New Report: The State of AI Governance 2026

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Privacy Assessments

GDPR Assessments

Technological advancement, and the massive, global exchange of personal data borne of it, must have its counterbalances. The General Data Protection Regulation (GDPR) is the manifestation of this notion.

Contact a Specialist Build Your Compliance Roadmap

What is the GDPR?

The General Data Protection Regulation (“GDPR”) is the European Union’s comprehensive data privacy law effective as of May 25, 2018.  The regulation establishes rules on how organizations collect, use, and protect personal data of individuals in the European Union, and grants those individuals rights over their data, including the right to delete their data and the right to access their data. 

gdpr-schellman

Why GDPR?

Many companies exploring this new privacy doctrine, in the Unites States and elsewhere, are asking “does the GDPR even apply to me?” and “how can the GDPR have province over our business if we’re not even located in the European Union?” The GDPR applies to any organization that is offering goods or services (irrespective of payment) to residents of the European Union or who is monitoring residents of the European Union. Monitoring in the GDPR framework is referred to as “profiling” and is defined as the automated analysis or predicting of behavior, location, movements, reliability, interests, personal preferences, health, economic situation, performance, etc. It does not matter whether an organization operates physically within Europe (a concept referred to as “extraterritoriality”).

gdpr-schellman
schellman-gdpr-assessment-3

Applicability of the GDPR

Many companies based outside of the European Union are asking “does the GDPR apply to our operations?” and “how can the GDPR have province over our business if we’re not even located in the European Union?”  The GDPR applies to any organization that is offering goods or services (irrespective of payment) to residents of the European Union or that is monitoring residents of the European Union.  Monitoring is referred to as “profiling” under the GDPR and is defined as the automated analysis or predicting of behavior, location, movements, reliability, interests, personal preferences, health, economic situation, performance, etc.  It does not matter whether an organization operates physically within Europe (a concept referred to as “extraterritoriality”). 

schellman-gdpr-assessment-3
schellman-gdpr-assessment-1

Why Perform a GDPR Assessment?

A GDPR assessment is not required by law, however, it may be useful for companies to identify gaps in compliance with the regulation and avoid the risk of severe financial penalties.  Assessments against the GDPR also demonstrate a commitment to privacy that ultimately builds trust and enhances reputation.  Recurring assessments can be conducted as a company’s technology evolves, business ventures solidify, or data usage changes.   

schellman-gdpr-assessment-1

GDPR Assessment Process

Schellman performs each assessment with your end goals and preparation for future key compliance initiatives in mind.  Effective communication and timely coordination of project activities are central to our methodology. 

1. Planning

2. Fieldwork

3. Reporting

GDPR Specialist

Chris Lippert

Chris is a Director and Privacy Technical Lead at Schellman based out of Atlanta, GA. With more than five years of experience in information assurance, Chris has a concentration in privacy-related engagements.

Meet Chris Contact Us

  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

How much will your audit cost?

Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.

The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.

Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing:

  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

Talk to a Practice Leader