Know where you stand before a regulator does.
Expert-led review, not an automated scan. GDPR compliance comes down to judgment calls a script can't make - lawful basis, data processing agreements, breach procedures - so every review here is done by hand, by me.
What it covers
Three phases, all done by hand: a technical review, a structured questionnaire, and a personal write-up of both - no automated scoring at any stage.
Technical Review
Cookie consent banner check, tracking script detection, privacy policy presence, and HTTPS/data-in-transit check - checked by hand, not run through an automated scanner, so a technically-present-but-non-compliant banner doesn't get waved through.
Data Practices Questionnaire
Structured questions covering what data you collect, how consent is captured, retention periods, third parties you share data with, and breach readiness - the parts a scan can't see.
Manual Review
I go through the scan results and your questionnaire answers together, flag the gaps, and prioritize them by actual regulatory and reputational risk - not a generic checklist.
How it runs
No automated compliance score. No generic checklist. You get a report written by a person who actually read your answers.
Ready to know where the gaps are?
Request an assessmentAlready spoken with me about a scan? Submit written authorization to get it scheduled - this comes after that initial conversation, not instead of it.