About gdprIQ
Our Mission
gdprIQ was founded with a simple yet powerful mission: to help business owners, data protection officers, and compliance and IT managers everywhere make smarter decisions, through approachable guidance that makes consent management, cross-border data transfers, breach response, retention policies, and data subject access requests clearer, more rigorous, and more practical.
We believe that everyone who handles personal data or is responsible for compliance, from a small-business owner writing their first privacy notice to a seasoned DPO running a multinational programme, deserves access to accurate resources, plain-language explainers, and trustworthy guidance. Our platform bridges the gap between dense regulatory text and confident, well-informed decisions about GDPR implementation, consent and lawful bases, international transfers, breach notification, data retention, DSARs, staff training, and avoiding fines.
Alongside our guides, we offer a free collection of handy everyday calculators — an age calculator, GPA calculator, percentage calculator, unit converter, date calculator, countdown timer, tip calculator, and random number generator. These are general-purpose utilities for the everyday arithmetic of working life, not compliance tools, and each is designed with real-world usability in mind and continuously improved based on user feedback. To go deeper, explore our Museum of Privacy & Secrets, with wings on ciphers and secrets, watchers and surveillance, the law and rights, and data and the machine — the machines, laws, people, and ideas behind the modern idea of privacy.
Our Story
gdprIQ emerged from a need we experienced firsthand. While trying to sort through conflicting interpretations and scattered references, we noticed a common challenge: the lack of accessible, accurate, plain-language resources for the everyday decisions that come with handling personal data, building a compliance programme, and keeping up with evolving regulatory guidance.
Sound compliance relies heavily on good judgment and a careful reading of the rules, which are invaluable. However, a confident practitioner also benefits from clear answers about what a lawful basis actually requires, how consent should be collected and recorded, when a breach must be notified, how long records may be retained, and what a data subject access request obliges you to do. We saw an opportunity to combine well-researched privacy knowledge with clear, structured explainers to help people make confident decisions about every processing activity.
Our team began writing the guides we wished existed when we first worked through an implementation project. Each explainer was created to answer real questions encountered when mapping data flows, drafting notices and policies, or responding to a request or an incident. We checked every guide against the regulation itself and published supervisory-authority guidance, refined the wording based on feedback, and ensured that the content reflects current, widely accepted data-protection practice.
Today, gdprIQ serves readers worldwide, from first-time privacy leads to experienced compliance professionals. Our guides have helped people untangle consent requirements, plan cross-border transfers, prepare breach-response playbooks, set retention schedules, handle DSARs, and make more deliberate, confident compliance decisions.
Our Core Values
- Accuracy First: Every guide is grounded in the text of the regulation and published regulatory guidance and reviewed for reliability. We prioritize precision to ensure trustworthy content.
- Accessibility: Practical privacy education should be available to every organization that handles personal data, regardless of size or budget. All our guides and tools remain free and accessible worldwide.
- Evidence-Based: Our content draws on the regulation, supervisory-authority guidance, and widely accepted compliance practice. We refine our content based on trusted references and expert input.
- Community-Driven: User feedback drives our development. We listen to our community of business owners, DPOs, and compliance and IT managers and continuously improve our content based on real-world questions and suggestions.
- Privacy Focused:We practice what we cover. We don’t require accounts, our calculators run entirely in your browser, and we never sell data. Use our tools with complete privacy confidence.
- Modern & Mobile: Guides and tools work perfectly on any device, from a phone between meetings to a tablet in a workshop or a laptop at your desk. A responsive layout ensures optimal usability everywhere.
Our Expertise
gdprIQ’s guides are developed and maintained by a team with extensive experience in data protection and compliance across multiple areas:
- GDPR Implementation: Experience with data mapping, records of processing, privacy notices, and building a compliance programme from the ground up.
- Consent & Lawful Bases: Specialized knowledge of consent management, legitimate interests assessments, and choosing and documenting the right lawful basis for each processing activity.
- Cross-Border Transfers: Expert understanding of adequacy decisions, standard contractual clauses, transfer impact assessments, and the practicalities of moving data internationally.
- Breach Response & Retention: Comprehensive experience with incident-response planning, notification timelines, and building retention schedules that stand up to scrutiny.
- DSARs & Training: Practical knowledge of handling data subject requests end to end and building staff awareness and training programmes that actually stick.
- Research Collaboration: Ongoing reliance on the regulation itself, supervisory-authority guidance, and reputable professional resources.
Our team includes experienced practitioners, writers, and reviewers who bring years of combined experience to content development. We regularly consult regulatory guidance and trusted experts to ensure our content reflects current best practices. Our content is general informational and educational content, NOT legal advice; GDPR interpretation varies by case and jurisdiction, and regulations and regulatory guidance change over time — always consult a qualified data-protection lawyer or your supervisory authority before making compliance decisions.
Looking Forward
The future of data protection lies in the intelligent combination of sound legal understanding with practical processes and clear knowledge. At gdprIQ, we’re committed to staying at the forefront of this evolution.
Our development roadmap includes expanded guides on consent tooling, transfer mechanisms, vendor management, and breach-response drills. We’re also working on multilingual support to serve the global compliance community better, and developing specialized guidance for different sectors, company sizes, and stages of compliance maturity.
Most importantly, we remain committed to keeping our guides and tools free and accessible. As we grow, we’ll continue to prioritize user needs, ensuring that everyone has access to practical privacy education regardless of their budget.
Connect With Us
Have questions, suggestions, or feedback about our guides or tools? We’d love to hear from you. Our community of business owners, DPOs, and compliance and IT managers drives everything we do. Get in touch.