← IP, GDPR & Cybersecurity

GDPR · Integrated audit

GDPR audit and compliance for companies

GDPR compliance is not a standard file, but the company’s ability to explain and demonstrate what data it uses, for which purpose, on which legal basis, for how long, with whom it shares it and how it protects individuals. The audit starts from actual operations and ends with priorities, responsible persons and verifiable evidence.

data mapping record of processing activities remediation plan
Starting pointActual processes, systems, data and providers
DeliverablesRecords, notices, policies and an action plan
PrincipleDemonstrable accountability, not generic documents
01

Mapping data before drafting

Interviews trace flows in sales, HR, marketing, support, accounting, security and product. For each purpose, the data subjects, data, source, recipients, systems, transfers and retention period are recorded.

This map enables the role of controller, joint controller or processor to be established and feeds the record required by Article 30. The exemption for organisations with fewer than 250 employees is limited and must not be assumed automatically where processing is not occasional or involves risk or sensitive data.

02

Lawfulness, transparency and minimisation

Every purpose needs a legal basis and coherent information. Consent is not a universal solution, and legitimate interests require analysis, documentation and a genuine right to object where the law recognises it.

  • Purpose and legal basis: defined separately, without incompatible reuse.
  • Data: only what is necessary, with role-based access limits.
  • Information: clear, accessible and delivered at the right time.
  • Retention: criteria and periods technically implemented, not merely declared.
  • Providers: contracts, instructions, subprocessors and transfers.
  • Data subjects: channel, identity, deadlines and response records.
03

Security and risk to individuals

Article 32 requires technical and organisational measures appropriate to the risk. The legal audit does not replace technical testing, but examines access governance, backups, encryption, logging, provider management and the incident procedure.

Processing likely to create a high risk must be analysed to determine whether a DPIA is needed. Launching new technology, combining databases or systematic monitoring may change the assessment even if the old documents have not changed.

04

The remediation plan and evidence of implementation

Findings are prioritised by risk, effort and dependencies. Urgent measures may concern uncontrolled access, missing contracts, transfers or retention; structural measures may require technical development and staff training.

Each measure identifies the responsible person, deadline and evidence of completion. Management must be able to track progress, and policies must be tested through exercises: responding to requests, simulating a breach and checking deletion.

05

How we work together

  1. 01
    Collecting information

    We establish the processes, systems, providers, data categories, roles and existing documents relevant to the GDPR audit.

  2. 02
    Risk and legality analysis

    We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.

  3. 03
    Documents and workflow

    We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.

  4. 04
    Controlled implementation

    We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.

QUESTIONS

Frequently asked questions

Does a set of downloaded policies mean GDPR compliance?

No. Documents must reflect the processes and be implemented. The gap between policy, interface and practice is itself a risk.

Is a data protection officer mandatory?

Only in the cases provided by Article 37 GDPR. Even without an obligation to appoint a DPO, the company must allocate responsibilities and resources for compliance.

How often is the audit updated?

There is no single interval. Review must be triggered by relevant changes and performed periodically according to risk, providers and the organisation’s pace.

Need a GDPR audit and compliance plan?

Send your documents for a legal assessment and a solution tailored to your commercial objective.