Managing GDPR compliance across a complex stakeholder landscape

Introduction

Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.

Client

Mega

Client since

Technologies

No items found.

The problem

Mega had no structured way to assess whether its international data transfers met GDPR requirements. Personal data crossed borders routinely, through external suppliers and intra-group partners, but there was no consistent process to identify which transfers were happening, what safeguards were in place, or how much risk each relationship carried. Without that, the organisation could neither demonstrate compliance nor catch problems before they became contractual commitments. As the organisation matured its compliance posture and launched an ISO 27001 initiative, the absence of a repeatable process for assessing third-party data transfers became untenable.

DTA walked into a gap that is common but rarely acknowledged: a company doing cross-border business without a repeatable way to assess whether that business is GDPR-compliant.

How we solved it

Mapped every non-EEA relationship from scratch

DTA worked with Sales, Marketing, and Operations to identify every external supplier and internal holding or sister organisation transferring personal data outside the EEA. For each, DTA assessed the local data protection framework against the nature of the data and data subjects involved. Every gap was listed and translated into an execution plan, shared with a cross-functional working group spanning IT, Legal, Sales, Marketing, Operations, CISO, and the DPO.

Built on what already existed

Rather than introduce a separate compliance workflow, DTA integrated GDPR due diligence directly into the procurement process Mega was already building as part of its ISO 27001 initiative. Information security and data protection requirements were aligned from the start — one process, not two.

Designed a standardised operating model for all partners

DTA defined a clear onboarding sequence for new partners: data protection assessment first, then IT and DPO review, then, where needed, a Transfer Impact Assessment, and only then contract execution by Legal. For existing non-EEA partners, DTA ran the same assessment retrospectively, capturing responses alongside their DPA and applicable SCCs. DTA then adapted the external process for internal transfers, setting one consistent compliance standard across suppliers and holding/sister organisations alike.

The results

The fix had to fit the organization, not sit alongside it.

A single, repeatable due diligence process now covers every partner

IT and DPO sign-off is required before any contract is signed, for new partners and existing ones. Ad hoc assessments are gone.

International transfer risk is addressed before contracts are signed

Non-EEA partners are assessed upfront. Where needed, a Transfer Impact Assessment and SCCs are in place before any legal commitment is made.

GDPR compliance embedded into ISO 27001 procurement; not added on top of it

One process, one standard, applied consistently to external vendors and internal holding and sister organisations. Compliance stops at nobody's walls.

Key Learnings

Our lessons learned for compliance in a complex environment.

Embedding

Data protection due diligence into an existing operational process, here, ISO 27001-aligned procurement, delivers more durable compliance than running GDPR as a separate workflow.

Cross-functional

Involvement (IT, Legal, Sales, Operations, CISO, DPO working from one gap list) is the only way to accurately map non-EEA data flows. Piecemeal mapping leaves blind spots.

Same standard

For internal transfers (holding and sister organisations) as external vendors is not optional if you want genuine, organisation-wide compliance. Not just compliance that stops at the company's own walls.

Degroof Petercam

From fragmented controls to scalable regulatory data quality

Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.

LM Oost-Vlaanderen

From regulatory scrutiny to demonstrated compliance

LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.

Transport Infrastructure Organization

From manual RoPA management to continuous compliance

Our client is a public railway infrastructure manager, responsible for building, maintaining, and operating the country's rail network. As a public-sector organisation handling a broad range of personal data across multiple domains and subdomains, maintaining a compliant and well-governed Register of Processing Activities (RoPA) is both a legal obligation and an operational challenge.