Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

How to Conduct a Proper GDPR Audit: 4 Key Steps

By TheFinanceBase Team12 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A proper GDPR audit is a documented, risk-based examination of whether an organisation’s real data processing, contracts, systems and staff behaviour match its legal obligations and stated privacy controls. It is not a one-time checklist or a certification exercise.

The most useful method has four stages: scope the audit and map processing; test legal and individual-rights controls; test processors, security, DPIAs and breach readiness; then risk-rank findings, remediate and retest. The result should be evidence that controls work in practice—not simply a file of policies.

This guide focuses on the EU GDPR under Regulation (EU) 2016/679. Organisations subject to the UK GDPR should distinguish that regime from the EU GDPR and consult current ICO guidance; the ICO framework is useful but is not a substitute for jurisdiction-specific legal advice.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a GDPR audit should prove

A GDPR audit should answer four practical questions:

  1. Does the organisation know what personal data it processes, why, where and with whom?
  2. Are the legal, transparency, retention, transfer and data-subject-rights controls properly designed?
  3. Do processors, security measures, DPIAs and incident procedures operate effectively?
  4. Are weaknesses assigned to accountable owners, corrected and independently retested?

The audit should assess both design effectiveness—whether a control is appropriately designed—and operating effectiveness—whether people and systems actually follow it. The ICO’s February 2026 audit guide describes an approach based on document review, interviews, operational evidence and testing, rather than reliance on written policies alone. Read the ICO audit guide.

There is no single legally prescribed audit format. Scope and depth should reflect the organisation’s size, data sensitivity, monitoring or profiling, international transfers, processor dependence, previous incidents, complaints and regulatory exposure. The ICO also cautions that its framework is a starting point, not an exhaustive guarantee of compliance. See the ICO data protection audit framework.

Before the audit: set the ground rules

Decide who commissioned and approved the audit and whether it is internal, independent, customer-driven, regulator-driven or linked to a product launch, acquisition or incident. Confirm the legal entities, countries, supervisory authorities, business units and systems in scope.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Also establish:

  • Whether the organisation acts as controller, joint controller, processor or in more than one role.
  • The audit period and the GDPR articles, contracts, policies or standards being assessed.
  • The highest-risk processing activities and known incidents, complaints, rights-request failures or previous findings.
  • Who may access personal data during the audit and how confidentiality, privilege and employment-law constraints will be managed.
  • What evidence must be preserved before testing begins.
  • How samples will be selected and who owns each process.

A blended model can work well: internal staff provide operational access and maintain remediation, while an independent privacy, legal or security specialist reviews high-risk areas or validates the methodology.

Step 1: Define the scope and map every relevant processing activity

Start with an audit objective

Do not begin by auditing “the company” in the abstract. Write a scope statement that says what the audit must determine. Examples include whether a new EU product is ready, whether marketing practices have a valid basis, whether previous findings are closed, whether rights requests can be fulfilled, or whether third-country transfers are documented and risk-assessed.

Identify:

  • Legal entities, business units and countries.
  • Controller, joint-controller and processor relationships.
  • Websites, applications, databases, cloud services, physical records and integrations.
  • Data-subject groups, such as customers, employees, applicants, children or suppliers.
  • Personal-data categories, including special-category and criminal-offence data.
  • Purposes, recipients, vendors, subprocessors, retention rules and transfer destinations.
  • High-risk processing, profiling, automated decisions, monitoring and new technologies.

Build or update the RoPA

The Article 30 record of processing activities, or RoPA, should be the audit’s central inventory. It is not merely a list of applications. Processing should be organised around the purpose; one application may support several legally distinct activities, and one activity may span multiple systems.

For each activity, record at least:

  • Purpose and lawful basis.
  • Controller, processor, joint-controller and representative details, where applicable.
  • Categories of data subjects and personal data.
  • Special-category or criminal-offence data.
  • Recipients and internal access groups.
  • Processors and subprocessors.
  • Retention period or deletion criteria.
  • Security measures.
  • International transfers and transfer mechanisms.
  • DPIA or risk-assessment status.
  • Relevant privacy notice, system of record, process owner and review date.

