← All assessments
For software and technology companies selling to enterprise · fixed-fee assessment

Your GDPR posture, scored — and a roadmap to fix it.

An enterprise buyer’s security review is the moment GDPR gaps surface. Find and close them before the deal depends on it.

A scored diagnostic across all nine GDPR domains, every gap rated by risk and effort, and a prioritised roadmap with the templates pointed at your gaps — delivered in about a week.

✓ Put-right-or-refund guarantee. Fixed scope, fixed fee · report in about a week · Enterprise scoped on a free intro call.

representative layout
GDPR Gap Assessment

Your GDPR report

  • Board summary1 p
  • Score · nine domainsRAG-rated
  • Gap registerrisk × effort
  • Remediation roadmapfix-first
  • Templates pointed at gapsincluded
  • Walkthrough call60 min
Findings — extract
HighTransfers — no safeguards on US analytics vendorfix · 1 wk
MedRoPA — six activities undocumentedfix · 2 wks
LowRetention schedule stale (Mar 2025)at renewal
Fix-first roadmap
SCORE · Developingcurrent as of July 2026
What you get

Two ways to run it.

Standard is a fixed price you buy directly. Enterprise covers multiple entities and hands-on rollout, scoped on a short call.

Standard · €4,900

Your GDPR posture, scored

  • Scored across all nine domains — lawful bases, data-subject rights, records (RoPA), security (Art 32), processors & DPAs, international transfers, breach readiness, retention and consent
  • A gap register, each gap rated by risk and effort
  • A prioritised remediation roadmap, plus the GDPR kit templates pointed at your gaps
  • A written report (board summary + findings) and a walkthrough call
  • Your reviewed processing activities returned structured in the RoPA register, from the information you provide — ready to maintain, not a blank template

Fixed scope — one entity, up to ~20 processing activities · report in about a week

Book now — €4,900

✓ Put-right-or-refund — revised until right, or refunded in full (14 days)

Enterprise · from €8,900

Multi-entity & DPO-level

  • Everything in Standard, plus:
  • Multiple entities, products or large data estates
  • Hands-on remediation, including DPAs and vendor chains
  • Ongoing review as you implement

Scoped to your estate

How it works

From access to roadmap in about a week.

How every assessment runs
01 · intake
Scope confirmed

You share access and context; we agree the scope in writing before any work starts.

02 · analysis
Classified & scored

We test your setup against the obligations that bind you — each finding cited, rated by risk and effort.

03 · report
Board-ready findings

A written report: findings, a scored rating and a prioritised fix-first roadmap.

04 · walkthrough
Live call

We talk through the findings, the priorities and your questions.

05 · follow-up
Yours to keep

The report, roadmap and relevant kit templates — plus a review a month on.

Working with your team

Enterprise and retained work can run in a shared Slack or Microsoft Teams channel — hand-offs where your team already works, our side archived on Proton.

The deliverable

A report you can take to the board.

What lands in your inbox.

A written, board-ready report (PDF) — all nine domains scored, findings rated by risk and effort, a fix-first roadmap — plus your RoPA returned as a structured, maintained register, the GDPR kit templates mapped to your gaps, and a 60-minute walkthrough call.

Representative layout.

Example findings

  • — “Transfers: no safeguards on your US analytics vendor · risk High / effort Low.”
  • — “RoPA: six processing activities undocumented, one listed system already retired · risk High / effort Medium.”
  • — “Breach plan written, never rehearsed; vendors owe you no notice · risk Medium / effort Low.”
A consultancy’s GDPR gap assessment is open-ended and billed by the hour.

The same nine-domain diagnostic, gap register and roadmap — from someone who has built GDPR programmes at scale — as a fixed €4,900, in about a week. Put-right-or-refund, in writing.

Who does the work
SENIOR
EXPERT

You work with the person behind the templates: 15 years across contracts, GDPR, IP and the AI Act — 10,000+ contracts and corporate documents reviewed, 1,000+ deals negotiated, a recent USD 40M+ exit managed end to end. Consulting clients work with the founder directly, by name.

Fixed scope, fixed fee, agreed up front · not legal advice · no lawyer–client relationship

Want the DIY version first? The GDPR Compliance Kit — the same substance, done yourself for a fraction of the price.

See the kit

Already own the GDPR Compliance Kit? Its fee is credited in full against this assessment.

Scope — what €4,900 buys, and the limits

Limits — additional activities in blocks of 10 at +€600; one lead-authority context. Not included — DPIA drafting for specific processing (quoted separately), DPO service.

