Regulation (EU) 2016/679 has applied since 25 May 2018, and it is the instrument every privacy law written since has been measured against. It reaches any organisation processing the personal data of people in the Union, whatever address that organisation keeps, wherever it sits.
Compliant is not enough. You have to be able to show it.
GDPR follows the person, not your head office - and accountability means proving it article by article, rather than asserting it.
Our promise
“Compliance is a claim. Article 30 is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditGDPR, in three chapters
Six principles sit in Article 5(1), accountability in Article 5(2), and data protection by design in Article 25. Most teams can recite them. Far fewer can produce the record, the basis, the notice and the assessment that show one was actually applied to a real system, not asserted.
We are the independent reader the accountability principle assumes. iDharma works from your systems rather than your questionnaire, tests each obligation against the article it comes from, and hands back the records, procedures and assessments that evidence it — dated.
Anything that points back to a person.
Any information relating to an identified or identifiable living person - however indirectly.
- Controllers, who decide why and how data is used
- Processors, acting on a controller’s instructions
- Employers and HR platforms holding staff records
- Anyone running solely automated decisions
- You offer goods or services to people in the EU or UK
- You track, profile or analyse how they behave
- Data leaves the EEA - a US cloud region counts
- You reuse data collected for one purpose to train a model
The duty is yours. The systems are theirs.
The controller of the processing
You decide why and how personal data is processed, so almost every duty in the Regulation lands on you first - whoever actually runs the systems. Article 5(2) then adds the one that governs the rest: you must be able to demonstrate compliance, not merely achieve it and assert that you have.
The people who run it for you
Acts on your documented instructions, and the label follows the facts rather than the contract. A processor is not a place to put your duties: Article 28 binds it by contract, while Articles 30, 32 and 33 and Chapter V bind it directly - and none of that discharges a single one of yours, in either direction.
Outside the EU is not outside GDPR
Article 3(2) reaches you if you offer goods or services to people in the Union, or monitor their behaviour. Payment is not required and an English-language site alone is not the test - but ordinary analytics and ad pixels sit squarely inside the monitoring limb, which is how most teams arrive in scope.
“We’re not established in the EU, so this isn’t ours.”
GDPR follows the person, not the letterhead.
It is the most common finding we write up.
- Who it is for
- SaaS & cloud platforms
- E-commerce & marketplaces
- Marketing & AdTech
- HR & employer platforms
- AI and model builders
Article 5(2) puts the burden of proof on you. Being compliant and being able to demonstrate it are two separate obligations, not one.
A supervisory authority can open on one person’s complaint. It does not need a programme of inspections to reach you.
Your notices, your consent banner and your sub-processor list are all checkable from outside, by anyone, before a letter is ever written.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four clocks, and not one of them is yours to set.
Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.
-
Notify
72 hoursThe breach clock runs from when you become aware, not from when the investigation closes or the cause is known.
-
Respond
One monthEvery data subject request, extendable by two months for complexity - if you say so within the first one.
-
Assess
Before you startA DPIA runs before high-risk processing starts. After launch it is a record of what happened, not a forecast.
-
Re-record
On every changeThe Article 30 record tracks the estate. A new system, a new purpose or a new processor dates it on arrival.
Teams book the DPIA and forget that it has to be finished before the processing starts. Run after launch it is a description of what you already did - a record rather than an assessment, and the wrong document to hand over.
What the Regulation says, what we ship
12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.
- Records of processing Article 30
- A completed ROPA for each role you hold, with purposes, categories, recipients, transfers and retention filled in rather than left as headings.
- Lawful basis register Articles 6 and 9
- A basis recorded per purpose, the Article 9 condition where special category data is involved, and a legitimate interests assessment where you rely on one.
- Privacy notices Articles 13 and 14
- Notices per audience, checked line by line against the mandatory content list - including the Article 14 case where you did not collect the data yourself.
- Data subject rights procedure Articles 12 and 15-22
- One intake route, an identity-verification step, the one-month clock with its extension criteria, and a decision record per request.
- Impact assessments Article 35
- A screening test that says when a DPIA is needed, the methodology, and completed DPIAs for the processing that triggers it.
- Breach response Articles 33 and 34
- A detection-to-decision runbook, the 72-hour notification pack, the internal breach register, and the high-risk test for telling individuals.
- Processor contracts Article 28
- A clause-by-clause review of your processor terms, a sub-processor position, and the gap list against the eight mandatory contract terms.
- International transfers Chapter V
- A transfer register, the mechanism per route - adequacy, SCCs, BCRs - and a transfer impact assessment where the mechanism needs one.
- Retention schedule Article 5(1)(e)
- A period per data category with the justification beside it, and the deletion route named rather than assumed to exist.
- Security measures Article 32
- The measures you actually run, mapped to the risk they address, so "appropriate" is an argument on paper rather than an adjective.
