This practical guide looks at companies offering GDPR audit services in London, from larger multidisciplinary organisations to narrower data protection specialists. It is intended as an overview rather than ranking companies against one another. The focus is on who these companies are, the types of organisations they support, and the areas of GDPR, privacy, governance and compliance they cover. Some combine data protection work with broader risk, cyber security or assurance services, while others concentrate closely on privacy and regulatory compliance. The aim is to give readers enough context to compare the options and decide which type of company fits their needs.

Acumon
Acumon is a UK firm of chartered accountants and registered auditors providing GDPR and data protection audit services to companies and organisations in London and across the UK.
The firm works with organisations ranging from growing owner-managed businesses through to larger corporate groups and regulated entities. GDPR audit engagements are designed to assess whether documented privacy arrangements reflect the way personal data is actually collected, used, stored, shared, retained, and protected in day-to-day operations.
Acumon’s GDPR audit work covers both governance documentation and operational controls. Reviews can examine records of processing activities, lawful bases, privacy notices, consent arrangements, individual rights procedures, data retention, information security measures, processor relationships, international transfers, website cookies, and PECR compliance.
The audit methodology is designed to identify gaps between an organisation’s documented framework and observable practice. Findings are assessed according to regulatory and commercial significance, with remediation actions prioritised so that management can focus on the areas presenting the greatest exposure.
GDPR compliance often overlaps with wider governance, cyber security, supplier management, and internal control requirements. Acumon provides data protection audits through its broader Risk & Technology Assurance practice, allowing privacy issues to be considered alongside technology risk and organisational controls where relevant.
This can be particularly relevant for organisations introducing new systems, changing suppliers, expanding marketing activity, handling increasing volumes of personal data, or reviewing privacy arrangements that have not been reassessed since their original GDPR implementation.
GDPR Audit Capabilities
Acumon provides GDPR and data protection audit services across a range of operational and compliance areas.
These include:
- Article 30 Records of Processing Activities
- Lawful Bases for Processing
- Privacy Notices and Transparency Requirements
- Consent and Direct Marketing Controls
- Data Subject Access Request Procedures
- Data Retention and Deletion
- Information Security Measures
- Personal Data Breach Procedures
- Processor and Supplier Arrangements
- International Data Transfers
- Website Cookies and PECR Compliance
Audit findings can be presented with prioritised remediation actions based on the level of regulatory and commercial risk identified during the review.
Regulatory Licences and Registrations
Acumon holds several professional registrations and audit authorisations that support its wider assurance and governance work.
These include:
- UK Statutory Audit Registration
- Public Interest Entity (PIE) Audit Authorisation
- Jersey Recognised Auditor Status
- Isle of Man Recognised Auditor Status
- ICAEW Registration for Audit Work
These registrations relate to Acumon’s broader audit practice rather than GDPR compliance itself, but they reflect the regulated assurance environment in which the firm’s risk and technology services operate.
Core Services
In addition to GDPR and data protection audits, Acumon provides services that support governance, risk management, financial reporting, and technology assurance.
These include:
- GDPR and Data Protection Audits
- Risk and Technology Assurance
- Internal Audit
- Governance Reviews
- Cyber Security Audit Support
- Statutory External Audit
- Group and Subsidiary Audits
- Public Interest Entity Audits
- Risk Management and Compliance Support
GDPR audit work can be particularly relevant for organisations that are:
- Reviewing Existing GDPR Frameworks
- Preparing for Customer or Investor Due Diligence
- Introducing New Systems or Suppliers
- Expanding Data Processing Activities
- Reviewing Data Retention and Individual Rights Procedures
- Strengthening Privacy Governance and Internal Controls
Early review can help identify where policies, records, contracts, and operational practices no longer align with the organisation’s current data processing environment.
Contact Information
- Website: acumon.com
- Phone: 020 8567 3451
- Email: [email protected]
- Address: 1-2 Craven Road, Ealing, London, W5 2UA, UK

