Audits and the GDPR

If your company is preparing for GDPR compliance, you’ll need to conduct a data audit. Or perhaps you have achieved compliance and need to carry out the mandatory annual audit to ensure you are still compliant.

If you are wondering how conduct an audit, don’t worry, you’re not alone. Many organisations are struggling to figure out how to conduct a GDPR compliance audit properly. However, we’re here to help. In this blog post, we guide you on how to conduct a GDPR compliance audit properly.

Conducting a GDPR compliance audit can be daunting, but you must do it properly if you want to ensure that your organisation is compliant with the GDPR.

What is a GDPR audit?

A GDPR compliance audit gives you a clear picture of how your organisation is performing in relation to the regulation. If you want to ensure that your organisation complies with the GDPR, this will be essential. Your customers may require proof that you are compliant. Simply saying you are complaint will not suffice. You must evidence the outcome of your audit when asked.

Do I need a GDPR audit?

Your company must conduct an audit of your data protection policies in light of GDPR rules. Data audits can provide businesses with a good opportunity to assess their conformity to GDPR requirements. This must be carried out at least annually.

The six data protection principles are:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Data accuracy
  • Storage limitation
  • Integrity and security

A seventh principle was added when the UK Data Protection Act of 2018 became law, and that is, the accountability principle.

What are the requirements of the GDPR?

The GDPR comes with many requirements that your company must meet.

These include the following:

  1. Ensuring personal data is processed lawfully, fairly, and transparently; protecting personal data from loss or misuse by taking appropriate technical and organisational measures;
  2. Make sure that data is collected only for specified lawful purposes and that it is adequate, relevant, and limited to what is necessary for processing personal data; ensuring that personal data should not be kept longer than necessary.

What data is protected by the GDPR?

All personal data is protected by the GDPR. Anything that can be used to identify an individual ranging from a photograph, to an IP address, or an online identifier is personal data. Simple items such as name, address, email address, phone number and dates of birth are included. Data such as sexual orientation, religious beliefs, political views, trades union membership are all classified as special category. This data requires further security measures and controls. This should only be collected if absolutely necessary.

If your business is required to comply with anti-money laundering regulations and/or the right to work, you are likely to have images of passports, driving licences and visas etc. This data must be treated extremely carefully as if you lose it, fines and legal action will follow. Of that there is no doubt!

Conducting a GDPR Data Audit

What do you need to carry out a GDPR compliance audit?

To carry out a GDPR compliance audit properly, you will need the following:

  • An understanding of what data you have and where it is located. You’ll also need to understand why you have this data and whether or not it complies with the GDPR.
    • This will be recorded on your data asset register
  • A list of all third parties with whom you share data.
    • This will be recorded on your Data Flow Map or your ROPA (Article 30) document
  • A list of all people who have access to your organisation’s data and their roles within the organisation.
    • This will be recorded in several places and is likely to be linked to an organisational chart and AD diagram if you have one
  • An understanding of how this data is processed and for what reasons.
    • Your Data Asset Register will contain this data

Therefore, you will need your Data Asset Register, Data Flow Map and, if you have one, your ROPA (Article 30) document.

How do you audit your GDPR compliance?

Conducting a GDPR compliance audit is no easy task. It will take time and effort, but you’ll be glad that you did it when it comes to passing your audit. Follow these steps to complete your GDPR audit properly:

  1. Start with the end in mind. What information do you need to conduct an accurate GDPR compliance audit? Having a clear picture of what you are looking for will help you get the most out of your GDPR compliance audit.
  2. Conduct an inventory of all data that you have within the organisation. This will include information on where this data is stored, why it was collected, who has access to it, and how it is processed.
  3. Conduct a review of all third-party connections that your organisation has. Look into what data is exchanged and for what reasons. Conduct an in-depth review of your partners, suppliers, and customers to ensure that you are compliant with the GDPR when it comes to sharing information.
  4. Review who has access to this data and how they use it (this will be relevant for your employees).
  5. Understand how this data is processed (this aspect is particularly important for your IT team, as they may need to make some changes to comply with the GDPR).

Think about what else you should do after carrying out your GDPR compliance audit. Review the results of this audit and make a plan for how you will become GDPR compliant. You may need to think about getting help if this is sounding too daunting or time consuming.

How to conduct a proper GDPR compliance audit

Your company’s GDPR audit checklist will depend on several factors, including your company’s size and the amount and type of data that your company deals with. Other factors will include, but are not limited to, data moving across borders, in particular outside of the EU.

GDPR audit checklist

  1. List the data you must protect.
  2. Check whether your supply chain is GDPR is compliant. If not, take necessary actions to ensure compliance including auditing them.
  3. Ensure that your company can respond when asked for user controls and downloads under GDPR rules. Ensure confidentiality of communications with users (i.e., encrypting data).
  4. Make sure that you do not keep data once you no longer have a legal basis for processing.
  5. Ensure your employees are trained in all aspects of the GDPR. Ensure they are aware of their responsibilities. This must be demonstrable.
  6. Make sure that technologies used by your company comply with GDPR requirements as well as third-party products or services that you purchase from other companies.
  7. Retain control of how your data is shared or transferred outside the EU.
  8. Ensure that consent for using personal data is requested by GDPR rules, and that this consent is not bundled into terms and conditions.
  9. Understand hidden costs of breaches to GDPR provisions, which can be significant even if they appear to be minor based on the numbers involved.
  10. Complete a gap analysis of your current GDPR practices.

What is a Data Protection Officer and what do they do?

A data protection officer is an internal role that works to ensure compliance with GDPR rules. They are responsible for overseeing all data processing activities to ensure that the company complies with the GDPR. This includes working closely with engineering teams to implement privacy technologies. They will also liaise directly with regulators and conduct internal investigations in the event of a data breach. 

The data protection officer is responsible for ensuring that all company policies and procedures relating to data protection are being followed, as well as overseeing the entire compliance process, including a personal information management system (PIMS). This is part of the ISO27001 standard.

Summary

To comply with the GDPR in full, an audit must be conducted. A regularly performed internal audit should help ensure you comply with the GDPR requirements before inviting an external audit. External GDPR audits must be carried out by a specialised company, not an internal team. We hope that you found this article helpful, and it will provide you with the information required to ensure GDPR compliance.