GDPR
- Company typePrivate
- Founded2009
- HeadquartersSandyford, Ireland
- Headcount11–50
- GTM typeB2B
- OfferingServices
What GDPR does
GDPR.ie operates as the trading brand of the Data Protection Group, a private Irish data protection consultancy that is part of Blackfoot UK Ltd., an English private limited company (Company Number 06778791). The firm delivers GDPR compliance services, data protection officer outsourcing, penetration testing, vulnerability management, social engineering simulations, and AI-powered human risk management to SMEs, enterprises, government departments, semi-state bodies, and professional associations across Ireland and Europe. Its service portfolio combines consultancy, managed services, and certified training delivered via IAPP and PECB partnerships.
The technology stack centres on three proprietary platforms: the Sentry Portal (penetration testing engagement management), the Vulnerability Manager (centralised technical assurance reporting with API integration), and an AI-powered Human Risk Management platform that uses adaptive training, predictive behavioural analytics, and phishing simulations, with integrations into Microsoft 365 and Microsoft Defender. Security testing is delivered by CREST-certified professionals and the firm holds PCI SSC Approved Scanning Vendor status for PCI DSS compliance scanning.
Revenue is generated primarily through professional services and managed services streams: project-based GDPR audits, remediation, and policy drafting; retainer-based External DPO and External Data Protection Manager services; one-off or ongoing penetration testing and vulnerability scanning engagements; and certified training course fees covering IAPP (CIPP/E, CIPM, CIPT) and PECB (CDPO, ISO 27701, ISO 42001) programmes. Pricing is quote-based and not publicly disclosed; the company distributes through direct consultancy engagement, partner-delivered training programmes, and content marketing including blog, webinars, and podcast channels.
GDPR firmographics
Firmographics- Name
- GDPR
- Legal name
- Blackfoot UK Ltd.
- Website
- https://gdpr.ie
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
GDPR industry classification
Industry- Product category
- Data Protection and Cybersecurity Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Data Security & Privacy Services (DLP, Encryption, Privacy Ops) (BPAKAHAM)
- akta.pro secondary industry
- Data Security & Privacy Managed Services (DLP/Encryption) (BPAEADAL)
Keywords
Where GDPR is headquartered
LocationHeadquarters
- HQ city
- Sandyford
- HQ country
- Ireland
- HQ region
- Europe
Offices1 record
Markets served
GDPR business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Professional Services (Consultancy): GDPR.ie provides expert data protection and privacy consultancy services including GDPR compliance audits, remediation, policy drafting, and ongoing DPO services. Revenue is generated through project-based engagements and retainer arrangements for data protection officer services.
- Training and Certification Courses: The company delivers IAPP and PECB certified training courses for data privacy professionals, including CIPP/E, CIPM, CIPT, CDPO, ISO 27701, and ISO 42001 programmes. Revenue is generated through course fees which include training delivery, materials, exam fees, and certification.
- Security Testing Services: Penetration testing, vulnerability assessments, social engineering simulations, and ASV scanning services delivered by CREST-certified professionals. Services are offered as one-off engagements or ongoing programmes through the Sentry portal.
- External Data Protection Manager (eDPM): On-demand data protection management support providing expert guidance on day-to-day data protection operations, data subject requests, and breach management on a flexible retainer basis.
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
GDPR product offering
Product offeringCore offering
GDPR.ie provides data protection and cybersecurity consultancy services to organisations in Ireland and Europe, including GDPR compliance audits, remediation, policy drafting, external Data Protection Officer (eDPO) and External Data Protection Manager (eDPM) services, CREST-accredited penetration testing, vulnerability assessments, social engineering simulations, and IAPP- and PECB-certified training courses (CIPP/E, CIPM, CIPT, CDPO, ISO 27701, ISO 42001). Service delivery is supported by proprietary platforms including the Sentry Portal, Vulnerability Manager, and an AI-powered Human Risk Management platform.
Product overview
GDPR.ie, part of the Data Protection Group (Blackfoot UK Ltd), offers a comprehensive portfolio of data protection, privacy compliance, and cybersecurity services. The core offerings include Human Risk Management (an AI-powered platform for security awareness), Penetration Testing Services (covering web apps, infrastructure, cloud, APIs, and mobile), and Social Engineering Testing (phishing, vishing, smishing simulations). Their Data Protection services include External DPO (eDPO), GDPR Consultancy, Compliance Checks, and Auditing. The platform integrates with Vulnerability Manager for centralized reporting. Training offerings include IAPP (CIPP/E, CIPM, CIPT) and PECB (CDPO, ISO 27701, ISO 42001) certification courses. Additional services include Managed Vulnerability Scanning, Cyber Risk Scorecards, ASV Scanning for PCI DSS, and Firewall Assessment. The company delivers via online portal, live training, and on-site engagements throughout Ireland and Europe.
Differentiator
Problem solved
Functional benefit
Brands
- Privacy Impact Shop: A podcast focused on data protection and privacy topics, hosted by industry experts Shaab Al-Baghdadi and Ben Stevens, brought to you by Blackfootuk.com and GDPR.ie
Products and services
- GDPR Consultancy and Compliance Comprehensive GDPR compliance consulting including processing activity reviews, privacy policy development, consent management, and subject rights handling for organisations needing to meet regulatory obligations.