CNIL’s RoPA guidance recommends interviewing operational supervisors, reviewing websites and online forms, listing processing by purpose and regularly updating the record.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Trace real data flows

Use more than the existing inventory. Interview business and operational owners; review website forms, cookie and analytics configurations, procurement records, identity-and-access systems, CRM, HR, support, marketing and data-warehouse environments. Examine application diagrams, APIs, cloud architecture and vendor records.

Then sample real records and trace where they came from, who can access them, where they travel, which processors receive them and when they should be deleted. Include shadow IT, spreadsheets, email exports, test environments, backups, logs and support tools. A vendor’s claim that it is “GDPR compliant” does not prove that the organisation’s actual use of the service is compliant.

Step 1 deliverables

  • Approved scope statement.
  • Current RoPA or processing inventory.
  • Data-flow diagrams for material or high-risk activities.
  • System, vendor, subprocessor and transfer registers.
  • Evidence-request list and risk-based sampling plan.
  • Named interviewees and process owners.

Step 2: Test lawfulness, transparency, rights, retention and transfers

For every material or sampled processing activity, compare the organisation’s stated purpose and legal basis with what its systems and employees actually do.

Test the GDPR principles

Principle Audit question
Lawfulness, fairness and transparency Is the processing disclosed and supported by a valid legal basis?
Purpose limitation Is data used only for specified purposes or compatible further purposes?
Data minimisation Is every collected field necessary?
Accuracy Can people correct inaccurate data, and are quality controls operating?
Storage limitation Are retention periods defined and enforced?
Integrity and confidentiality Are appropriate technical and organisational measures operating?
Accountability Can the organisation prove the above with reliable evidence?

These principles appear in Articles 5 and 6 of the GDPR, which also set out the principal lawful bases.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify the lawful basis

Document the legal basis separately for each purpose. Do not use one broad basis for unrelated service delivery, analytics, direct marketing, fraud prevention and employee monitoring.

For each purpose, ask:

  • What basis is recorded and why does it apply?
  • Is contract necessity genuine, rather than merely convenient?
  • For consent, do records show who consented, when, to what wording and how withdrawal works?
  • For legitimate interests, is there a documented assessment balancing the organisation’s interests against individuals’ rights?
  • For special-category data, is an additional Article 9 condition documented?
  • Does the privacy notice match the actual purpose and basis?

Compare privacy notices with system behaviour

Check whether notices identify the controller, DPO contact details where applicable, purposes, legal bases, data categories, recipients, processors, transfers, retention criteria, rights, complaint routes and automated decision-making or profiling.

Check timing and presentation too. A notice should appear at the correct point in a website, mobile, employee or customer journey and remain understandable. Include cookie banners and layered notices where relevant. For data obtained indirectly, verify that the notice explains the source or categories of source as required.

A useful walkthrough is to select a real record and trace it backwards: where was the person informed, what did the notice say and does current processing match it?

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test data-subject rights end to end

Review how requests arrive through email, web forms, customer support and other channels. Then test identity verification, searches, legal review, redaction, approval, response, fulfilment and logging.

Include access, correction, deletion, restriction, portability and objection workflows where applicable. Test whether the organisation can search its CRM, support platform, marketing tools, data lake, backups and processor environments. Check how processors assist, how exemptions are applied, how complex-request extensions are communicated and how the response history is evidenced.

Under Article 12, a response is generally due without undue delay and, in principle, within one month. The period may be extended by up to two further months for complex or numerous requests if the requester is informed within the initial month. See Articles 12–22 of the GDPR.

Test retention and deletion

For each data category, identify the event that starts retention, the justification for the period and the system control that enforces it. Test inactive accounts, exports, logs, paper records, test data, backups and legal holds. Verify that vendors delete or return data when instructed and that data is not retained simply because storage is inexpensive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Article 5’s storage-limitation principle requires identifiable personal data to be kept no longer than necessary for its purposes, subject to applicable exceptions. A retention policy that systems cannot enforce is not an effective control.

