The process
How it works
A GDPR project runs as a clear sequence: a scoping call, a gap analysis or an audit against the UK GDPR and the ICO framework, findings triaged and prioritised, a report with a costed remediation plan, and, where you want it, remediation and a re-check. The same sequence runs whether you commission a single piece of work or a full compliance project. It is delivered in-house by CyPro's data protection consultants, one team from first call to final report.
Six steps
From scoping call to a compliant position
Every engagement runs this sequence. What changes between a gap analysis, an audit, a DPIA and a full compliance project is how deep the review goes, not the shape of the process around it.
Step 1
The scoping call
Free, taken by a data protection consultant rather than a salesperson. We establish where your organisation is, what personal data you hold and where it flows, whether a gap analysis or a fuller audit fits, and the organisation-size bracket you sit in. By the time the call ends you already know the indicative fixed fee, the same figure we set out on the pricing page.
Step 2
Scope confirmed, access arranged
We confirm in writing the piece of work in scope, the organisation-size bracket, and the systems, records and processing the project covers, then arrange access to the people and documentation it draws on. A fixed-scope statement of work is agreed before the project begins, so there are no moving goalposts once it is under way.
Step 3
The gap analysis or audit against the UK GDPR
Our consultants review your data protection against the UK GDPR and, for a fuller audit, the ICO's accountability and audit framework. We map what personal data you hold, where it flows and how it is protected, drawing on your policies, records of processing, systems and management sessions. What gets examined scales with the depth you commissioned.
Step 4
Findings triaged and prioritised
Every finding is weighed for the risk it carries and prioritised: a serious exposure is separated from a housekeeping fix, and the things that matter from the noise. Before anything reaches you, each finding is checked over for accuracy and relevance, so what lands in the report has been reviewed rather than handed across unfiltered.
Step 5
Findings and a costed remediation plan
You receive a clear report: where you stand against the UK GDPR, what is at risk, and a prioritised, costed remediation plan ordered for the people who will act on it. It is written to put in front of a board, an auditor or a client, without reworking it first.
Step 6
Remediation support and a re-check
Where you want it, the same consultants carry out the remediation: policies, records of processing, DPIAs and the supporting documentation put right. A re-check then confirms the gaps are closed. Remediation and the re-check can be folded into a full compliance project or scoped separately; the same team stays with you throughout.
How the work is scoped
One piece of work, or the whole programme
The sequence above runs the same way whichever route you take. What changes is how much of it you commission, and it is always delivered as a fixed-scope project rather than an open-ended retainer.
A single piece of work. A gap analysis, a GDPR audit or a DPIA, scoped and priced on its own, when you know the piece you need and want it done well. Each produces a report and, where relevant, a costed remediation plan you can act on.
A full compliance project. The gap analysis or audit, the remediation that follows and a re-check, run as one fixed-scope project when you want your GDPR position put right end to end. See the prices on the pricing page.
The exchange
What the project needs from you, and what you get back
What it asks of you
- A named contact: someone who receives the findings and can reach the people who run your systems and processing.
- Your organisation and the work defined: the organisation-size bracket, and whether it is a gap analysis, an audit, a DPIA or a full compliance project.
- Access to the policies, records of processing, systems and people the review draws on, arranged at scoping.
- Written authorisation for any technical access to or testing of your systems, agreed at scoping; we never test systems we have not been authorised on.
What it hands back
- A clear view of where your organisation stands against the UK GDPR, and exactly where the risk sits.
- Findings ordered by the risk they carry, with a prioritised, costed remediation plan, not a raw list to decode.
- A report you can put in front of a board, an auditor or a client without reworking it.
- One team throughout, hands-on remediation where you want it, and a re-check that confirms the gaps are closed.
Common questions
What organisations ask before they commission
What does a GDPR project involve?
It runs as a clear sequence: a scoping call to fix what you need, access to your policies, records and systems, the gap analysis or audit against the UK GDPR, then every finding triaged and prioritised, a report with a costed remediation plan, and, where you want it, the remediation and a re-check. The same shape runs whether you commission a gap analysis, an audit, a DPIA or a full compliance project. What changes is how deep the review goes, not the order of the work.
What is the difference between a gap analysis and an audit?
A gap analysis maps where you stand against the UK GDPR and produces a prioritised, costed plan; it is the natural first step and the lighter piece of work. A GDPR audit goes deeper and is evidence-based, run against the ICO's accountability and audit framework, and suits an organisation that needs a fuller, defensible assessment. The scoping call confirms which one fits, and both are delivered in-house by the same consultants.
How is a GDPR project priced?
To a fixed fee against an agreed scope, not an open day rate. What sets the figure is the size of your organisation and the complexity of your data: how much personal data you hold, how many systems and third parties it moves through, and how sensitive it is. The indicative prices are published on the pricing page, and the fee is confirmed for your organisation at scoping.
What happens after we get the findings?
You get a report and a prioritised, costed remediation plan, and we talk through what the highest-risk findings mean and how to close them. The plan is yours to act on with your own team, or you can bring us in to carry out the remediation, put the policies, records and documentation right, and run a re-check that confirms the gaps are closed. Where that is the plan from the outset, it is scoped as a full compliance project.
Step one costs nothing
Book the scoping call
Bring where your organisation is now and a rough idea of what you need. We bring the sequence above, the indicative fixed fee, and a clear view of whether a gap analysis, an audit or a full compliance project fits.