- What they do
- Data protection + ISO 27001
- Who they help
- Evalian is a data protection + ISO 27001 based in UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Information Security & Privacy
GDPR
The General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union's data protection law, adopted April 27, 2016 and applicable since May 25, 2018. It applies to any organization established in the EU that processes personal data, and to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior.
It sets principles (lawfulness, purpose limitation, minimization, accuracy, storage limitation, security, accountability), individual rights, controller and processor duties, cross-border transfer rules, 72-hour breach notification to the supervisory authority, and fines of up to 20 million euros or 4 percent of worldwide annual turnover.
The accountability principle makes documentation mandatory. Controllers and processors must keep records of processing activities (Article 30), sign written contracts with processors (Article 28), carry out data protection impact assessments for high-risk processing (Article 35), appoint a Data Protection Officer where required (Article 37), publish privacy notices, and keep policies and evidence showing appropriate technical and organizational measures (Article 32).
Certification under Article 42 is voluntary; approved schemes now include Europrivacy as a European Data Protection Seal and national schemes such as GDPR-CARPA in Luxembourg.
Who has to comply
Controllers and processors established in the EU or EEA, regardless of where processing happens, and non-EU organizations that target or monitor people in the EU. Small organizations are exempt from Article 30 records only if they have fewer than 250 employees and their processing is occasional, low risk and does not involve special categories.
What the assessor asks to see
Records of processing activities; lawful basis analysis and consent records; privacy notices; processor agreements and sub-processor lists; data protection impact assessments; DPO designation and reports; data subject request logs; security policies and Article 32 measures; breach register and notifications; international transfer tools and transfer impact assessments; training records; for certification, the scheme's specific criteria evidence.
Where the requirement sits: Art 5(2) accountability; Art 24 policies; Art 30 RoPA; Art 32 security; Art 35 DPIA; Art 39(1)(b) awareness/training
Article 42 certification
Certification is voluntary and does not reduce liability. The EDPB register lists approved mechanisms, including Europrivacy (an EU-wide European Data Protection Seal, with updated criteria approved in EDPB Opinions 14/2026 and 15/2026, the latter for use as a transfer tool by non-EEA importers), GDPR-CARPA (Luxembourg) and national schemes in Germany, Austria, France and the Netherlands.
Check the register for the current list and the accredited certification bodies for each scheme.
What AllyMatter does here
Policy documentation and staff-acknowledgment layer.
AllyMatter publishes this site.
Assessors
Who assesses GDPR
No mandatory assessor. Supervisory authorities (for example CNIL, the Irish DPC, the German state authorities) investigate and enforce. Voluntary Article 42 certification is issued by certification bodies accredited under Article 43 against EDPB-approved criteria, or by the supervisory authority itself.
Accredited by National accreditation bodies under ISO/IEC 17065 (with supervisory authority requirements) or the supervisory authority itself, per Article 43; the EDPB approves criteria for European Data Protection Seals.
Public register of assessors: https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en
No firm has claimed a GDPR assessor listing yet. Claim yours →
Consultants
Who helps with GDPR
A very large ecosystem: privacy law firms, DPO-as-a-service providers, privacy consultancies and GRC platforms. They build records of processing, run DPIAs, draft notices and processor agreements, handle transfer impact assessments and act as outsourced DPO. Engagement shapes range from one-off gap assessments to standing retainers.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
Software
Tools for GDPR
Tools that name this framework in their own material.
Related reading
- Record of processing activities: are you ready for maturity?Article 30 records are the document a supervisory authority asks for first; this explains what a usable one contains.IAPP
- How to draft a GDPR-compliant retention policyPractical guidance on turning storage limitation into a written policy with defensible periods, from the privacy profession's own body.IAPP
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for GDPR
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of GDPR in AllyMatter
Approve the policies GDPR asks for, keep every version, and record a named acknowledgment from each person who has to read them.