After the report you’re not on your own — execute it yourself with the GDPR Kit, hand remediation to the Enterprise tier, or keep it current with Fractional support.

The GDPR menu

Wherever you are with GDPR, here’s what fits.

Pick the one that matches where you are — each stands alone, buy in any order or on its own. Your team does the work with our templates; that’s why this costs a fraction of a consultancy.

Check yourself — free
GDPR Readiness ScorecardA dynamic read across your bases and transfers in minutes.Open ›
Get assessedyou’re here
GDPR Gap Assessment · €4,900Nine domains scored, gaps rated, a prioritised roadmap.On this page
Get the documents
GDPR Compliance Kit · €690The full policy, notice, DPA and register set — deployable.Open ›
Get it done, keep it current
Enterprise · Fractional · a free intro callHands-on remediation, ongoing upkeep, or a free scoping call.Open ›
A specific DPA on the table?
Expert Contract ReviewSenior review and negotiation of the contract in front of you.Open ›
Eligibility, up front

Can we take this directly?

Three questions

1 · WHOSE RULES APPLY?

  • You’re established in the EU/EEA or the UK, or you target those marketsyes — delivered directly by the founder. Measuring what you have against what a regulation requires is compliance work, not reserved legal practice, which is why a senior assessment is available here at a fraction of a consultancy — lawfully, and in the open.
  • Another regime → tell us which in the enquiry. Most assessment work is open on the same basis; a few markets reserve formal advice on local law to admitted lawyers. We confirm within one business day, before any charge.

2 · WHAT THE ASSESSMENT PRODUCES

  • A findings report — your actual position measured against the Articles, cited, severity-ranked, with a prioritised remediation roadmap and the evidence trail behind each finding → that’s exactly what we deliver.
  • Something you can hand over — to a buyer’s diligence team, an enterprise procurement reviewer, or your board, without translating it first.

3 · WHERE THE LINE SITS

  • Reserved work → representation before a supervisory authority, regulator or court; conducting litigation; filings or notifications made on your behalf; notarial acts; a formal legal opinion in a market that restricts who may give one. That’s an admitted lawyer, and we’ll say so and route you rather than blur the line — introduced and coordinated by us, contracted by you directly.
  • Statutory appointments → naming a DPO, an Article 27 EU Representative or an AI Act Authorised Representative is a separate engagement with its own terms and its own liability, not something an assessment includes. If the assessment finds you need one, we’ll tell you — and we can take the role under a separate mandate.
  • Privilege → an assessment report is a written record of where you currently stand, and it is not covered by legal professional privilege. For most readiness work that’s the point — it’s evidence you’re looking honestly. Where there’s live investigation, complaint or litigation exposure, that calculus changes, and we’ll say so before we write rather than after.
  • What it is and isn’t → an assessment is a dated snapshot against the law as it stands on the day. It doesn’t itself make you compliant, and it doesn’t bind a regulator’s view.

We are not a law firm and don’t hold ourselves out as one. No court work, no filings, no regulated titles, no privilege. Tell us where you’re established and what needs assessing — scope is confirmed within one business day, and you’re never charged before it is.

Questions

Before you book.

Do you need access to our systems?

We need context and limited access to the right people and documents — confirmed in writing as part of scope before any work starts. We don’t need production data.

How long does it take?

About a week from when access and scope are confirmed. Standard covers one entity and up to ~20 processing activities.

Is this restricted legal advice?

No. This is a fixed-scope commercial compliance assessment — structured information and expert analysis of your posture — not legal advice, a formal legal opinion, or representation before a regulator. It’s run by a senior practitioner; no lawyer–client relationship or privilege is created, and Xprofesso LLC is not a law firm.

What we’ll do: assess your setup against the GDPR framework, score it, and hand you a prioritised, fix-first roadmap plus the templates to close the gaps — where you stand, and what to do next.

What we won’t: draft DPIAs for specific processing (quoted separately), act as your DPO, act for you before a supervisory authority or regulator, or give an opinion on whether a measure is legally sufficient under a specific law. Where you need a regulated professional, we say so and point you to a licensed lawyer.

What if I’m not happy with it?

Put-right-or-refund guarantee — if the report falls short, say so within 14 days of delivery: we revise it until it’s right or refund the fee in full.

Direct line · reply within one business day

Ask about scope before you book

One message — no account, no call required. It lands in our Proton inbox.

Proton (Switzerland) · no ad-tech · purged after 12 months

Prefer to talk it through? Book a free 20-minute intro call ›

Pass the security review instead of stalling on it.