VITI Security
We do the security engineering, not the audit or the legal work. VITI Security implements and tests the technical security controls these frameworks require - access control, encryption, logging and monitoring, vulnerability management, and penetration testing. The certification or attestation is issued by an independent, accredited auditor or CPA firm that you retain; formal policy authoring, legal review, and Data Protection Officer duties sit with your auditor and privacy counsel, not with us. We have no partnership, referral fee, or kickback with any certifying body - you pick them, and we make the technical controls pass.

Service · GDPR (security side)

GDPR: we cover the security of processing.

GDPR is mostly privacy law - lawful basis, consent, DPAs, data-subject rights, cross-border transfers, and the DPO role. That is work for privacy counsel, not us. What we do is the security half: the Article 32 technical measures that protect personal data, and the technical readiness to detect and report a breach inside the Article 33 window.

What we do (Article 32 + 33, technical)

What technical security does GDPR require?

Article 32 asks for 'appropriate technical measures.' This is that - the engineering, not the legal drafting.

Where personal data lives (technical)

We map the systems, stores, and data flows that hold personal data so it can actually be secured. The legal Record of Processing (RoPA) is built by your privacy lead; we supply the technical picture.

Encryption + access control

Encryption in transit and at rest, MFA, least-privilege access, and key management around personal-data stores.

Logging, monitoring + detection

The monitoring that lets you notice a breach quickly - the difference between a 72-hour notification and finding out from a regulator.

Penetration testing

VAPT and continuous scanning (Vexta) - the 'regular testing of effectiveness' Article 32 explicitly calls for.

Breach-response readiness (technical)

Detection, containment, and evidence-preservation runbook, plus a tabletop so the technical team is not improvising during the 72-hour clock. The legal notification wording and regulator liaison stay with your DPO/counsel.

Resilience + recovery

Backup, restore drills, and availability controls - the 'ability to restore access to personal data' Article 32 requires.

What we own vs. what stays with legal

Art. 32
Technical security measures we implement + test
Art. 33
Breach detection + technical response readiness
Counsel
Consent, DPAs, DPO, transfers - not us

How we scope it

How do we scope the GDPR security work?

Sized to your systems and data after a short scoping call.

01

Map

Where personal data lives across your systems, and where it is exposed. Output: a ranked list of technical gaps.

02

Secure

Encryption, access control, logging/monitoring, and resilience around those data stores.

03

Test

Penetration testing and scanning to confirm the measures are effective - the testing Article 32 requires.

04

Rehearse

A breach tabletop so detection, containment, and evidence handling are practiced before you need them for real.

GDPR FAQ

What exactly do you do vs. not do?
We do the security half: Article 32 technical measures (encryption, access control, monitoring, testing, resilience) and the technical side of breach detection and response. We do not do the legal half: lawful basis, consent and cookie law, Data Processing Agreements, data-subject-rights processes, cross-border transfer mechanisms (SCCs/IDTA/TIA), DPIAs as legal assessments, or the Data Protection Officer role. Those need a privacy lawyer or a qualified DPO - we will happily work alongside yours.
Can you be our DPO or write our consent flows?
No. A DPO and consent/cookie-law design require privacy-law expertise we do not hold and would not pretend to. We build the technical controls and secure the systems those flows run on; the legal design stays with counsel.
Are you GDPR-certified yourselves?
There is no government-issued GDPR certification - the Regulation does not work that way. We are not certified under any voluntary scheme (ISO 27701, BS 10012, etc.) and do not partner with anyone who issues them. We build to good security practice internally; we do not claim more than that.
What does it cost?
The security-of-processing work is scoped per engagement after a short call, based on your systems and data footprint - we quote a fixed price before we start.

Need the security side of GDPR done right?

Let's scope the Article 32 work. Bring your DPO or privacy counsel for the legal side - we handle the engineering.