- Accountability and roles Articles 5(2), 24 and 37-39
- The DPO test answered either way in writing, a RACI for the duties, and the evidence pack that demonstrates compliance rather than asserting it.
- Automated decision safeguards Article 22
- A register of solely automated decisions, the lawful gateway for each, the logic explanation, and a human-intervention route a person can actually reach.
Personal data, independently reviewed
From one CRM to a cross-border estate.
-
Map
Which systems hold personal data, on what basis, and where it goes.
-
Test
Records, notices, rights, DPIAs, transfers and security, article by article.
-
Report and hand over
You see the draft first. Then the report, the register and the templates - dated.
Why teams choose iDharma for their GDPR review
Genuinely independent
We sell no privacy platform and no certificate, and we take no fee tied to what the review finds.
Written to the article
Every finding names the article it comes from, so your counsel checks it against the text rather than against us.
One review, end to end
Records, notices, rights, DPIAs and transfers in one scope, so nothing falls into the gap between vendors.
Evidence, not assertion
You get the artefacts Article 5(2) asks you to produce - not a score, and not a badge for your footer.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
GDPR readiness report
The full review: what you process, on what basis, where it goes and what is missing - written article by article, with each finding ranked by the consequence to a person rather than by how easy it is to close. Where a scope question is genuinely arguable, it says so instead of picking the convenient reading.
Article 30 records
The ROPA for each role you hold, mapped from the systems inwards rather than from a questionnaire outwards, so it matches what your estate actually does.
Policy and notice set
The data protection policy, privacy notices per audience and the retention schedule, drafted against your processing rather than a template library.
Data subject rights pack
One intake route, identity verification, response templates for all eight rights, and a search that reaches the ticketing system and the backups.
DPIA methodology
The screening test that says when one is needed, the methodology, and the completed assessments for the processing that actually triggers it.
Breach runbook
Detection to decision, the notification pack drafted before you need it, the internal register, and the separate high-risk test for telling individuals.
Transfer register
Every route personal data takes out of the EEA, the mechanism holding it up, and the transfer impact assessment where that mechanism needs one.
Real numbers, upfront.
- Scope
- Set by the Regulation, not by us
- Data
- Your systems and your records
- Re-review
- Every twelve months - $10,500 against your known baseline
The Regulation fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- Independent GDPR readiness report
- Article 30 records & lawful basis register
- 31 policy and notice documents
- DPIA, breach and transfer packs
Four things you have to be able to produce
GDPR is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The record,
current
An Article 30 record that matches the estate as it actually runs today. It is the first thing a supervisory authority asks for, and it is usually the first to have gone stale.
The basis,
per purpose
A lawful basis recorded against each purpose rather than each system, with the Article 9 condition where the data is special category. Consent is the fragile one.
The clocks,
both met
Seventy-two hours to the supervisory authority, counted from awareness, and one month to the person who asked. Neither clock waits while you decide.
The transfer,
lawful
A mechanism per route out of the EEA, and the impact assessment behind each one. A cloud region setting is a configuration, not a Chapter V transfer mechanism.
Four cards, and the date on each one is part of the card.
Does GDPR apply to us if we are outside the EU?
If you offer goods or services to people in the EU, or monitor their behaviour, Article 3(2) reaches you wherever you are established. Payment is not required, and an English-language site alone is not the test.
What is the difference between a controller and a processor?
A controller decides the purposes and means; a processor acts on documented instructions. The label follows the facts, not the contract - a vendor that uses the data for its own ends is a controller for that processing.
How long do we have to answer a data subject request?
One month from receipt, extendable by two for complexity - but you must tell the person inside the first month, with the reason. The clock does not pause while you decide whether the request is valid.
What does the 72-hour breach clock actually run from?
From when you become aware, not from when the investigation finishes. You may notify in phases if you cannot supply everything in time, but the initial notification still has to go in.
What does an iDharma GDPR review cost, and what comes with it?
A flat fee, stated in full on this page, with nothing charged until you approve the scope. It includes the Article 30 records, the assessments, and the policy and notice set the review writes against.
Request your GDPR review
Tell us what you process and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this comes out of your systems and vendor paperwork in an afternoon, and we tell you which extracts before you commit.
- Which systems hold personal data, and for what purpose
- Whether any of the people are in the EU or the UK
- Your processor list, and where each one is hosted
- Whatever Article 30 record already exists
- Your target date, if a customer or a regulator set one
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Regulation (EU) 2016/679, on EUR-Lex
- EDPB guidelines and ICO UK GDPR guidance
- In force
- 24 May 2016
- Applies from
- 25 May 2018
What it means
- General information about what the Regulation requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- Do not rest a binding decision on it; engage qualified counsel.
- Use it as a starting point for a scoping conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom