Since 1988 Independent IT testing
IAPP-certified Credentialed privacy assessors
No software to sell Findings with no product agenda
ISO 27001 certified Independently audited security
Data Privacy Services

Two ways to work with TestPros on data privacy

Engage us to independently audit where your privacy program stands, or to advise on what to fix and build the process and procedure artifacts your program needs. Both come from a firm with no software or platform to sell.

Independent Verification

Data Privacy Audit

An independent assessment of where your privacy program stands against the laws that apply to your business, with documented findings, risk ratings, and specific remediation guidance.

  • Assessment against applicable privacy laws
  • Data inventory and processing review
  • Gap analysis with risk ratings
  • Findings report and remediation guidance
Explore data privacy audit services
Advise & Build

Data Privacy Consulting

Guidance on what to fix and in what order, plus the process and procedure artifacts that put your program into practice: policies, procedures, a Record of Processing Activities, DPIA templates, and notices.

  • Data mapping and inventory build-out
  • Privacy program advisory
  • Prioritized remediation roadmap
  • Policy and procedure artifacts (RoPA, DPIA templates, notices)
Explore data privacy consulting services

Independent throughout: TestPros sells no privacy software or platform and never acts as your outsourced DPO, so every finding and recommendation is free of any product agenda.

Privacy Frameworks

Which privacy laws apply to your business?

We assess your program against the laws most likely to govern how you handle personal data. Start with the framework that fits your business. If several apply, we map them together.

EU / International

GDPR

General Data Protection Regulation

Applies to any organization that handles the personal data of people in the EU or EEA, wherever the organization itself is based.

GDPR compliance services
US Healthcare

HIPAA

Health Insurance Portability and Accountability Act

Applies to US healthcare providers, health plans, and clearinghouses, and to the business associates that handle protected health information on their behalf.

HIPAA compliance services
Children's Privacy

AADC

Age-Appropriate Design Code

A growing set of state design-code laws covering online services likely to be accessed by minors, with South Carolina in effect and more states advancing.

Age-Appropriate Design Code
US State / California

CCPA

California Consumer Privacy Act, as amended by the CPRA

Applies to qualifying for-profit businesses that handle the personal information of California residents above defined revenue or data-volume thresholds, now with regular privacy risk assessments among the obligations.

CCPA compliance services
How It Works

A clear path from kickoff to a report you can act on

Every engagement follows the same disciplined sequence, so you always know where the assessment stands and what comes next.

1

Scope & Kickoff

We confirm which privacy laws apply to your business and what is in scope for the assessment.

2

Discovery

We review your data practices, policies, and processing activities against the standards that bind you.

3

Assessment

We test your safeguards and privacy controls, document gaps, and rate each finding by severity.

4

Reporting

You receive a documented report with findings mapped to each requirement and a remediation step for every gap.

5

Remediation Support

We walk your team through the findings and the fixes, so you can close gaps with confidence.

The Deliverable

What an independent assessment leaves you with

Every engagement ends in a documented report your team can act on and share with the people who need to see it. Here is what the inside of a HIPAA assessment looks like.

Inside the report

A HIPAA assessment documents where your safeguards and privacy practices stand, and what to fix first.

  • An executive summary written for leadership.
  • Every finding mapped to the HIPAA safeguard it affects.
  • A severity rating and remediation step on each finding.
  • A format you can share with auditors, business partners, and your board.
Multistate Compliance

Your privacy obligations change from state to state

There is no single US privacy law. A growing number of states regulate how personal data is collected, shared, and protected, and the requirements differ from state to state. We map which laws apply to your business and assess your program against them.

Comprehensive state privacy laws

Broad consumer privacy laws now exist in states such as California, Virginia, and Colorado, each with its own requirements.

Age-appropriate design codes

New state laws covering online services likely to be accessed by minors. South Carolina is in effect, with more states advancing.

Sector and data-type laws

Biometric, health-data, and data-broker laws that can apply regardless of where your business is based.

Not sure which state laws reach your business?

Contact Us
Credentials

The credentials behind every assessment

Compliance with privacy laws like GDPR and HIPAA is not something an accredited body certifies. What you can verify is the rigor and independence of the firm that assesses yours.

TestPros has tested IT independently since 1988. Our privacy assessors hold IAPP certifications, and our own operations are independently certified to recognized standards.

Independently certified operations
ISO 27001:2022

Information security

ISO 9001:2015

Quality management

ISO 20000-1:2018

IT service management

CMMI Level 3

Process maturity

FAQ

Common questions about data privacy compliance

Answers to what organizations ask most often before an assessment.

Which data privacy laws apply to my industry?

It depends less on your industry and more on the data you handle and where the people behind that data are located. Healthcare providers and their vendors face HIPAA. Online services likely to be reached by minors face state age-appropriate design codes. Financial institutions face GLBA along with a growing set of state privacy laws. Most organizations that handle consumer data are also covered by GDPR, comprehensive state privacy laws, or both. We map the specific laws that reach your business before we assess against them.

Does TestPros certify that we are GDPR or HIPAA compliant?

No. Compliance with privacy laws like GDPR and HIPAA is not something any accredited body certifies. What we provide is an independent assessment that documents where your program stands against the law and what to prioritize. Because we have no software or services riding on the result, that documentation carries weight with the customers, auditors, and regulators who read it.

What is the difference between your audit and consulting services?

An audit is independent verification. We assess your program against the applicable laws and document the findings, with no role in building what we are reviewing. Consulting is where we advise and help build the program itself, including data maps, policies, procedures, and the records the laws expect you to keep. Some organizations use one, some use both at different stages.

Do you sell privacy software or act as our outsourced DPO?

No on both. We do not sell privacy software, scanners, or platforms, and we do not serve as your outsourced data protection officer. That independence is deliberate. It means our findings reflect where you actually stand rather than steering you toward a product or a retainer we benefit from.

How do you handle compliance across multiple states?

There is no single US privacy law, and the requirements differ from state to state. We start by mapping which laws reach your business based on where you operate and whose data you hold, then assess your program against each one. That includes comprehensive state privacy laws, age-appropriate design codes, and sector or data-type laws such as biometric and health-data rules.

What does a data privacy assessment include?

A typical assessment moves through five stages: defining scope, mapping where personal data lives and how it flows, analyzing gaps against the applicable laws, documenting findings with risk ratings, and giving your team prioritized remediation guidance. You finish with a report you can act on internally and share with customers, auditors, or your board.

Do you only identify gaps, or help us fix them?

Both. Every assessment includes remediation guidance, the specific steps to close each gap. If you want hands-on help building the fixes, our consulting engagement develops the policies, procedures, and records the laws expect. The one thing we never do is hand you a tool to buy, because we do not sell one.

How do we get started?

It starts with a short scoping conversation about the data you handle, the laws that apply, and your timeline. From there we scope the assessment to your situation. Reach out through our contact form and a TestPros assessor will follow up.

Ready When You Are

Know where your privacy program actually stands.

Tell us which laws apply, what you have in place, and your timeline.

Get Started
  • No software, no conflicts
  • ISO 27001 + CMMI ML3
  • Independent IT testing since 1988