Evalian
Evalian provides specialist data protection, privacy and information security services, including dedicated GDPR internal audits. Its London presence makes the company relevant to organisations that want a privacy-focused provider rather than a general accountancy or business advisory practice.
Audits use an evidence-based methodology combining stakeholder interviews, document reviews and analysis of actual data processing activities. Scope can include accountability, lawful bases, privacy information, retention, data subject rights, processors, international transfers, breach reporting, information security, DPIAs and record keeping.
The engagement normally begins with scoping, followed by evidence gathering and a gap analysis. Evalian then provides a report covering assurance levels, compliance gaps and prioritised recommendations. Both one-off and continuing audit arrangements are available, with on-site and remote delivery options.
Key Facts
- Core services: GDPR audits, gap analysis, DPO services, privacy consultancy, PECR reviews
- Audit approach: Interviews, documentary evidence and operational review
- Relevant regulations: UK GDPR, Data Protection Act and PECR
- Delivery: On-site and remote
- Location: London presence with wider UK coverage
Contact Information
- Website: evalian.co.uk
- Phone: 03330 500 111
- Email: [email protected]
- Address: Blackwell House, Guildhall Yard, London, EC2V 5AE
- LinkedIn: www.linkedin.com/company/evalian

Data Privacy Advisory Service
Data Privacy Advisory Service, commonly referred to as DPAS, provides GDPR audits and wider data protection consultancy from locations including London. Its work is focused specifically on privacy rather than treating data protection as a small component of a broader technology service.
The GDPR audit service is designed to identify gaps between an organisation’s current arrangements and its legal obligations. DPAS combines audit work with access to data protection consultants and DPO expertise, allowing findings to feed into subsequent remediation, governance work or ongoing privacy support.
This model can suit organisations that want an audit followed by practical assistance rather than a standalone findings report.
Key Facts
- Core services: GDPR audits, privacy assessments, DPO support, consultancy
- Specialisation: Data protection and privacy compliance
- Suitable for: Organisations seeking both assessment and remediation support
- Coverage: London, Devon and Yorkshire
Contact Information
- Website: www.dataprivacyadvisory.com
- Phone: 0203 3013384
- Email: [email protected]
- LinkedIn: www.linkedin.com/company/data-privacy-advisory-service
- Facebook: www.facebook.com/DataProtectionAdvisoryService
- Instagram: www.instagram.com/dataprivacyadvisoryservice

Xcina Consulting
Xcina Consulting is a London-based risk management and assurance company offering data protection consulting and GDPR audits. Its privacy work is integrated with broader information security, internal audit and regulatory compliance capabilities.
The company uses the ICO Accountability Tracker as part of its methodology and supplements this with additional consideration of PECR. Reviews can assess the overall data protection framework, benchmark controls against regulatory expectations and identify gaps requiring remediation.
Xcina can continue beyond the audit with framework implementation, remediation, privacy training and virtual DPO support. Its published work includes GDPR gap analysis and remediation for an international bank as well as data protection programme reviews.
Key Facts
- Core services: GDPR audits, data protection consulting, remediation, vDPO
- Methodology: ICO Accountability Framework-based assessment
- Additional scope: PECR
- Wider capability: Information security, internal audit and regulatory compliance
- Location: City of London
Contact Information
- Website: xcinaconsulting.com
- Phone: +44 (020) 3745 7820
- Email: [email protected]
- Address: 32 Threadneedle Street, London, EC2R 8AY
- LinkedIn: www.linkedin.com/company/xcinaconsulting
- Twitter: x.com/xcinaconsulting

activeMind.legal UK
activeMind.legal UK is a London-based law firm focused on data protection and related information security matters. Its service portfolio includes UK GDPR audits alongside DPO services, ongoing data protection support and UK representative services.
The company’s combination of legal, technical and organisational privacy expertise makes its audits relevant where compliance questions involve both legal interpretation and operational controls. GDPR audit work can therefore sit alongside support with records of processing, international data obligations and wider privacy governance.
Unlike broader cyber consultancies, privacy and data protection law form the central focus of the practice.
Key Facts
- Core services: UK GDPR audits, DPO services, privacy support
- Specialisation: Data protection law
- Additional services: UK representative services and ROPA support
- Regulation: Solicitors Regulation Authority
- Location: London
Contact Information
- Website: www.activemind.uk
- Phone: +44 20 89383608
- Address: Flat 73 Waterside Apartments, Goodchild Road, London N4 2AJ, United Kingdom

