GDPR and Compliance

Compliance Fails for Operational Reasons, Not Legal Ones.

Almost nobody fails an audit because they misread the regulation. They fail because nobody knows where the data lives, no one owns the deletion requests, and the retention policy exists in a document the team has never opened. Those are process problems - which is what we fix.

UK and EU GDPR - India DPDP Act - ISO 27001 and SOC 2 readiness. Operational work, not legal advice.

The Problem

The Policy Exists. Nobody Follows It.

Most growing companies are not non-compliant because they decided not to bother. They bought a policy pack, someone adapted it, it went into a shared drive, and the business carried on operating exactly as it did before. The gap between the documented position and the actual one is where the exposure sits.

Nobody can say with confidence where personal data actually lives across your systems and spreadsheets.

A subject access request arrives and it is handled ad hoc, by whoever is free, usually late.

The retention policy says two years. In practice nothing has ever been deleted.

A customer's security questionnaire is blocking a deal and nobody can answer half of it.

Your processor and vendor list is out of date, and some of it was never written down.

An ISO or SOC readiness effort was started and stalled once it met the day job.

What We Do

What a Compliance Engagement Delivers.

A defensible position that reflects how the business actually operates - and keeps reflecting it after we leave.

Data Mapping

Where personal data enters, where it lives, who touches it, where it goes, and how long it stays. Done properly across systems, spreadsheets and third parties - this is the foundation everything else rests on, and it is the step most often skipped.

Gap Assessment

Article-by-article against UK and EU GDPR, or control-by-control against the India DPDP Act, ISO 27001 or SOC 2. Assessed against how you genuinely operate rather than against the policy document.

Remediation, Not Just Findings

Most compliance consultants hand over a gap analysis and leave. We do the work: rewriting the processes, building the request-handling workflow, fixing retention and access, and making the controls something the team can actually follow.

Policies People Use

Documentation written for how this business runs, tied to the real process, in language the team will follow - rather than a template pack that satisfies an auditor and nobody else.

Readiness Preparation

For ISO 27001 or SOC 2, getting the organisation into a state where the audit is a formality. Control design, evidence routines, and the operational habits that keep them true between audits.

Ongoing Governance

A monthly retainer covering policy upkeep, periodic review, incoming security questionnaires, and subject access requests as they arrive. Compliance decays the moment the project ends unless someone owns it.

Who This Is For

When This Engagement Fits.

A deal is blocked

An enterprise customer sent a security questionnaire or asked for SOC 2, and you cannot answer it. The commercial cost of not fixing this is immediate and quantifiable.

Growing across borders

UK or EU customers and staff, or Indian operations under the DPDP Act. The obligations arrived before anyone had time to work out what they meant.

Policy without practice

You have documentation from a template pack or a previous adviser, and you know the business does not actually operate the way it describes.

A stalled readiness effort

ISO 27001 or SOC 2 was started, hit the day job, and stopped. It needs someone to own it through to done rather than another kickoff.

How It Works

How the Engagement Runs.

The same sequence as every Velox engagement: find out what is actually true, fix the process, then keep it working.

1

Diagnostic Call

A free 45 minutes to establish which regimes genuinely apply to you and what is driving the urgency. If the honest answer is that none of this is pressing yet, we will say so.

2

Data Mapping and Gap Assessment

Where the data actually lives and how far the real operation sits from the required one. Assessed against practice, not against the policy document.

3

Remediation Plan

What to fix, in what order, with the exposure each item carries. Prioritised by risk and by what is blocking the business commercially, not by the order the articles happen to appear in.

4

Implementation

The process work: request handling, retention and deletion, access control, vendor management, and documentation written for how the business runs. This is the part most compliance engagements leave to the client.

5

Governance Handover

Ownership assigned, review cadence set, and either a clean handover to your team or an ongoing retainer if you would rather it stayed with us.

Common Questions

Questions Founders Ask

No, and we are careful about the line. We are not lawyers and we do not give legal opinions. What we do is the operational work compliance actually depends on: finding where personal data lives, fixing the processes that handle it, assigning ownership, and making the controls something the team can follow. Where a genuine legal question arises - lawful basis, contractual terms, a regulator response - that goes to your counsel, and we will tell you when you have reached that point.

Find Out Where You Actually Stand.

45 minutes, no pitch. We will tell you which regimes apply, what is genuinely urgent, and what can wait.