GDPR, Run As A Programme
GDPR is a regulation, not a certification. There is no certificate to earn and no auditor to pass. What a supervisory authority asks for is evidence that you know what personal data you hold, why you hold it, and what you do when someone asks about it. Auditara turns that into a programme you can actually run.
What This Is, And What It Is Not
Not Legal Advice
Auditara is a compliance programme platform delivered with a PECB certified Lead Auditor and Lead Implementer. It is not a law firm and does not provide legal advice. Where a question turns on legal interpretation, we will tell you to take advice.
Not A Certificate
No one issues a GDPR certificate. Anyone selling you one is selling you something else. What you get here is a defensible programme and the evidence behind it.
Works Alongside ISO 27001
Security of processing under Article 32 is where GDPR and ISO 27001 meet. Run both in the same workspace and the security evidence serves both programmes.
What The Programme Covers
Forty one obligations across the areas a regulator examines, each assessed with your context and evidence guidance in plain English.
Principles And Lawful Basis
Every purpose you process personal data for, with the legal basis that permits it, and legitimate interests assessments where you rely on them.
Transparency
Privacy notices at the point of collection and for data obtained from other sources, written so people can actually understand them.
Individual Rights
Access, rectification, erasure, restriction, portability and objection. A workflow that works before the first request arrives, not after.
Accountability
Records of processing, the DPO assessment, privacy by design in your projects, and the evidence pack a regulator would ask to see.
Processors And Contracts
A register of who processes data on your behalf, the contract terms that must be in place, and visibility of their sub processors.
Security Of Processing
Technical and organisational measures proportionate to the risk, mapped the same way an ISO 27001 control set would be.
Breach Response
The seventy two hour clock, the assessment that decides whether it starts, notification templates, and a breach register that covers events you did not report.
International Transfers
Where data leaves the region, the mechanism relied on for each route, and transfer risk assessments where standard clauses are used.
Data Lifecycle
Retention schedules that are enforced rather than filed, minimisation at the point of collection, and accuracy over time.
How The Programme Runs
The same guided journey as every framework in Auditara. The content changes; the method does not.
Book The Call
Fifteen minutes with a PECB certified Lead Auditor and Lead Implementer. Your role as controller or processor, the data you hold, and where the pressure is coming from. Your workspace opens after the call.
Answer The Intake
Plain English questions about your organisation. Your answers shape the programme, the register and the documents that follow.
Assess Every Obligation
Work through the obligations one at a time in guided mode, with guidance on each explaining what evidence looks like in practice.
Remediate With Owners And Dates
Every gap becomes a tracked item with an owner, a priority and a target date. Recurring obligations become tasks with reminders.
Hold The Evidence In One Place
Your record of processing, processor register, DPIA screening records, breach log and training records live in the workspace, not across four inboxes.
Stay Accountable
Reviews come round on a schedule. The accountability pack stays current, so a regulator request is a download rather than a fire drill.
Every route starts with a call with a certified ISO 27001 and ISO 42001 Lead Implementer.
Book A CallQuestions
Do we need a DPO?
It depends on what you process and at what scale. The programme includes a documented assessment either way, which is itself part of the accountability obligation.
We are a processor, not a controller. Does this still apply?
Yes. Processors have direct obligations, including contract terms, security of processing, sub processor authorisation and assisting controllers with rights requests. The intake asks which role applies to you.
We are outside the EU. Does GDPR reach us?
It can, where you offer goods or services to people in the EU or monitor their behaviour. The intake captures this, and the programme covers the representative requirement where it applies.
How does this relate to UK GDPR?
The obligations are closely aligned. Where your lead regulator sits changes who you notify and consult, which the intake captures.
Can you write our privacy notices?
Documents in Auditara are generated from your own answers and then approved with you. You get a starting draft that reflects your actual processing rather than a template someone else filled in.
What happens if we have a breach during the programme?
The breach procedure and register are part of the programme, so the process exists before you need it. The seventy two hour clock starts on awareness, not on certainty.
Ready To Get Started?
Book the call. Fifteen minutes, no obligation, and you leave with a route.