Infinity Group
Infinity Group provides GDPR consultancy to businesses in London and elsewhere in the UK. Its service incorporates both a GDPR audit and gap analysis, with a particular emphasis on IT and cyber security arrangements.
Consultants assess the organisation’s current technology and security environment and produce an analysis of its existing GDPR position. The resulting report identifies areas requiring attention, recommendations and actions linked to relevant GDPR requirements.
Because the audit has a strong technology component, Infinity Group is more closely aligned with businesses concerned about the relationship between GDPR compliance, IT infrastructure and cyber security than organisations seeking a primarily legal privacy review.
Key Facts
- Core services: GDPR audit, gap analysis and consultancy
- Focus: IT and cyber security aspects of GDPR
- Output: Compliance overview and recommendations
- Coverage: London and wider UK
- Location: Paddington, London
Contact Information
- Website: www.infinitygroup.co.uk
- Phone: 0330 191 3798
- Email: [email protected]
- Address: 6th Floor, 2 Kingdom Street, London, W2 6BD
- LinkedIn: www.linkedin.com/company/infinity-technology-solutions-limited
- Facebook: www.facebook.com/infinityts
- Twitter: x.com/infinitygrouptw

DataGuard
DataGuard combines privacy consultancy with compliance software used to organise and monitor ongoing data protection activities. Its UK service includes GDPR reviews, gap analysis and implementation support.
Consultants assess the existing compliance framework and examine whether policies and procedures are being followed in practice. A gap analysis can then identify weaknesses in governance, processes and technology, with implementation support available once priorities have been established.
The combination of advisory support and a compliance platform differs from a traditional one-off audit model. It can be relevant to businesses wanting to maintain records, controls and improvement activities after the initial review rather than manage remediation solely through documents and spreadsheets.
Key Facts
- Core services: UK GDPR reviews, gap analysis, implementation support
- Additional service: Outsourced DPO
- Delivery model: Consultancy combined with compliance software
- Industries: Includes software, healthcare, finance, retail and higher education
- London presence: UK operations include London
Contact Information
- Website: www.dataguard.com
- Address: Suite 1, 7th Floor, 50 Broadway, London SW1H
- LinkedIn: www.linkedin.com/company/dataguard1
- Twitter: x.com/DataGuard_dg

Boardroom Matters
Boardroom Matters provides UK GDPR audits and operates from a London address in Covent Garden. Its audits are available to private, public and voluntary sector organisations and can be conducted on-site or remotely.
The assessment combines preparation and documentation review with examination of data flows and existing compliance arrangements. The resulting report can include an executive summary, DPIA findings and a practical action plan. Follow-up work is available to review whether recommended improvements have been implemented.
The service is relatively focused, making it suitable for organisations primarily looking for an independent GDPR compliance assessment rather than a wider enterprise risk engagement.
Key Facts
- Core services: UK GDPR audits and compliance reviews
- Audit areas: Documentation, data flows and DPIAs
- Delivery: Remote or on-site
- Follow-up: Remediation support and subsequent review
- Location: London
Contact Information
- Website: boardroommatters.co.uk
- Phone: +44 (0)203 733 6443
- Email: [email protected]
- Address: 71-75 Shelton Street, London WC2H 9JQ

RSM UK
RSM UK provides technology risk assurance, privacy and data protection services within a broader risk and governance practice. The company’s London teams work on assignments covering data protection, information governance, cyber security, internal controls and technology risk.
Its technology and data risk offering includes data protection and privacy services intended to help businesses assess alignment with regulatory obligations. RSM professionals have experience delivering GDPR audits alongside reviews of cyber security, IT governance, infrastructure, business continuity and IT controls.
RSM is therefore more relevant where a GDPR assessment needs to be considered as one component of a larger technology assurance or internal audit programme.
Key Facts
- Core services: Data protection, privacy and technology risk assurance
- Related assurance: Cyber security, IT controls and governance
- Delivery context: Internal audit and technology assurance
- Suitable for: Organisations with wider risk and compliance requirements
- Location: London and multiple UK offices
Contact Information
- Website: www.rsmuk.com
- Phone: +44 (0)20 3201 8000
- Address: 25 Farringdon Street, London, EC4A 4AB
- LinkedIn: www.linkedin.com/company/rsm-uk
- Instagram: www.instagram.com/rsm.uk

