GDPR service options
Choose the GDPR service level that matches supplier criticality, required review depth, and the level of confidence your organisation needs.
GDPR preset has a fixed scope (no extra modules). Custom assessments are priced per module.
Controlled Supplier Monitoring
Best for: controlled access to public-source monitoring before or independently of a managed GDPR assessment
Controlled access
Commercial terms and monitored-supplier scope are provided during access review; recurring execution is not open self-service.
- Exact-L1 automated OSINT only — deterministic rules, no AI and no human review
- Scheduled public-source supplier baseline and recurring monitoring where separately enabled
- Supplier identity and objective trustworthiness-supporting public signals
- Traceable before / after change history and updateable downloadable report
- Provider-gated sources are identified with access limitations and official links where available
- Decision-support indicators only — not a rating, certification, verdict, or assurance
Supplier outreach, questionnaires, evidence review and expert assessment are part of managed L2/L3 services, outside the controlled Essential access scope.
Managed GDPR Assessment
Best for: fintech startups and other SMB firms that need outsourced GDPR supplier assessment without building the capability in-house
Price: €2,500 (excl. VAT)
Target delivery: 5–7 business days (after required inputs are received)
- Managed GDPR assessment delivered through the platform
- GDPR-focused supplier questionnaire, document collection, and evidence review
- Expert review of answers & evidence (manual validation)
- 1 clarification round (follow-ups)
- Written findings (HTML/DOCX) + board-ready summary
Enhanced GDPR Assessment
Best for: critical ICT and third-party providers where deeper evidence review and stronger decision support are required
Price: €4,000 (excl. VAT)
Target delivery: 10–15 business days (after required inputs are received)
- Everything in Advanced (L2), plus audit-style evidence review and control-level findings
- Supplier interview (60–90 minutes) + evidence walkthrough (what exists, what is missing)
- Up to 2 clarification rounds (follow-ups) + tracked evidence gaps within defined scope
- Traceable GDPR risk narrative for defensible decisions (not certification / not assurance)
- Written findings (HTML/DOCX) + decision-ready summary pack
- Internal governance reuse focus (clear evidence trail within defined scope)
VAT is applied based on customer location and VAT status. EU business customers with a valid VAT ID are typically charged 0% VAT under reverse charge.