All frameworks
    Regulatory auditEuropean Union; enforced by national Data Protection Authorities

    GDPR

    GDPR: General Data Protection Regulation (EU 2016/679)

    GDPR is the EU's data protection law. Compliance is demonstrated through audits and documentation, not a single official certificate.

    Last verified Jul 17, 2026

    Q&A

    What is GDPR?

    GDPR is the EU's data protection law. Compliance is demonstrated through audits and documentation, not a single official certificate.

    Who needs GDPR?

    Any organization, anywhere, that processes the personal data of individuals in the EU, including non-EU companies offering goods or services to, or monitoring, people in the EU.

    How long does GDPR take?

    GDPR compliance is ongoing. An initial gap assessment and remediation program typically span several months, after which the program is maintained and periodically re-audited.

    How much does a GDPR audit cost?

    Audit and gap-assessment fees vary with data footprint and complexity. The larger cost is usually implementing and maintaining the privacy program, including any DPO function.

    What does a GDPR audit cover?

    An independent audit reviews your processing activities, lawful bases, data-subject-rights handling, security measures, and documentation against the GDPR, producing findings and recommendations rather than a pass/fail certificate.

    What it is

    The General Data Protection Regulation governs how organizations process the personal data of people in the EU, regardless of where the organization itself is based. It sets out lawful bases for processing, strengthened data-subject rights, obligations around consent, records of processing, data protection impact assessments, and, for some organizations, a Data Protection Officer.

    GDPR is a regulation rather than a certification scheme. While Article 42 allows for approved certification mechanisms, these remain limited in practice, so most organizations demonstrate compliance through independent audits, gap assessments, and documented programs rather than a certificate.

    Enforcement sits with national Data Protection Authorities, which can levy significant fines. The practical objective is a mature, evidenced privacy program that can withstand scrutiny from a regulator or a data subject exercising their rights.

    Who needs it

    Any organization, anywhere, that processes the personal data of individuals in the EU, including non-EU companies offering goods or services to, or monitoring, people in the EU.

    What's audited

    An independent audit reviews your processing activities, lawful bases, data-subject-rights handling, security measures, and documentation against the GDPR, producing findings and recommendations rather than a pass/fail certificate.

    Typical timeline

    GDPR compliance is ongoing. An initial gap assessment and remediation program typically span several months, after which the program is maintained and periodically re-audited.

    Typical cost

    Audit and gap-assessment fees vary with data footprint and complexity. The larger cost is usually implementing and maintaining the privacy program, including any DPO function.

    What to verify on an auditor

    Choose auditors with genuine EU data-protection expertise: privacy law grounding, DPO-level experience, and familiarity with the relevant supervisory authority. Where an Article 42 certification applies, confirm the body is accredited for it.

    Service pathways

    Not every service under this framework is fully available today. Hover a pathway for context.

    • Article 42 formal certification
      Article 42 certification schemes exist in only a few member states and no dominant EU-wide scheme has emerged. Most GDPR work in the market is audit and advisory rather than formal certification.
      Emerging
    • DPIA for specific processing activities
      Available
    • GDPR compliance audit
      Available
    • Outsourced DPO services
      Available

    Find GDPR auditors by region

    Browse independent GDPR auditors serving each region.