GDPR requires more than policies and documentation. The company must be able to demonstrate that data protection has been translated into clear responsibilities, processes and controls that operate in day-to-day activities. For many companies, the challenge is not a lack of documents but a lack of an overall overview: Which personal data is processed? Which requirements apply? Where are the most significant gaps? And how is compliance demonstrated to management, customers and other stakeholders? RSM helps you gain an overview, prioritise initiatives and establish a GDPR framework tailored to your company and its risks. 

How we help you 

We can help you to: 

  • map processing activities, data flows and responsibilities 
  • assess your current GDPR framework 
  • identify significant gaps and risks 
  • prepare a prioritised roadmap 
  • establish or improve processes and controls 
  • review data processing agreements and supplier management 
  • strengthen the handling of data subject rights, data deletion and personal data breaches 
  • establish ongoing follow-up and reporting 

The aim is not to create more documentation than necessary. The aim is an operational framework that the company can maintain and use in practice. 

From requirements to specific actions 

A typical engagement consists of three phases: 

1. Overview 

We clarify the company's role, processing activities, significant risks and relevant requirements. 

2. GAP assessment and roadmap 

We assess existing processes, controls and documentation and prepare a prioritised plan for the areas requiring improvement. 

3. Implementation and follow-up 

If required, we help establish the necessary processes, controls and documentation and embed GDPR into ongoing operations. 

Do your customers require assurance? 

For data processors and other service providers, internal GDPR documentation is not always sufficient. Customers may request independent assurance that the agreed technical and organisational measures have been established and operate effectively. 

In these cases, an ISAE 3000 report on GDPR-related controls may be relevant. 

An ISAE 3000 report can give customers and their auditors insight into: 

  • which GDPR-related controls are covered 
  • how the controls were tested 
  • whether the controls have been established and operate effectively 
  • any exceptions identified 

An ISAE 3000 report is not an official GDPR certification. 

Advisory services and any subsequent assurance engagement are planned in accordance with the applicable auditor independence requirements. 

Why customers choose us 

We combine an understanding of data protection legislation with experience in information security, risk management and independent assurance engagements. 

This means that we can support you throughout the process, from interpreting the requirements to establishing an operational control environment that can be evidenced to customers and other stakeholders. 

 

You receive a pragmatic approach, clear recommendations and an engagement based on your actual risks and needs. 

Find out where to start 

Contact us for an initial discussion about your GDPR framework, most significant gaps and any need to provide customers with assurance.