The place to start

GDPR Gap Analysis: Know Where You Stand

A GDPR gap analysis maps your organisation against the UK GDPR, shows exactly where the gaps are and hands you a costed plan to close them. It is the natural first step before a full audit or a remediation project. Fixed fee from £1,950, delivered in-house by CyPro's data protection consultants.

Why start here

Find out where you stand before you spend

Plenty of organisations know their GDPR compliance is not where it should be, but not which parts are the real exposure. A gap analysis answers that: a consultant reads your processing, policies and controls against the UK GDPR and tells you where you are genuinely at risk and where you are fine.

The output is not a scare-story list. It is a prioritised, costed plan, so you can fix the things that matter first, budget for the rest, and decide whether you need a full audit or hands-on remediation next.

You receive

  • A clear compliance position against the UK GDPR, area by area
  • Every gap rated by risk, so you know what actually matters
  • A costed remediation plan: what to fix, in what order, and the likely spend
  • A short management summary the board can read in minutes
  • A straight route into a full audit or a remediation project if you want one

Scope

What a gap analysis covers

The areas of the UK GDPR that most often carry hidden gaps for UK SMEs and mid-market organisations, each read in the context of how your business actually handles data.

  • Records of processing: what personal data you hold, where it sits and why
  • Lawful basis and consent for each processing activity
  • Privacy notices and transparency against what the UK GDPR requires
  • Subject access and the wider individual rights, tested against the deadlines
  • Security measures, retention and disposal of personal data
  • Supplier contracts, data sharing and any international transfers

The next step up

From gap analysis to full audit

Where the gap analysis shows you need a formal, evidence-based report, the full GDPR audit takes each area deeper and measures it against the ICO's Audit Framework. Many clients run the gap analysis first and commission the audit once the scope is clear. See the GDPR audit.

Overlap worth planning

Doing ISO 27001 as well?

Much of the security evidence a GDPR gap analysis gathers is the same evidence ISO 27001 asks for, so the two are best planned together rather than run twice. Our sister service covers the certification side. ISO 27001 certification.

Quick answers

Gap analysis questions, answered

What is the difference between a gap analysis and a full GDPR audit?

A gap analysis is the fast, lighter-touch entry point: it maps where you stand against the UK GDPR and gives you a costed plan to close the gaps. A full audit goes deeper, gathering evidence area by area against the ICO Audit Framework and producing a formal, defensible report. Most organisations start with the gap analysis, because it tells you the size and shape of the work before you commit to anything larger.

See the full GDPR audit

Do we get the cost of fixing the gaps, not just the list?

Yes. A list of gaps with no sense of effort or cost is of limited use, so the deliverable is a costed remediation plan: each gap ranked by risk, with the work to close it and an indicative cost attached. You leave knowing not only where you stand but what putting it right would take.

How does this relate to ISO 27001?

A large part of the evidence overlaps. The security controls a GDPR gap analysis looks at, access control, retention, supplier management and the rest, are much the same controls ISO 27001 asks you to demonstrate, so work done for one rarely goes to waste on the other. If you are pursuing certification as well, it is worth planning the two together.

ISO 27001 certification

What do you need from us to run one?

A scoping call, access to the documents you already have, such as privacy notices, policies and supplier contracts, and time with whoever owns data protection day to day. There is no software to install and nothing changes in your systems: a gap analysis reads how things are, it does not touch them.

Is it a fixed fee?

Yes, indicative fixed fees from £1,950, banded by the size and complexity of your organisation and confirmed at the scoping call. Because the scope of a gap analysis is well defined, we hold it to a fixed fee rather than an open day rate.

See published pricing

Rocket above the GDPR Consultancy call to action

One call to get started

Find out exactly where your GDPR stands

A free 45 minute scoping call, taken by a data protection consultant, sets out what the gap analysis would cover, the fixed fee to run it and what you get at the end.