← All postsHow-to

GDPR gap analysis: finding what is missing before someone else does

A gap analysis compares what the regulation requires against what you actually do. Its value depends entirely on evidence being tested, not asserted.

How-toG

A GDPR gap analysis is a structured comparison between what the regulation requires and what the organisation actually does, ending in a list of gaps with owners, priorities and dates. It is the sensible first exercise for a company that has never assessed itself, and the recurring one for a company that wants its programme to stay true.

Whether it produces anything useful depends on one methodological choice: whether each answer is evidenced or asserted. An analysis built from a questionnaire filled in by the people responsible reliably reports a healthier position than the same organisation would show under examination.

What a GDPR gap analysis examines

  • Records of processing: exist, complete, current.
  • Lawful bases: documented per purpose, and defensible for the purpose claimed.
  • Transparency: privacy notice content, and whether it matches reality.
  • Rights: a process that meets the deadlines, tested rather than described.
  • Processors: agreements in place, diligence performed, transfers covered.
  • Security: measures appropriate to the risk, including access control and encryption where warranted.
  • Retention: schedule defined and actually enforced.
  • Breach: detection, decision-making and the 72-hour route.
  • Governance: responsibility assigned, training delivered, DPIAs done where required.

Evidence, not answers

For every row, ask what would prove it. "We handle access requests within a month" is an assertion; the log of the last four requests with dates received and dates answered is evidence. "Retention is applied" is an assertion; a query showing the oldest record in a category is evidence.

Where evidence does not exist, the honest finding is not that the control is absent but that it cannot be demonstrated — and under an accountability-based regulation those amount to nearly the same thing.

Score gaps by regulatory exposure and by how visible they would be in an incident, not by how hard they are to fix. A missing processing record is more serious than an unpolished policy, even though the policy is quicker to produce — and a programme that starts with the quick items usually stalls before reaching the hard ones.

Turning the analysis into a plan

  1. Record each gap as a finding with the requirement it relates to and the evidence you looked for.
  2. Assign an owner who can actually make the change, not the person who reported it.
  3. Set a date, and a smaller first step where the full fix is months away.
  4. Separate remediation from business-as-usual: a control that now exists still has to keep operating.
  5. Re-test the closed items rather than closing them on the owner’s word.
  6. Repeat the analysis annually, and after any significant change of product, supplier or jurisdiction.

A gap analysis is a working table with a long tail: many rows, several assessors, and a comparison against last year that only means something if both versions survive. Ettex Sheets keeps the assessment with its history and links each row to the evidence examined, so the movement between cycles is visible and a closed finding can be shown to have been re-tested. The findings then feed the same GDPR compliance work the analysis was meant to direct.

Frequently asked

How long does a GDPR gap analysis take?

For a small company, one to three weeks including interviews and evidence review. The bottleneck is usually getting hold of processor agreements and system access lists rather than the analysis itself.

Who should run it?

Someone independent of the processes being examined — an internal privacy or risk function, or an external adviser. A self-assessment by the team that operates the controls is a starting point, not an assessment.

What is the difference between a gap analysis and a DPIA?

A gap analysis assesses the organisation against the regulation as a whole. A DPIA assesses one specific processing activity that is likely to be high risk, before it starts.

Do we need one if we already did an audit?

If the audit tested evidence and covered the same ground, no. If it was a questionnaire, the gap analysis is the version that tests what the questionnaire asserted.

AS
Written by Alex S.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.