Audit international transfers

Inventory cloud hosting, remote support, global employee access, analytics, advertising platforms, backups, disaster recovery, vendor telemetry and onward transfers from the EEA to third countries.

For each transfer, record the exporter and importer, destination, data categories, purpose, transfer mechanism, subprocessor chain, government-access considerations, supplementary measures, transfer-impact assessment where required, contract terms and privacy-notice references.

Transfers may rely on an adequacy decision or, where appropriate, safeguards such as approved standard contractual clauses or binding corporate rules; limited derogations may also apply. Review Articles 44–49 of the GDPR. An adequacy decision does not remove the need to understand actual access, onward transfers, contracts and security.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 2 deliverable

Create a matrix for every sampled activity showing its purpose, data categories, lawful basis, notice, retention rule, rights procedure, transfer mechanism, evidence reviewed, gaps and risk rating.

Step 3: Test processors, security, DPIAs and breach readiness

Review processors and subprocessors

For every material processor, verify a written Article 28-compliant contract covering documented instructions, confidentiality, security, subprocessor controls, assistance with rights requests and incidents, DPIA support, return or deletion, audit rights, breach-notification timing, data locations and transfers.

Compare contracts with the service actually delivered. Maintain a current subprocessor list and check whether the organisation receives meaningful notification of changes. A SOC 2 report, ISO 27001 certificate, penetration test or questionnaire may support an audit, but it does not automatically establish full GDPR compliance. Check whether the evidence covers the relevant service, period, locations, data and control objective. Vanta’s practical GDPR audit guidance discusses several of these evidence areas.

Test security against risk

Article 32 requires security appropriate to risk. The audit should assess proportionality rather than impose an identical checklist on every organisation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review applicable controls including:

  • Least privilege, privileged-access management and multifactor authentication.
  • Joiner, mover and leaver controls and periodic access reviews.
  • Encryption in transit and at rest and key management.
  • Network segmentation, secure development and change control.
  • Vulnerability, patch and endpoint management.
  • Logging, monitoring and data-loss prevention.
  • Backup protection and restoration testing.
  • Physical security, confidentiality commitments and role-specific training.
  • Pseudonymisation or anonymisation where appropriate.

Sample evidence rather than accepting assertions. Useful tests include a terminated employee’s access record, a privileged-account log, a remediation ticket, a backup restoration, a security incident ticket, a production-to-test data transfer and a deletion request across connected systems.

Determine whether a DPIA is required

A DPIA is required before processing likely to result in a high risk to individuals’ rights and freedoms. If high risks cannot be mitigated adequately, prior consultation with the supervisory authority may be required. See EDPB DPIA resources.

Screen for large-scale special-category or criminal-offence data, systematic monitoring, extensive profiling, significant automated decisions, vulnerable data subjects, biometric or genetic data, location tracking, unexpected dataset combinations and new technologies likely to create physical, financial, reputational or discriminatory harm.

For each DPIA, check that it accurately describes the processing, assesses necessity and proportionality, identifies risks to individuals, lists safeguards, has an owner and approval, influences design before launch and is reviewed after material changes, incidents or new evidence. A DPIA does not itself make processing lawful and is not the same as a general cyber-risk assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test breach readiness

Verify how staff report suspected incidents and near misses, who classifies them, how processor notifications escalate, who decides whether notification is required, how evidence is preserved and how lessons become corrective actions.

Under Article 33, a controller must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a reportable personal-data breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. The clock is measured from awareness, not necessarily from when the underlying incident began. Read Article 33.

Run a tabletop exercise or sample a historical incident. Test whether the organisation can quickly identify affected data, individuals, systems, processors, jurisdictions and notification decisions, including decisions not to notify.

