GDPR Readiness
Lawful bases, a Record of Processing Activities, working data subject rights, and a 72-hour breach process - built before a regulator or customer asks for them.
What This Engagement Covers
GDPR is not certified, it is enforced - and what a supervisory authority asks for after an incident is documentation you either have or you do not. We run readiness so your lawful bases, processing records, transfer mechanisms, data subject rights process, and breach notification procedure exist and work before anyone asks. The 72-hour notification clock is an operational problem, not a documentation one, and this is where that gets solved.
What This Means for Canadian Businesses
Canadian companies with customers, employees, or partners in the EU or UK are subject to GDPR regardless of where the company is incorporated. Post-Schrems II, Standard Contractual Clauses remain the most common mechanism for transferring personal data from Europe to Canada - but SCCs require a Transfer Impact Assessment to accompany them, and many Canadian companies have signed SCCs without completing the assessment. The EU has granted Canada an adequacy decision under the GDPR (for PIPEDA-covered organisations), but this does not cover all Canadian organisations or all transfers. Our team assesses your position against the full GDPR obligation set and pays particular attention to transfer mechanisms, processor chain documentation, and the data subject rights processes that EU customers will test.
Domains & Controls We Assess
We evaluate every technical, operational, and administrative requirement against authoritative criteria.
Principles and Lawfulness (Articles 5-6)
- Art. 5 - Data minimisation: only data necessary for the stated purpose is collected
- Art. 5 - Storage limitation: retention periods defined and enforced for each category
- Art. 6 - Lawful basis identified and documented for every processing activity
- Art. 9 - Special category data identified with appropriate legal basis and safeguards
Data Subject Rights (Articles 12-22)
- Art. 13/14 - Privacy notices provided at point of collection covering all required elements
- Art. 15 - Subject access request process: locate, compile, and respond within one month
- Art. 17 - Right to erasure: end-to-end deletion verified including third-party processors
- Art. 20 - Data portability: structured, machine-readable export process operational
- Art. 21 - Right to object to processing: mechanism available and honoured
Accountability and Governance (Articles 24-26)
- Art. 24 - Measures in place demonstrating compliance; reviewed and updated
- Art. 25 - Data protection by design and by default applied to new processing
- Art. 26 - Joint controller arrangements documented where applicable
- Art. 30 - Record of Processing Activities maintained and accurate
- Art. 37 - DPO designation assessed; appointment made if required
Security of Processing (Article 32)
- Art. 32(1)(a) - Pseudonymisation and encryption of personal data where appropriate
- Art. 32(1)(b) - Ongoing confidentiality, integrity, and availability of processing systems
- Art. 32(1)(c) - Ability to restore availability and access after physical/technical incident
- Art. 32(1)(d) - Regular testing and evaluation of security measure effectiveness
Breach Notification (Articles 33-34)
- Art. 33 - Breach detection, classification, and 72-hour supervisory authority notification process
- Art. 33(3) - Breach notification package: nature, categories, consequences, measures taken
- Art. 34 - High-risk breach communication to affected data subjects without undue delay
- Internal breach register maintained for all incidents regardless of notification threshold
International Transfers (Articles 44-49)
- Art. 44 - Transfer mechanism in place for every transfer outside the EEA
- Art. 46 - Standard Contractual Clauses signed and Transfer Impact Assessment completed
- Art. 28 - Processor agreements in place with all sub-processors; chain documented
- Adequacy reliance reviewed against current Commission decisions and transfer routes
Engagement Deliverables
Everything you need to prove control operating effectiveness to your auditors and enterprise clients.
Data Mapping and Record of Processing Activities (RoPA)
Lawful Basis Register for All Processing Activities
Gap Assessment Report Mapped to GDPR Articles
Transfer Impact Assessment and SCC Review
Data Subject Rights Process Documentation
Breach Notification Procedure (72-hour clock)
Trusted by Growing Businesses
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Common Questions
If you offer goods or services to people in the EU or UK, or monitor the behaviour of people in those jurisdictions, GDPR applies to you. The location of the company is not the test - the location of the data subjects is. If you have EU customers, EU employees, or EU website visitors you track, GDPR reaches you.
The EU adequacy decision for Canada covers organisations subject to PIPEDA for their commercial activities. It does not cover employee data, data handled by organisations outside PIPEDA's scope, or organisations that have moved to Quebec's Law 25 framework. The adequacy decision also does not mean your organisation is GDPR-compliant - it means transfers to you from the EU can occur without additional safeguards under the adequacy route, provided the data is handled lawfully. Your own obligations as a controller or processor remain.
SCCs are EU Commission-approved contract clauses that provide a legal basis for transferring personal data from the EU to countries without an adequacy decision - or to supplement adequacy where the risk profile requires it. Post-Schrems II, SCCs must be accompanied by a Transfer Impact Assessment evaluating whether the destination country's law undermines the protection the clauses provide. Many Canadian companies have SCCs in place without the TIA, which leaves the transfer mechanism incomplete.
Often Scoped Together
Ready for Your GDPR Readiness Assessment?
Speak directly with our senior Canadian compliance team. We establish your exact scope, quote a fixed flat-rate price, and deliver a definitive timeline.