Regulatory & Privacy · EU General Data Protection Regulation
A GDPR assessment that shows you exactly where you stand.
We examine how your company collects, uses, and moves EU personal data, then hand you a prioritized gap report and a remediation plan you can actually work through.
A GDPR assessment is a structured review of how your company handles EU and EEA personal data against the General Data Protection Regulation. FinAudit CPA maps your data flows, tests your lawful basis, records, and transfer mechanisms, then delivers a prioritized gap report and remediation plan so you can close the risks that matter most.
Reviewed by Debraj Hazra, CPA (USA), ACA (ICAEW, ICAI)
Last updated July 2026
What a GDPR assessment actually covers
The General Data Protection Regulation is the EU law that governs how organizations handle personal data belonging to people in the European Union and the wider European Economic Area. It applies by behavior, not by geography. If your product signs up users in Berlin, your marketing targets buyers in Paris, or your platform processes data on behalf of a client with European customers, GDPR reaches you even if every server and every employee sits in the United States.
A GDPR assessment answers a plain question your board and your enterprise customers keep asking: where do we actually stand? We work through the parts of the regulation that carry real risk. That means your lawful basis for each use of data, the rights you owe the people whose data you hold, the records you are required to keep, the impact assessments you may have skipped, the line between controller and processor, how data crosses borders, whether you need a data protection officer, and how fast you can react to a breach.
One boundary matters up front. This is a practical compliance assessment and a plan to fix gaps, not a legal opinion. We tell you what the regulation expects, where your program falls short, and how to close the distance. When you need a binding interpretation of a hard edge case, that formal opinion comes from privacy counsel, and we work alongside them rather than pretending to replace them.
GDPR does not care where your office is. It cares whose data you touch. A US company with a single European user is inside the regulation, and a regulator will read your records, not your intentions.
Does GDPR apply to your US company?
For most companies that reach us, the answer is yes, and the surprise is how little it takes to get there. The regulation applies to you in two broad situations. The first is when you offer goods or services to people in the EU, whether or not they pay. A free tier counts. The second is when you monitor the behavior of people in the EU, which sweeps in analytics, ad tracking, and profiling far more often than teams expect.
A few concrete cases show the reach:
- US SaaS with EU users. You sell software to companies or individuals, and some of them are in Europe. Their account data, usage logs, and support tickets are all personal data under GDPR.
- Global platforms and marketplaces. You operate at scale across regions, so European personal data flows through your systems constantly, often on behalf of your own customers.
- Companies that process data for others. You never sell to Europe directly, but a client does, and you handle that data as their vendor. You are a processor, and the regulation binds you too.
If any of these fit, the practical question is no longer whether GDPR applies. It is how far your current program sits from what the regulation expects, and which gaps a regulator or a European customer would flag first.
Controller or processor: which are you?
GDPR assigns duties based on your role in each activity, and most companies are a controller for some data and a processor for other data. Getting this right shapes your contracts, your records, and who answers to a regulator. Here is how the two roles differ.
| Controller | Processor | |
|---|---|---|
| Who it is | The company that decides why and how personal data is used | The company that processes personal data on a controller's instructions |
| Typical example | Your own product deciding what user data to collect and why | A vendor running analytics or storage on your behalf |
| Core duty | Establishes lawful basis and answers to data subjects | Follows the controller's documented instructions and secures the data |
| Records required | A full record of processing activities as controller | A record of processing carried out for each controller |
| Contract needed | Issues data processing agreements to its vendors | Signs data processing agreements with each controller it serves |
| Breach role | Notifies the regulator and, when required, the affected people | Notifies the controller without undue delay so they can act |
How our GDPR assessment runs
You always know which stage you are in and what we need from you. No vague retainer, no open-ended discovery.
-
01
Scoping and data mapping
We identify the systems, products, and vendors that touch EU personal data, and we map how that data enters, moves through, and leaves your organization. You get a fixed fee before we begin.
-
02
Lawful basis and rights review
We test whether each use of data has a valid lawful basis and whether you can actually honor access, deletion, correction, portability, and objection requests within the time limits.
-
03
Records and DPIA review
We check your records of processing (ROPA) for completeness and identify the high-risk activities that require a Data Protection Impact Assessment you may not have run.
-
04
Transfers and roles
We examine how data leaves the EU, whether your Standard Contractual Clauses and transfer safeguards hold up, and whether your controller and processor roles are documented correctly.
-
05
Governance and breach readiness
We assess whether you need a data protection officer, review your vendor agreements, and pressure-test whether you can meet the 72-hour breach notification duty.
-
06
Gap report and remediation plan
We deliver a prioritized report tied to the specific Articles at stake, ranked by risk, with a remediation plan you can hand to your team and track to completion.
What you get, and how long it takes
You receive a written GDPR assessment built around your actual data, not a generic template. It opens with a data flow map showing where EU personal data lives and moves. It then walks through each pillar of the regulation — lawful basis, data subject rights, records of processing, impact assessments, controller and processor roles, international transfers, the data protection officer question, and breach response — and states plainly where you comply and where you do not.
