1 - Initial GDPR compliance audit
Kada Data Protection conducts a comprehensive initial GDPR compliance audit designed to assess the organisation’s overall level of conformity with applicable data protection requirements. This audit provides a structured and objective overview of existing practices, identifies compliance strengths and weaknesses, and establishes a clear baseline from which corrective actions and long-term compliance strategies can be defined.
2 - Data processing mapping
KDP performs a detailed mapping of data processing activities, documenting the flow of personal data across systems, departments, and third parties. This mapping allows the organisation to gain full visibility over how personal data is collected, used, stored, and shared, forming a cornerstone of both regulatory compliance and effective data governance.
3 - Legal bases assessment
Each identified processing activity is subject to a legal bases assessment to ensure that processing is grounded in a valid and appropriate legal basis under the GDPR. KDP analyses the relevance, consistency, and proportionality of the chosen legal bases, ensuring that they are properly documented and defensible in the event of regulatory scrutiny.
4 - Compliance gap analysis
KDP conducts a structured gap analysis comparing the organisation’s current practices against regulatory requirements and recognised best practices. This analysis identifies areas of non-compliance or partial compliance and translates them into clear, prioritised remediation recommendations aligned with the organisation’s operational realities.
5 - Legal and operational risk assessment
Building on the audit findings, KDP evaluates legal and operational data protection risks, taking into account the nature of the processing activities, the categories of data involved, and the organisation’s business model. This risk-based approach enables informed decision-making and supports the implementation of proportionate and effective compliance measures.