# GDPR Compliance Service

## GDPR Compliance Service

### Enabling a fundamental human right

The CCS GDPR Compliance Service will provide you everything you need to get to the lawful basis for processing:

1. A **comprehensive data asset inventory** with recommendations for anonymisation, pseudonymisation, minimisation of data retention, or outright deletion;
2. A **mapping of all personal data flows** against business processes;
3. A **mapping of all data assets** to internal, international, and/or outsourced data repositories;
4. A list of all relevant ‘upstream’ and ‘downstream’ **third parties**;
5. A breakdown of **security controls** per repository.

GDPR compliance starts and ends with your data; _what_ it is, _where_ it is, and what you’re doing _with_ it.

_Note: Optionally, CCS can arrange for legal partners to help with the determination and documentation related to the lawful basis assignments._

## Our Methodology

CCS utilises a proven methodology, developed over the course of multiple engagements, to help organisations achieve _sustainable_ compliance.

CCS uses one or preferably both of the following methods:

1. _Manual, interview-based questionnaires and guidance_: CCS will conduct a series of expert-led sessions with subject matter experts from each department or line of business; and / or
2. _Automated, Data Loss Prevention (DLP) powered data discovery_: CCS will utilise industry leading DLP solution to discover and map the flows of structured and unstructured personal data throughout the environment.

### Assessment Plan

01

#### Program Goals

02

#### Project Plan Definition

03

#### Program Execution

04

#### Project Close
