KNOW THE REQUIREMENT. PLAN THE WORK.

Different rules.
A clearer next step.

GDPR, security standards and sector rules cover different things. Understand the scope, keep your evidence together and know when to bring in a specialist.

Choose your frameworks
Website testing Preparation records Specialist assessment

Privacy law

EU GDPR

Organisations within the GDPR’s territorial scope, including some businesses outside the EU.

How GDPRFix helps

Website consent evidence, processing records, supplier records and rights-request tracking.

What needs a wider review

Lawful-basis decisions, all internal processing, DPIAs, international transfers and legal advice require a wider assessment.

Preparation checklist
  • Confirm scope and controller/processor roles
  • Map processing, purposes and lawful bases
  • Assess consent, rights handling and transparency
  • Review security, transfers and high-risk processing
EUR-Lex · Regulation (EU) 2016/679 ↗

UK privacy & cookie rules

UK GDPR & PECR

Businesses processing personal information within UK GDPR scope; PECR separately regulates cookies and similar technologies.

How GDPRFix helps

Before-consent, rejection and acceptance browser tests, privacy-information checks and a record of technical fixes.

What needs a wider review

Exemptions, marketing permissions and internal complaint procedures need factual review. A green scan is not approval from the ICO.

Preparation checklist
  • Confirm UK GDPR and PECR applicability
  • Inventory cookies and assess exemptions
  • Test real consent and withdrawal behaviour
  • Document rights, complaints and retention processes
Information Commissioner’s Office ↗

Independent assurance

SOC 2

Service organisations seeking an examination of controls against applicable Trust Services Criteria.

How GDPRFix helps

Store preparation notes, responsibility, evidence references and review dates; use website evidence where relevant.

What needs a wider review

GDPRFix does not perform a SOC 2 examination or issue a SOC 2 report. A qualified independent CPA firm must carry out the examination.

Preparation checklist
  • Agree system boundaries and relevant Trust Services Criteria
  • Assign control owners and collect evidence
  • Review gaps with a qualified assessor
  • Arrange the independent examination
AICPA & CIMA · SOC services ↗

Security management standard

ISO 27001

Organisations establishing an information security management system; certification is a separate assessment.

How GDPRFix helps

Organise supplier reviews, data inventories and evidence references for your security programme.

What needs a wider review

This workspace does not implement a full ISMS, license the standard text or provide ISO certification.

Preparation checklist
  • Define ISMS scope and responsibilities
  • Assess information-security risks
  • Plan treatment and maintain the Statement of Applicability
  • Complete internal review and certification assessment if sought
ISO · ISO/IEC 27001 ↗

US health information rules

HIPAA

US covered entities and business associates, rather than every website discussing health.

How GDPRFix helps

Record an initial applicability assessment and supplier-review references without uploading patient data.

What needs a wider review

No HIPAA compliance audit or business associate agreement is provided by this workspace. Do not store protected health information here.

Preparation checklist
  • Determine covered-entity or business-associate status
  • Map protected health information in approved systems
  • Review supplier agreements and safeguards
  • Obtain a specialist privacy and security assessment
US HHS · Covered entities and business associates ↗

California privacy law

CCPA / CPRA

Businesses meeting applicable California statutory criteria; assess thresholds and exemptions.

How GDPRFix helps

Organise data categories, suppliers, rights cases and evidence references.

What needs a wider review

The scanner does not currently test all California opt-out, sale/sharing or Global Privacy Control requirements. GDPR consent alone does not establish CCPA compliance.

Preparation checklist
  • Assess applicability and exemptions
  • Map collection, disclosure, sale and sharing
  • Review notices and opt-out preference signals
  • Assess consumer-rights handling and applicable deadlines
California Privacy Protection Agency ↗

Payment data security

PCI DSS

Entities that store, process or transmit account data, or could affect the security of the cardholder-data environment.

How GDPRFix helps

Keep payment-provider references, scope notes, responsible owners and review dates.

What needs a wider review

No ASV scan, SAQ validation or QSA assessment is provided. Never store card numbers or security codes in GDPRFix.

Preparation checklist
  • Confirm scope with your payment provider/acquirer
  • Identify applicable validation requirements
  • Review payment-page scripts and relevant security controls
  • Arrange required validation and specialist assessment
PCI Security Standards Council ↗

Custom requirements

Other frameworks

Additional laws, sector rules or contractual requirements you need to assess.

How GDPRFix helps

Create a custom record with the applicable source, scope, owners and evidence references.

What needs a wider review

Coverage is not implied. Confirm requirements and specialist support before relying on a custom assessment.

Preparation checklist
  • Identify the authoritative source
  • Confirm applicability and scope
  • Assign an owner and evidence references
  • Arrange specialist review where needed
EDPB · Small business guidance ↗

Start with what your website does.

Test cookie behaviour, understand the findings, then get a bespoke technical fix plan.

Run a free website scan

Scope information reviewed 1 October 2026. Sources and requirements may change. The framework records are a preparation tool; GDPRFix does not issue SOC 2 reports, ISO certificates, HIPAA certifications or PCI attestations. No regulator endorsement is implied.