Standards / Information security, privacy and AI
GDPR EU data protection
Lawful, transparent processing of personal data of people in the EU.
Core documents AMS builds
- Records of processing
- Lawful basis register
- DPIAs
- Breach response procedure
Drafted from your actual processes and systems, then kept under version control with review dates.
The path to GDPR
Six steps from first conversation to GDPR. AMS and our consultants handle each one with you.
- 1Scope
Define which sites, teams, processes and systems GDPR will cover.
- 2Gap assessment
Compare what you do today with every GDPR requirement and list what is missing.
- 3Documents
Write the policies, procedures and records GDPR expects, starting with the records of processing.
- 4Implement and collect evidence
Put the processes into daily work and capture proof that they run, on a schedule.
- 5Internal review
Check readiness with an internal audit or self-assessment, and close the findings.
- 6Ongoing compliance
There is no single certificate. You keep records current, answer regulators and customers, and review controls as the rules change.
GDPR questions
Planning GDPR? Talk to our team
How long does GDPR implementation take?
Most organizations need about 8–14 weeks, depending on size, number of sites and how much is already in place. A gap assessment gives a firm estimate.
What documents does GDPR require?
Core documents usually include: records of processing, lawful basis register, dpias, breach response procedure. AMS drafts them from your actual processes and keeps them under version control.
Can GDPR be combined with other standards?
Yes. GDPR is often run together with ISO/IEC 20000-1, ISO/IEC 27001, ISO/IEC 27701. AMS maps shared requirements, so one record can count toward several standards.
How does AMS help with GDPR?
AMS runs the full GDPR program: scoping, gap assessment, documents, evidence capture, internal audits, corrective actions and the audit pack for your reviewers.