GDPR Technical Gap Assessment
2–3 week engineering audit of your infrastructure against GDPR Article 32. 20-page executive report with prioritized findings and 90-day remediation roadmap.
Web Direct's GDPR Technical Gap Assessment is a 2–3 week engineering audit of your infrastructure against the 14 technical requirements of GDPR Article 32. Senior engineers review your stack, deliver a 20-page executive PDF report with prioritized findings, and provide a 90-day remediation roadmap with budget estimates. Fixed price €1,800–2,700.
📋Why this service exists
GDPR Article 32 requires organizations to implement appropriate technical measures. Without a gap assessment, you cannot know which measures are missing — making this service the essential first step of any compliance programme.
What you get
- 20-page executive PDF report
- Prioritized findings by GDPR article
- 90-day remediation roadmap with budget estimates
- Risk register (high/medium/low)
- Live walkthrough call (1h) with your team
- 30-day Q&A support post-delivery
How we deliver
- Day 0You request quote → reply in 4 business hours
- Day 1–2Discovery call & scope clarification
- Day 3–5Contract signed, kickoff scheduled
- Day 5–7Implementation begins
- Day NFinal deliverables + walkthrough call
- +30 daysFree post-delivery support
Tools & technologies
Prerequisites
- Read-only access to infrastructure (AWS/GCP console or Terraform state)
- Architecture diagram or description
- List of third-party processors (SaaS tools used)
Pricing
✓ Within scope:
- •Infrastructure review (AWS/GCP/on-prem)
- •Single PostgreSQL/MySQL/MongoDB cluster
- •Application-level PII handling review
- •Third-party integrations (up to 10 vendors)
⚠ Outside scope (additional quote required):
- •Remediation implementation (separate service)
- •Policy/legal document review (lawyers' scope)
- •More than 3 separate environments
📋Final price confirmed in proposal within 4 hours of your request.
Realistic timeline — what to expect
- T+0hSubmit request
- T+4hInitial proposal (business hours)
- T+1–3dDiscovery call
- T+2–3dFinal invoice
- T+3–5dContract signed
- T+4–6dPayment received
- T+5–7dService kickoff
- T+5–7d+NService complete
Frequently asked questions
How is this different from a legal GDPR audit?
Do you need production access?
What format is the report?
Can this help us prepare for a DPA inspection?
What if we already have some controls in place?
Related services
Data Discovery & PII Mapping
Automated discovery of all personal data across databases, cloud storage, and SaaS tools — delivered as an Article 30 Records of Processing Activities (RoPA) data map.
PII Access Logging Implementation
Implement comprehensive audit logging of every access to personal data: who accessed what, when, from which IP, for what purpose — immutable, tamper-evident log storage.
SIEM Setup (Security Information & Event Management)
Deploy and configure a SIEM (Wazuh + OpenSearch or Elastic SIEM) to correlate security events, detect breach indicators, and enable 72-hour Article 33 breach notification compliance.
