Conducting GDPR Compliance Assessment
Effective Date: August 2026
Legal Basis: EU Regulation 2016/679 (GDPR), UK GDPR as amended by Data Protection Act 2018 and Data (Use and Access) Act 2025 (ukpga/2025/18)
Pending Changes: Digital Omnibus proposal (COM(2025) 837) would change Article 30(5) threshold from 250 to 750 employees and Article 33 breach notification from 72h to 96h. Still in proposal stage; current requirements remain in force.
When to Use
- When an organization processes personal data of EU residents (Article 3 territorial scope applies)
- When preparing for a supervisory authority audit (ICO, CNIL, BfDI) or responding to formal inquiry
- When implementing privacy-by-design requirements (Article 25) for new systems or data flows
- When scoping compliance gaps before M&A due diligence or contract negotiations with EU entities
- When responding to data subject access requests (DSARs) and discovering gaps in data inventory
- When assessing third-party processors for GDPR compliance before signing Data Processing Agreements (DPAs)
- After data breach incidents to verify notification procedures meet 72-hour requireme…