KNOW THE REQUIREMENT. PLAN THE WORK.
Different rules. A clearer next step. GDPR, security standards and sector rules cover different things. Understand the scope, keep your evidence together and know when to bring in a specialist.
Choose your frameworks Website testing Preparation records Specialist assessmentPrivacy law
EU GDPR Organisations within the GDPR’s territorial scope, including some businesses outside the EU.
How GDPRFix helps Website consent evidence, processing records, supplier records and rights-request tracking.
What needs a wider review Lawful-basis decisions, all internal processing, DPIAs, international transfers and legal advice require a wider assessment.
Preparation checklist Confirm scope and controller/processor roles Map processing, purposes and lawful bases Assess consent, rights handling and transparency Review security, transfers and high-risk processing EUR-Lex · Regulation (EU) 2016/679 ↗ UK privacy & cookie rules
UK GDPR & PECR Businesses processing personal information within UK GDPR scope; PECR separately regulates cookies and similar technologies.
How GDPRFix helps Before-consent, rejection and acceptance browser tests, privacy-information checks and a record of technical fixes.
What needs a wider review Exemptions, marketing permissions and internal complaint procedures need factual review. A green scan is not approval from the ICO.
Preparation checklist Confirm UK GDPR and PECR applicability Inventory cookies and assess exemptions Test real consent and withdrawal behaviour Document rights, complaints and retention processes Information Commissioner’s Office ↗ Independent assurance
SOC 2 Service organisations seeking an examination of controls against applicable Trust Services Criteria.
How GDPRFix helps Store preparation notes, responsibility, evidence references and review dates; use website evidence where relevant.
What needs a wider review GDPRFix does not perform a SOC 2 examination or issue a SOC 2 report. A qualified independent CPA firm must carry out the examination.
Preparation checklist Agree system boundaries and relevant Trust Services Criteria Assign control owners and collect evidence Review gaps with a qualified assessor Arrange the independent examination AICPA & CIMA · SOC services ↗ Security management standard
ISO 27001 Organisations establishing an information security management system; certification is a separate assessment.
How GDPRFix helps Organise supplier reviews, data inventories and evidence references for your security programme.
What needs a wider review This workspace does not implement a full ISMS, license the standard text or provide ISO certification.
Preparation checklist Define ISMS scope and responsibilities Assess information-security risks Plan treatment and maintain the Statement of Applicability Complete internal review and certification assessment if sought ISO · ISO/IEC 27001 ↗ US health information rules
HIPAA US covered entities and business associates, rather than every website discussing health.
How GDPRFix helps Record an initial applicability assessment and supplier-review references without uploading patient data.
What needs a wider review No HIPAA compliance audit or business associate agreement is provided by this workspace. Do not store protected health information here.
Preparation checklist Determine covered-entity or business-associate status Map protected health information in approved systems Review supplier agreements and safeguards Obtain a specialist privacy and security assessment US HHS · Covered entities and business associates ↗ California privacy law
CCPA / CPRA Businesses meeting applicable California statutory criteria; assess thresholds and exemptions.
How GDPRFix helps Organise data categories, suppliers, rights cases and evidence references.
What needs a wider review The scanner does not currently test all California opt-out, sale/sharing or Global Privacy Control requirements. GDPR consent alone does not establish CCPA compliance.
Preparation checklist Assess applicability and exemptions Map collection, disclosure, sale and sharing Review notices and opt-out preference signals Assess consumer-rights handling and applicable deadlines California Privacy Protection Agency ↗ Payment data security
PCI DSS Entities that store, process or transmit account data, or could affect the security of the cardholder-data environment.
How GDPRFix helps Keep payment-provider references, scope notes, responsible owners and review dates.
What needs a wider review No ASV scan, SAQ validation or QSA assessment is provided. Never store card numbers or security codes in GDPRFix.
Preparation checklist Confirm scope with your payment provider/acquirer Identify applicable validation requirements Review payment-page scripts and relevant security controls Arrange required validation and specialist assessment PCI Security Standards Council ↗ Custom requirements
Other frameworks Additional laws, sector rules or contractual requirements you need to assess.
How GDPRFix helps Create a custom record with the applicable source, scope, owners and evidence references.
What needs a wider review Coverage is not implied. Confirm requirements and specialist support before relying on a custom assessment.
Preparation checklist Identify the authoritative source Confirm applicability and scope Assign an owner and evidence references Arrange specialist review where needed EDPB · Small business guidance ↗ Start with what your website does. Test cookie behaviour, understand the findings, then get a bespoke technical fix plan.
Run a free website scan