Skip to main content
Home/Readiness/GDPR Readiness
GDPR Compliance

GDPR Readiness

Lawful bases, a Record of Processing Activities, working data subject rights, and a 72-hour breach process - built before a regulator or customer asks for them.

Standard GDPR
Typical Timeline 2-4 weeks
Starting Price $7,500
Scope Delivery Calgary, Toronto & Remote
Assessment Scope

What This Engagement Covers

GDPR is not certified, it is enforced - and what a supervisory authority asks for after an incident is documentation you either have or you do not. We run readiness so your lawful bases, processing records, transfer mechanisms, data subject rights process, and breach notification procedure exist and work before anyone asks. The 72-hour notification clock is an operational problem, not a documentation one, and this is where that gets solved.

Canadian Operations & Law

What This Means for Canadian Businesses

Canadian companies with customers, employees, or partners in the EU or UK are subject to GDPR regardless of where the company is incorporated. Post-Schrems II, Standard Contractual Clauses remain the most common mechanism for transferring personal data from Europe to Canada - but SCCs require a Transfer Impact Assessment to accompany them, and many Canadian companies have signed SCCs without completing the assessment. The EU has granted Canada an adequacy decision under the GDPR (for PIPEDA-covered organisations), but this does not cover all Canadian organisations or all transfers. Our team assesses your position against the full GDPR obligation set and pays particular attention to transfer mechanisms, processor chain documentation, and the data subject rights processes that EU customers will test.

Calgary HubAlberta Operations
Toronto HubOntario Operations
Control Framework

Domains & Controls We Assess

We evaluate every technical, operational, and administrative requirement against authoritative criteria.

Principles and Lawfulness (Articles 5-6)

  • Art. 5 - Data minimisation: only data necessary for the stated purpose is collected
  • Art. 5 - Storage limitation: retention periods defined and enforced for each category
  • Art. 6 - Lawful basis identified and documented for every processing activity
  • Art. 9 - Special category data identified with appropriate legal basis and safeguards

Data Subject Rights (Articles 12-22)

  • Art. 13/14 - Privacy notices provided at point of collection covering all required elements
  • Art. 15 - Subject access request process: locate, compile, and respond within one month
  • Art. 17 - Right to erasure: end-to-end deletion verified including third-party processors
  • Art. 20 - Data portability: structured, machine-readable export process operational
  • Art. 21 - Right to object to processing: mechanism available and honoured

Accountability and Governance (Articles 24-26)

  • Art. 24 - Measures in place demonstrating compliance; reviewed and updated
  • Art. 25 - Data protection by design and by default applied to new processing
  • Art. 26 - Joint controller arrangements documented where applicable
  • Art. 30 - Record of Processing Activities maintained and accurate
  • Art. 37 - DPO designation assessed; appointment made if required

Security of Processing (Article 32)

  • Art. 32(1)(a) - Pseudonymisation and encryption of personal data where appropriate
  • Art. 32(1)(b) - Ongoing confidentiality, integrity, and availability of processing systems
  • Art. 32(1)(c) - Ability to restore availability and access after physical/technical incident
  • Art. 32(1)(d) - Regular testing and evaluation of security measure effectiveness

Breach Notification (Articles 33-34)

  • Art. 33 - Breach detection, classification, and 72-hour supervisory authority notification process
  • Art. 33(3) - Breach notification package: nature, categories, consequences, measures taken
  • Art. 34 - High-risk breach communication to affected data subjects without undue delay
  • Internal breach register maintained for all incidents regardless of notification threshold

International Transfers (Articles 44-49)

  • Art. 44 - Transfer mechanism in place for every transfer outside the EEA
  • Art. 46 - Standard Contractual Clauses signed and Transfer Impact Assessment completed
  • Art. 28 - Processor agreements in place with all sub-processors; chain documented
  • Adequacy reliance reviewed against current Commission decisions and transfer routes
What You Receive

Engagement Deliverables

Everything you need to prove control operating effectiveness to your auditors and enterprise clients.

Data Mapping and Record of Processing Activities (RoPA)

Lawful Basis Register for All Processing Activities

Gap Assessment Report Mapped to GDPR Articles

Transfer Impact Assessment and SCC Review

Data Subject Rights Process Documentation

Breach Notification Procedure (72-hour clock)

Client Stories

Trusted by Growing Businesses

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
FAQ

Common Questions

Does GDPR apply to our Canadian company if we are not in Europe? +

If you offer goods or services to people in the EU or UK, or monitor the behaviour of people in those jurisdictions, GDPR applies to you. The location of the company is not the test - the location of the data subjects is. If you have EU customers, EU employees, or EU website visitors you track, GDPR reaches you.

Canada has an adequacy decision. Does that mean we are automatically compliant? +

The EU adequacy decision for Canada covers organisations subject to PIPEDA for their commercial activities. It does not cover employee data, data handled by organisations outside PIPEDA's scope, or organisations that have moved to Quebec's Law 25 framework. The adequacy decision also does not mean your organisation is GDPR-compliant - it means transfers to you from the EU can occur without additional safeguards under the adequacy route, provided the data is handled lawfully. Your own obligations as a controller or processor remain.

What are Standard Contractual Clauses and do we need them? +

SCCs are EU Commission-approved contract clauses that provide a legal basis for transferring personal data from the EU to countries without an adequacy decision - or to supplement adequacy where the risk profile requires it. Post-Schrems II, SCCs must be accompanied by a Transfer Impact Assessment evaluating whether the destination country's law undermines the protection the clauses provide. Many Canadian companies have SCCs in place without the TIA, which leaves the transfer mechanism incomplete.

Get Started

Ready for Your GDPR Readiness Assessment?

Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.