EY
EY provides privacy consulting through its UK cybersecurity and consulting practices. Its offering includes privacy assessments, transformation work and GDPR compliance services, supported by specialists in data protection, cyber security, digital identity and regulatory risk.
The breadth of the practice makes EY more applicable to complex organisations where a GDPR review forms part of a wider privacy transformation, cyber security programme or multinational compliance environment. Its London-based teams can combine legal, consulting and technology expertise when examining how personal information is governed across systems and business functions.
This is a broader privacy assurance model than the narrowly defined checklist-style GDPR audits offered by smaller specialist consultancies.
Key Facts
- Core services: Privacy assessment, GDPR compliance and privacy transformation
- Related capability: Cyber security and data protection
- Approach: Multidisciplinary consulting
- Suitable for: Larger and complex organisations
- Location: London
Contact Information
- Website: www.ey.com
- Phone: +44 20 7951 2000
- Address: 1 More London Place, London SE1 2AF
- LinkedIn: www.linkedin.com/company/ernstandyoung
- Facebook: www.facebook.com/EY
- Twitter: x.com/EYnews

ITGRC Advisory
ITGRC Advisory is a London-based governance, risk and compliance consultancy providing specialist technology and information security audits.
Its audit practice explicitly includes personal data protection assessments covering GDPR and comparable privacy requirements alongside IT, cyber security, SOC and business continuity audits. The company also provides GDPR consulting within its wider compliance services.
This combination is relevant to organisations where data protection needs to be assessed alongside technical security controls, information management systems or formal assurance frameworks.
Key Facts
- Core services: GDPR audits, IT audit and cyber security audit
- Related frameworks: SOC, information security and business continuity
- Additional capability: GDPR compliance consulting
- Specialisation: Technology governance, risk and compliance
- Location: London
Contact Information
- Website: www.thesoc2.com
- Phone: +48 604 559 818
- Email: [email protected]
- Address: 590 Kingston Road, London, United Kingdom, SW20 8DN

WorkNest
WorkNest provides data protection and cyber security services that include GDPR gap analysis, implementation, consultancy and recurring GDPR audits.
Its audit service is intended for organisations that already have a GDPR framework and want to confirm whether it continues to operate as expected. Reviews can examine whether employees are following established policies and procedures and whether the organisation continues to maintain its compliance framework.
The company’s wider technical security offering includes penetration testing, ISO 27001 support, managed security and cyber security assessments. This gives WorkNest a stronger technical security orientation than privacy consultancies whose work is primarily legal or governance based.
Key Facts
- Core services: GDPR audits, gap analysis and implementation
- Additional privacy services: Data protection consultancy and outsourced DPO
- Wider capability: Cyber security and penetration testing
- Audit use case: Periodic reassessment of an established GDPR framework
- Coverage: UK organisations
Contact Information
- Website: worknest.com
- Phone: 0345 226 8393
- Email: [email protected]
- Address: Woodhouse, Church Lane, Aldford Chester CH3 6JD
- LinkedIn: www.linkedin.com/company/worknest-group
- Facebook: www.facebook.com/WorkNestGroup
Conclusion
Choosing between GDPR audit companies in London depends on business size, sector, the maturity of existing privacy processes and the level of regulatory scrutiny involved. Some companies combine GDPR work with wider cyber security, governance and assurance services, while others focus more narrowly on data protection and privacy compliance. The right choice also depends on whether the organisation needs a focused compliance review or a broader assessment of controls and risk. This guide is intended to provide neutral context for comparing those different approaches and identifying a suitable partner. A strong match should provide independent assurance, clarify areas of risk and set out practical actions that strengthen compliance and support longer-term resilience.