Articles 13 and 14
Notices per audience, checked line by line against the mandatory content list - including the Article 14 case where you did not collect the data yourself.
Data subject rights procedure Articles 12 and 15-22
One intake route, an identity-verification step, the one-month clock with its extension criteria, and a decision record per request.
Impact assessments Article 35
A screening test that says when a DPIA is needed, the methodology, and completed DPIAs for the processing that triggers it.
Breach response Articles 33 and 34
A detection-to-decision runbook, the 72-hour notification pack, the internal breach register, and the high-risk test for telling individuals.
Processor contracts Article 28
A clause-by-clause review of your processor terms, a sub-processor position, and the gap list against the eight mandatory contract terms.
International transfers Chapter V
A transfer register, the mechanism per route - adequacy, SCCs, BCRs - and a transfer impact assessment where the mechanism needs one.
Retention schedule Article 5(1)(e)
A period per data category with the justification beside it, and the deletion route named rather than assumed to exist.
Security measures Article 32
The measures you actually run, mapped to the risk they address, so "appropriate" is an argument on paper rather than an adjective.
Accountability and roles Articles 5(2), 24 and 37-39
The DPO test answered either way in writing, a RACI for the duties, and the evidence pack that demonstrates compliance rather than asserting it.
Automated decision safeguards Article 22
A register of solely automated decisions, the lawful gateway for each, the logic explanation, and a human-intervention route a person can actually reach.
The engagement

Personal data, independently reviewed

From one CRM to a cross-border estate.

  1. Map

    Which systems hold personal data, on what basis, and where it goes.

  2. Test

    Records, notices, rights, DPIAs, transfers and security, article by article.

  3. Report and hand over

    You see the draft first. Then the report, the register and the templates - dated.

Request your GDPR review
An auditor in a navy trouser suit and cream blouse, with shoulder-length blonde hair, standing against a warm pale wall and pointing into the open space alongside.
The record is the deliverable - that is what you are buying.
Struck in your favour

Why teams choose iDharma for their GDPR review

Genuinely independent

We sell no privacy platform and no certificate, and we take no fee tied to what the review finds.

Written to the article

Every finding names the article it comes from, so your counsel checks it against the text rather than against us.

One review, end to end

Records, notices, rights, DPIAs and transfers in one scope, so nothing falls into the gap between vendors.

Evidence, not assertion

You get the artefacts Article 5(2) asks you to produce - not a score, and not a badge for your footer.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

GDPR readiness report

The full review: what you process, on what basis, where it goes and what is missing - written article by article, with each finding ranked by the consequence to a person rather than by how easy it is to close. Where a scope question is genuinely arguable, it says so instead of picking the convenient reading.

Workbook

Article 30 records

The ROPA for each role you hold, mapped from the systems inwards rather than from a questionnaire outwards, so it matches what your estate actually does.

Repository

Policy and notice set

The data protection policy, privacy notices per audience and the retention schedule, drafted against your processing rather than a template library.

Procedure

Data subject rights pack

One intake route, identity verification, response templates for all eight rights, and a search that reaches the ticketing system and the backups.

Method

DPIA methodology

The screening test that says when one is needed, the methodology, and the completed assessments for the processing that actually triggers it.

72 hours

Breach runbook

Detection to decision, the notification pack drafted before you need it, the internal register, and the separate high-risk test for telling individuals.

Chapter V

Transfer register

Every route personal data takes out of the EEA, the mechanism holding it up, and the transfer impact assessment where that mechanism needs one.

Format & fee

Real numbers, upfront.

Scope
Set by the Regulation, not by us
Data
Your systems and your records
Re-review
Every twelve months - $10,500 against your known baseline

The Regulation fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
GDPR · Named engagement $12,500 flat
  • Independent GDPR readiness report
  • Article 30 records & lawful basis register
  • 31 policy and notice documents
  • DPIA, breach and transfer packs
Show your hand

Four things you have to be able to produce

GDPR is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The record,
current

An Article 30 record that matches the estate as it actually runs today. It is the first thing a supervisory authority asks for, and it is usually the first to have gone stale.

The basis,
per purpose

A lawful basis recorded against each purpose rather than each system, with the Article 9 condition where the data is special category. Consent is the fragile one.

The clocks,
both met

Seventy-two hours to the supervisory authority, counted from awareness, and one month to the person who asked. Neither clock waits while you decide.

The transfer,
lawful

A mechanism per route out of the EEA, and the impact assessment behind each one. A cloud region setting is a configuration, not a Chapter V transfer mechanism.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Scope, roles, deadlines, transfers, cost. Answered straight.

Request this review
Does GDPR apply to us if we are outside the EU?

If you offer goods or services to people in the EU, or monitor their behaviour, Article 3(2) reaches you wherever you are established. Payment is not required, and an English-language site alone is not the test.

What is the difference between a controller and a processor?

A controller decides the purposes and means; a processor acts on documented instructions. The label follows the facts, not the contract - a vendor that uses the data for its own ends is a controller for that processing.

How long do we have to answer a data subject request?

One month from receipt, extendable by two for complexity - but you must tell the person inside the first month, with the reason. The clock does not pause while you decide whether the request is valid.

What does the 72-hour breach clock actually run from?

From when you become aware, not from when the investigation finishes. You may notify in phases if you cannot supply everything in time, but the initial notification still has to go in.

What does an iDharma GDPR review cost, and what comes with it?

A flat fee, stated in full on this page, with nothing charged until you approve the scope. It includes the Article 30 records, the assessments, and the policy and notice set the review writes against.

Get started

Request your GDPR review

Tell us what you process and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this comes out of your systems and vendor paperwork in an afternoon, and we tell you which extracts before you commit.

  1. Which systems hold personal data, and for what purpose
  2. Whether any of the people are in the EU or the UK
  3. Your processor list, and where each one is hosted
  4. Whatever Article 30 record already exists
  5. Your target date, if a customer or a regulator set one

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request your GDPR review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Regulation (EU) 2016/679, on EUR-Lex
  • EDPB guidelines and ICO UK GDPR guidance
In force
24 May 2016
Applies from
25 May 2018

What it means

  • General information about what the Regulation requires — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • Do not rest a binding decision on it; engage qualified counsel.
  • Use it as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us