The heart of the deliverable is the gap report. Every finding cites the part of the regulation it relates to, carries a risk rating, and comes with a concrete remediation step. High-risk gaps that a regulator or a European buyer would flag first sit at the top, so you spend your effort where it counts rather than polishing low-stakes paperwork.
Timing depends on your size and how much of your data landscape is already documented. A focused assessment for a single SaaS product often takes a few weeks from kickoff to final report. A global platform with many systems, vendors, and cross-border flows takes longer, because the data mapping alone is heavier. We give you a realistic schedule during scoping and hold to it.
What actually drives the cost
We quote a fixed engagement fee after scoping, so you will not face a surprise hourly bill. The number reflects real factors, not guesswork:
Volume and variety of data
A single product with a clean data model costs less to assess than a platform collecting many categories of personal data across several services.
Number of systems and vendors
Every system and sub-processor that touches EU data adds to the mapping and the transfer review. More moving parts means more to examine.
How much is already documented
If your records of processing and data flows already exist, we move faster. If we have to build the map from scratch, that discovery is where the hours go.
Cross-border complexity
Data that stays in one place is simpler than data flowing to multiple regions under different transfer mechanisms, each of which we have to check.
Why run your GDPR assessment with FinAudit CPA
Privacy compliance is not a form to fill in. It is a discipline built from controls, evidence, and honest reporting, which is exactly the work a CPA firm does every day. We approach your GDPR program the way we approach any control environment: we test what you claim, document what we find, and rank the risks by what a scrutinizing outsider would actually cite.
You also get the practical benefit of overlap. The records, access controls, vendor oversight, and breach procedures GDPR expects share a great deal with SOC 2, ISO 27701, and other frameworks. We map your privacy controls once so the evidence carries over instead of being rebuilt for each program. And we stay in our lane. We deliver assessment and remediation, and we coordinate cleanly with your privacy counsel when a question needs a formal legal opinion rather than a compliance judgment.
The result is a report you can act on. Your team gets a ranked list of fixes, your leadership gets a defensible view of where the company stands, and your European customers get evidence that you take their data seriously.
Pair your GDPR assessment with
- CCPA and CPRA compliance, when the same platform serves California consumers alongside EU users
- ISO 27701 privacy, when you want a certifiable privacy management system built on your GDPR work
- HIPAA, when your platform also handles protected health information for US health-tech clients
- SOC 2, to show buyers the security controls that underpin the privacy commitments you make
GDPR Assessment · questions buyers ask
Yes, in most cases we see. GDPR applies to any organization that offers goods or services to people in the EU or monitors their behavior, regardless of where the company is based. A US firm with EU users, EU-facing marketing, or analytics that track European visitors falls inside the regulation. Having no European office does not exempt you, so the real question is how large your compliance gap is.
GDPR requires a valid legal reason for every use of personal data. The six lawful bases include consent, contract, legal obligation, vital interests, public task, and legitimate interests. You must pick and document the right one for each activity before you process the data. If you cannot point to a lawful basis, the processing is unlawful, which is one of the first things a regulator checks.
A record of processing activities documents what personal data you handle, why, who you share it with, where it goes, and how long you keep it. GDPR requires most organizations to maintain one. It is often the first document a regulator asks for, because it shows whether you actually understand your own data. Our assessment reviews your ROPA for completeness or helps you build it from your data map.
A DPIA is required when a processing activity is likely to create a high risk to people, such as large-scale profiling, systematic monitoring, or handling sensitive data at scale. It documents the risk and how you reduce it. Many companies skip DPIAs they legally owe. Our assessment flags the high-risk activities in your environment that require one so you can close the gap.
Moving EU personal data outside the EEA requires a valid transfer mechanism. Transfers to countries with an adequacy decision are straightforward. For others, including much of the US, you typically rely on Standard Contractual Clauses plus supplementary safeguards. We check whether your transfers rest on a valid mechanism and whether the paperwork behind them actually holds up under scrutiny.
Not every company does. GDPR requires a DPO when your core activities involve large-scale, regular monitoring of people or large-scale processing of sensitive data, or when public-body rules apply. Many companies fall outside the mandatory trigger but still benefit from assigning clear privacy ownership. Our assessment tells you whether the requirement applies to you and how to structure accountability if it does not.
When a personal data breach occurs, a controller generally must notify the relevant supervisory authority within 72 hours of becoming aware of it, and inform affected people when the risk to them is high. Meeting that window takes preparation, not improvisation. We pressure-test whether your detection, escalation, and notification process can realistically move that fast under real conditions.
No. FinAudit CPA delivers a practical GDPR assessment and a plan to remediate gaps, grounded in what the regulation requires and how a regulator reads it. We are a licensed US CPA firm applying audit discipline to your privacy controls. When a question needs a binding interpretation or a formal legal opinion, that comes from your privacy counsel, and we coordinate with them directly.
Pair it with
Audit once, comply many.
CCPA / CPRA Compliance
Get your California privacy program right before a consumer request or the state agency tests it.
HIPAA Compliance Assessment
Prove your health-tech platform handles PHI the way HIPAA requires — assessed by a licensed CPA firm.
ISO/IEC 27701 (Privacy)
Turn your ISO 27001 ISMS into a certified privacy program buyers trust.