A GDPR Expert?
There are many out there who claim to be experts in GDPR. They may have a great story to tell but are they indeed, experts? We sent a friend of ours, Marsha Taylor, to carry out some research to find out what a GDPR expert should know and what qualifications they should have. Here is what she found out.

And some of the so-called GDPR experts are in fact, just that. I found many companies of varying shapes and sizes all with differing levels of competence. Some were very good, others, less sadly. So what makes someone or a business a GDPR expert? Qualifications are an obvious measure. Experience is absolutely vital, and training. Where did they train and who trained them?
I will start with training, as this can be good, bad or pointless. This will depend on your situation. I spoke with one consultant and he was trained on GDPR by one of the big banks. He was very proud of this fact and his factual knowledge of the regulation was impressive. However, this training, whilst it may be very good and informative, is completely inappropriate when trying to help a small business owner with their GDPR compliance. Therefore he is a GDPR expert, but not correctly positioned in the market.
We discovered that the documentation was very good. However, most was appropriate to a business with multiple hundreds of employees, not, for example, seven employees. The implementation of polices and procedures had been left to the business owner to organise and the training was poor. This was because it was plagiarised from the bank and was therefore not practical or relevant.
Qualifications
GDPR qualifications are important as they show that an understanding of the regulations and its meaning has been studied. However, be careful. Some certificates are issued for ‘participation’ in a course. Was there a test and was it properly invigilated?
Is the issuing body recognised? For example, The BCS Foundation and Practitioner Certificates are recognised nationally. The testing is on-site invigilated exams.
The CIPP/E is the globally recognised certification for GDPR, the ‘E’ referring to Europe. This is the mark of a true GDPR expert.
Testing understanding
Testing of knowledge is vital. Short and simple multiple choice question sets aren’t really the best way to test understanding of such an important subject. We found a GDPR foundation and practitioner course which claimed to be with a governing body that never responded to us. On investigation, the governing body was nothing of the sort and merely a marketing tool to reassure potential customers.
Certificates
The GDPR expert will claim to have certificates, so make sure you ask to see them! Some may be digital certificates so you can click on them to ensure they are valid. Others may not be but it is worth checking with the issuer. Be wary of participation certificates as this means the GDPR Expert turned up for the course but was never properly tested.
Experience
A GDPR Expert will have helped several or many businesses with their GDPR compliance. Therefore, you should ask how many and in what sector of business. The more the better.
Other Skills
Does the company you are talking to offer other services? Do they have wider experience in ISO27001 for example? This is the ultimate data security standard. Perhaps they offer Cyber Essentials, the government-backed cyber security scheme for small and medium sized businesses. This will help them ensure you are delivering ‘security and privacy by design and by default’ as required by the regulation.
Do they offer PCI DSS? If you take credit cards, you need to certify to this standard. This again demonstrates a wider offering and a deeper understanding of regulation.
A GDPR Expert should offer more than just GDPR.
References
References have some value, but a prospective provider will only give you references where the relationship is good. This will come as no great surprise. Don’t be afraid to ask questions about their experience with the provider. Did everything go smoothly or were there problems. How were the problems addressed and how quickly?