TOM gap analysis
Current-state assessment of all technical measures against Art. 32 GDPR and ISO 27001 controls simultaneously.
GDPR Compliance
Art. 32 GDPR demands more than ticking boxes. We implement TOMs that genuinely protect - and test their effectiveness with penetration testing and gap analysis. From a single source, on a fixed-price basis.
ISO 27001 certified · Fixed-price commitment · GDPR expertise since 2018
Art. 32 GDPR - Four Pillars
Pseudonymisation & Encryption
Render personal data technically unreadable
Confidentiality & Integrity
Ongoing assurance through technical measures
Availability & Resilience
Backup strategy, business continuity, restorability
Regular Testing
Effectiveness testing of measures - penetration test
Trusted by our clients
Our Services
We combine data protection expertise with offensive security know-how - unique in this form. Our services cover all technical requirements of the GDPR.
01
Systematic review of all existing technical and organisational measures against Art. 32 GDPR requirements. Implementation of missing controls: encryption, pseudonymisation, access management, backup, incident response.
Art. 32 GDPR
02
Systematic assessment of high-risk processing operations per Art. 35 GDPR: description of processing, necessity and proportionality assessment, risk assessment, and concrete mitigating measures. Mandatory for video surveillance, profiling, and special category data.
Art. 35 GDPR
03
External DPO as a managed service per Art. 37 GDPR - immediately available, independently advising, and with contractual liability. Expert contact for supervisory authorities and data subjects. Available from EUR 800/month.
Art. 37-39 GDPR
04
Regular penetration test as evidence of TOM effectiveness - directly satisfying Art. 32(1)(d) GDPR. We test whether personal data is genuinely protected against unauthorised access: web applications, databases, access controls, network segmentation.
Art. 32(1)(d) GDPR
Synergies
ISO 27001 and GDPR complement each other ideally. A certified ISMS per ISO 27001 covers large parts of the GDPR's technical and organisational requirements - and provides documented evidence for supervisory authorities.
Art. 32 - TOMs
ISO 27001 Annex A (93 controls)
Art. 32(1)(a) - Encryption
ISO 27001 A.8.24
Art. 33 - 72h breach notification
ISO 27001 A.6.8 (Incident Reporting)
Art. 17 - Right to erasure
ISO 27001 A.8.10 (Data deletion)
Art. 5(1)(f) - Integrity & confidentiality
ISO 27001 core objective
TOM gap analysis
Current-state assessment of all technical measures against Art. 32 GDPR and ISO 27001 controls simultaneously.
ISMS build-out
Build or extend the ISMS per ISO 27001 - as the documented foundation for GDPR TOMs.
DPIA for high-risk operations
Systematic assessment of all processing operations requiring a DPIA per Art. 35 GDPR.
Penetration test
Annual test of TOM effectiveness per Art. 32(1)(d) - the most important evidence for data protection authorities.
External DPO
On request: take on all DPO functions per Art. 37-39 GDPR as a managed service.
Why AWARE7 for GDPR compliance
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Your GDPR experts
Our certified consultants combine data protection expertise with offensive security knowledge - unique in this form.
References
These case studies are available in German.
Frequently Asked
Answers to the most common questions about our GDPR consulting offering, costs, and our approach.
Aus dem Blog
Der Informationssicherheitsbeauftragte ist der Ansprechpartner für Informationssicherheit im Unternehmen. Diese Aufgaben hat er!
DSGVO-Compliance: Rechtsgrundlagen, Bußgeldrahmen, AVV, Datenpanne-Meldepflicht, DSFA und Verarbeitungsverzeichnis - mit Praxisbeispielen.
DSFA nach Art. 35 DSGVO: Wann Pflicht, Schritt-für-Schritt-Anleitung, Blacklist der Aufsichtsbehörden und typische Fehler in der Praxis.
We implement TOMs that genuinely protect and provide a fixed-price quote within 24 hours. No open consultant days, no surprises.
Free · 30 minutes · No obligation
Arturs Nikitins
Initial consultation & needs analysis
Looking for personal advice?
No obligation · Reply within 24h on business days