- External Data Protection Officer (eDPO)
Quantifiable outcome
- Human Risk Management platform can reduce human-initiated security incidents by up to 78%
- +1 more outcomes
Companies that use GDPR
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles4 records
GDPR technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability6 records
Feature3 records
GDPR partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and flagship.
- PECBcoreGDPR.ie partnered with PECB, a leading certification body providing education, certification, and certificate programmes for professionals across various disciplines. This partnership allows GDPR.ie to offer a range of PECB-certified training courses that lead to valuable certifications, supporting professional growth and expanding the company's product offerings.
- Blackfoot CybersecurityflagshipGDPR.ie became part of Blackfoot Cybersecurity in 2024. Blackfoot, formed in 2008, is an industry-leading Information Security and Data Protection company. Under this ownership, GDPR.ie leverages Blackfoot's resources and expertise to strengthen its capabilities and better serve clients.
- IAPP (International Association of Privacy Professionals)coreGDPR.ie is an IAPP Certified Training Partner, delivering live online IAPP privacy training courses including CIPP/E, CIPM, and CIPT. The courses are presented by Shaab Al-Baghdadi (CIPPE, CIPM, CIPT, CDPO, CLPI) and provide internationally recognised training and certification for data privacy professionals. GDPR.ie is an OnlineDPO Partner for IAPP.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
GDPR competitors and assessment
Company assessmentDirect peers
- BH Consulting: Irish cybersecurity and data protection consultancy offering GDPR advisory, pen testing, and DPO services to SMEs and enterprises—a near-identical service portfolio to GDPR.ie and the closest direct peer in the Irish market.
- Bishop Fox: US-based offensive security consultancy delivering pen testing, red teaming, and vulnerability research—directly comparable service portfolio targeting similar enterprise and technology-buyer segments.
- Integrity360: Ireland-headquartered cybersecurity services firm providing managed security, pen testing, and compliance services across Ireland and the UK—operates in the same regional competitive set with overlapping enterprise and public-sector clients.
- Tevora: US-based security consultancy offering pen testing, compliance, and risk advisory services with a similar mid-market to enterprise focus—directly comparable business model and service mix.
- IOActive: Global security consultancy specialising in penetration testing, vulnerability assessments, and security research—directly comparable core offering to GDPR.ie's CREST-certified security testing services.
Broad incumbents
- NCC Group: UK-listed cybersecurity and risk mitigation consultancy with global pen testing, compliance, and DPO-adjacent services—comparable capability set but operates at significantly larger scale and broader geographic footprint.
- Trustwave: Global MSSP and cybersecurity consultancy offering pen testing, vulnerability management, and data protection services—comparable service breadth but operating at much larger scale with managed security operations focus.
- Mandiant (Google Cloud): Now part of Google Cloud, Mandiant provides incident response, pen testing, and threat intelligence services with privacy/compliance adjacency—comparable security testing capabilities but at vastly larger scale and global reach.
- Optiv Security: US-based cybersecurity solutions integrator and consultancy offering pen testing, vulnerability management, and compliance services—operates across the same enterprise buyer set but with much broader portfolio and larger delivery footprint.
Emerging players
- Arctic Wolf: Cybersecurity operations vendor offering MDR, vulnerability management, and risk advisory through a partner-led model—overlaps with GDPR.ie's managed security testing and vulnerability services but with a different go-to-market.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
GDPR social profiles
Digital presenceGDPR compliance and trust
Trust signalCompliance3 records
GDPR financial estimates
Financial estimateRevenue estimate
Valuation estimate
GDPR leadership team
Management profileNumber of profiles
Profiles2 records
GDPR subsidiaries and ownership
Company hierarchySubsidiaries2 records
GDPR funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
GDPR M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about GDPR
What does GDPR do?
GDPR.ie provides data protection and cybersecurity consultancy services to organisations in Ireland and Europe, including GDPR compliance audits, remediation, policy drafting, external Data Protection Officer (eDPO) and External Data Protection Manager (eDPM) services, CREST-accredited penetration testing, vulnerability assessments, social engineering simulations, and IAPP- and PECB-certified training courses (CIPP/E, CIPM, CIPT, CDPO, ISO 27701, ISO 42001). Service delivery is supported by proprietary platforms including the Sentry Portal, Vulnerability Manager, and an AI-powered Human Risk Management platform.
Is GDPR a public or private company?
GDPR is a private company. It is classified as corporate owned and is currently operating.
When was GDPR founded?
GDPR was founded in 2009. It employs 11 to 50 people.
Where is GDPR based?
GDPR is headquartered in Sandyford, Ireland, in the Europe region.
How does GDPR make money?
Four revenue lines are on record. Professional Services (Consultancy) is the primary driver. The others are training and Certification Courses, security Testing Services and external Data Protection Manager (eDPM).
Who are GDPR's main competitors?
Direct peers on record are BH Consulting, Bishop Fox, Integrity360, Tevora and IOActive. Broad incumbents are NCC Group, Trustwave, Mandiant (Google Cloud) and Optiv Security. Arctic Wolf is listed as an emerging player.
Does GDPR have an API?
No public API is recorded for GDPR.
What industry is GDPR in?
GDPR's product category is Data Protection and Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAM, Data Security & Privacy Services (DLP, Encryption, Privacy Ops), with a secondary code of BPAEADAL, Data Security & Privacy Managed Services (DLP/Encryption). Its NAICS code is 5616 and its SIC code is 7370.