GDPR · Integrated audit
GDPR audit and compliance for companies
GDPR compliance is not a standard file, but the company’s ability to explain and demonstrate what data it uses, for which purpose, on which legal basis, for how long, with whom it shares it and how it protects individuals. The audit starts from actual operations and ends with priorities, responsible persons and verifiable evidence.
Mapping data before drafting
Interviews trace flows in sales, HR, marketing, support, accounting, security and product. For each purpose, the data subjects, data, source, recipients, systems, transfers and retention period are recorded.
This map enables the role of controller, joint controller or processor to be established and feeds the record required by Article 30. The exemption for organisations with fewer than 250 employees is limited and must not be assumed automatically where processing is not occasional or involves risk or sensitive data.
Lawfulness, transparency and minimisation
Every purpose needs a legal basis and coherent information. Consent is not a universal solution, and legitimate interests require analysis, documentation and a genuine right to object where the law recognises it.
- Purpose and legal basis: defined separately, without incompatible reuse.
- Data: only what is necessary, with role-based access limits.
- Information: clear, accessible and delivered at the right time.
- Retention: criteria and periods technically implemented, not merely declared.
- Providers: contracts, instructions, subprocessors and transfers.
- Data subjects: channel, identity, deadlines and response records.
Security and risk to individuals
Article 32 requires technical and organisational measures appropriate to the risk. The legal audit does not replace technical testing, but examines access governance, backups, encryption, logging, provider management and the incident procedure.
Processing likely to create a high risk must be analysed to determine whether a DPIA is needed. Launching new technology, combining databases or systematic monitoring may change the assessment even if the old documents have not changed.
The remediation plan and evidence of implementation
Findings are prioritised by risk, effort and dependencies. Urgent measures may concern uncontrolled access, missing contracts, transfers or retention; structural measures may require technical development and staff training.
Each measure identifies the responsible person, deadline and evidence of completion. Management must be able to track progress, and policies must be tested through exercises: responding to requests, simulating a breach and checking deletion.
How we work together
- 01Collecting information
We establish the processes, systems, providers, data categories, roles and existing documents relevant to the GDPR audit.
- 02Risk and legality analysis
We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.
- 03Documents and workflow
We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.
- 04Controlled implementation
We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.
Frequently asked questions
Does a set of downloaded policies mean GDPR compliance?+
No. Documents must reflect the processes and be implemented. The gap between policy, interface and practice is itself a risk.
Is a data protection officer mandatory?+
Only in the cases provided by Article 37 GDPR. Even without an obligation to appoint a DPO, the company must allocate responsibilities and resources for compliance.
How often is the audit updated?+
There is no single interval. Review must be triggered by relevant changes and performed periodically according to risk, providers and the organisation’s pace.
Need a GDPR audit and compliance plan?
Send your documents for a legal assessment and a solution tailored to your commercial objective.
Aveți nevoie de asistență juridică urgentă sau de consultanță de specialitate?
Notă juridică și limitarea răspunderii
Informațiile și articolele publicate pe acest site web sunt puse la dispoziție de Avocatul „Basuc Cosmin Ștefan” exclusiv în scop informativ și educativ general. Materialele prezentate reprezintă analize teoretice și opinii de specialitate la data redactării lor, fără a constitui consultanță juridică, asistență legală sau o opinie aplicabilă unui caz concret. Lectura sau utilizarea acestui conținut nu creează o relație profesională avocat-client între cititor și Cabinet. Având în vedere dinamica legislativă și specificul fiecărei situații de fapt, interpretările conținute nu pot substitui analiza individuală a unei cauze. Pentru stabilirea cadrului juridic aplicabil problemei dumneavoastră și obținerea unei consultații profesionale dedicate, vă invităm să contactați Cabinetul prin mijloacele oficiale de comunicare afișate.
Linkuri utile și legislație