Step 3 deliverables

  • Processor and subprocessor register.
  • Contract-gap matrix.
  • Security-control test results.
  • DPIA screening and completed-DPIA register.
  • Breach tabletop or historical-incident review.
  • Training and escalation evidence.
  • List of controls that exist on paper but fail in operation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Step 4: Report, remediate, document and retest

Risk-rank findings

Use a consistent method based on potential impact to individuals, likelihood, regulatory significance, detectability, persistence and breadth. Consider sensitivity, scale, vulnerable people, discrimination, financial loss and loss of control—not only cyberattack probability.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Classify findings clearly, for example as critical, high, medium or low, but define the thresholds before rating them. A missing deletion process, invalid lawful basis or inability to fulfil rights may be a serious privacy risk even where no security incident has occurred.

Make each finding actionable

Every finding should include:

  1. Condition: what was observed.
  2. Requirement: the relevant GDPR article, contract, policy or control.
  3. Evidence: documents, interviews, samples and tests supporting the conclusion.
  4. Cause: why the gap exists.
  5. Risk: what could happen to individuals or the organisation.
  6. Recommendation: the required change.
  7. Owner and due date.
  8. Success measure: evidence required for closure.
  9. Retest date and result.

Separate containment from remediation

For serious findings, distinguish immediate containment—such as stopping collection, disabling an integration, restricting access or pausing a launch—from corrective action, such as fixing a contract, notice, process or system. Preventive action might add automated deletion, privacy-by-design review, monitoring or recurring testing.

Retest closure

A rewritten policy does not prove that a finding is closed. Closure evidence could include a successful deletion test, completed rights request, corrected notice displayed at the correct point, signed processor contract, transfer assessment, restored backup, completed access review or successful incident exercise.

Track findings in an action plan with an accountable owner, deadline, status, residual risk and retest result. Management should explicitly accept any remaining risk at the appropriate authority level. The ICO framework supports recording, tracking and reporting progress through audit trackers and action plans.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practical GDPR audit worksheet

Use a spreadsheet, GRC platform or privacy-management system, provided the tool supports judgement rather than replacing it.

Field What to record
Processing activity Purpose-based name and process owner
Legal basis Basis for each purpose and any Article 9 condition
Data and people Data categories, special categories and data subjects
Systems and recipients Systems, internal users, recipients and processors
Transfers Destination, access route and transfer mechanism
Retention Period, trigger, deletion method and backup treatment
DPIA Screening result, status, owner and review date
Control tested Walkthrough, sample, interview or technical test
Evidence Document, record, log, ticket or test output
Finding and risk Condition, requirement, impact, likelihood and rating
Remediation Owner, action, deadline and containment
Retest Closure evidence, date and result

Important edge cases

Small organisations

The limited Article 30 exception for organisations with fewer than 250 employees is often overstated. Recurring customer, employee, supplier, marketing, analytics or support processing is unlikely to be “occasional”. Risky or special-category processing can independently trigger record-keeping obligations. A smaller organisation should generally maintain a proportionate RoPA rather than assume it is exempt.

Organisations with dual roles

A business may be a controller for its own employees and customers while acting as a processor for customer data. Keep those roles distinct in the inventory, contracts, notices and control tests.

International groups

Group policies do not automatically resolve transfer issues. Test shared services, central support, global administrators, identity systems, data lakes, onward transfers and the actual locations of staff with access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI, profiling and employee monitoring

Add tests for training-data provenance, purpose, lawful basis, minimisation, transparency, accuracy, human review, contestability, special-category inference, vendor access, retention and transfers. Assess whether profiling or automated decisions have legal or similarly significant effects and whether a DPIA is required.

Marketing, cookies and cloud platforms

Do not isolate website consent from the broader customer journey. Trace identifiers into analytics, advertising, CRM, support and data-warehouse systems. For cloud services, test administrator access, support locations, subprocessors, backups, deletion and onward transfers.

How often should a GDPR audit be repeated?

Repeat the audit on a risk-based schedule and whenever processing or exposure changes materially. Triggers include a new product, merger or acquisition, major vendor change, new country, significant incident, new profiling or AI use, regulatory concern, repeated rights failures or a material change in systems.

The practical cycle is simple: map, test, fix, prove and repeat. The quality of evidence and retesting matters more than the appearance of a complete checklist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.