GDPR compliance audit
We verify legal bases, transparency notices, registers, retention, data subject rights, processor agreements and safeguards.
- Nonconformity report
- Risk assessment
- Corrective action plan
GDPR audit and personal data protection
We combine legal requirements with operational practice: mapping data, assessing risk, organising documentation and supporting controllers, DPOs and teams during personal data breaches.
Scope of support
We assess not only documentation but also how data actually flows between people, systems, suppliers and recipients.
We verify legal bases, transparency notices, registers, retention, data subject rights, processor agreements and safeguards.
We provide independent Data Protection Officer support: compliance monitoring, advice, training and contact with individuals and the supervisory authority.
We help contain the event, collect facts, assess risks to individuals, document decisions and prepare required notifications and communications.
We embed data protection into new services, systems and process changes. We perform risk analysis and assess whether a data protection impact assessment is required.
Audit process
We identify processing activities, purposes and legal bases, categories of individuals and data, recipients, systems, processors, transfers outside the EEA, and retention periods. We verify that actual practices are consistent with records and documentation.
We assess compliance with the GDPR principles, transparency duties and data subject rights, as well as processor arrangements and international transfers. We analyse risk, the adequacy of safeguards and the need for a data protection impact assessment.
We translate audit findings into an action plan with priorities, accountability, deadlines and expected outcomes. We update documentation, records, privacy notices, agreements and procedures, and support the implementation of safeguards and training.
We verify completion of the actions and the effectiveness of the changes introduced. We monitor breaches, data subject rights, retention, access rights, processors and new activities, providing accountability evidence and a basis for continual improvement.
Engagement outcome
The final set of deliverables depends on the audit or implementation scope and the role in which we support the controller.
A structured description of purposes, legal bases, data categories, recipients, systems, processors, transfers and retention periods.
Findings, an assessment of risks to individuals’ rights and freedoms, and a prioritised action plan with owners and deadlines.
Updated records, notices, agreements and procedures for rights requests, retention, breaches and processor management.
Support with action delivery, safeguard selection, training, recommendation monitoring and collection of compliance evidence.
DPO outsourcing
We provide support aligned with the Data Protection Officer’s statutory tasks while safeguarding the DPO’s independence and the controller’s responsibility for its decisions.
We review the organisational structure, processing activities, responsibilities, key risks and previous compliance work. We agree the monitoring plan, communication arrangements, access to information and the process for involving the DPO in new initiatives.
We review documentation and operational practice, monitor fulfilment of obligations and issue recommendations. We verify corrective actions and legal or organisational changes while preserving the independence of the DPO function.
We advise on new processing activities, systems, agreements, personal data breaches and data protection impact assessments. We deliver role-based training and support teams in applying data protection requirements in everyday operations.
We act as a contact point for data subjects and the supervisory authority. We provide management with periodic reports on compliance, risks and recommendations without assuming the controller’s legal responsibility.
Personal data breach support
We support the controller in promptly establishing the facts, assessing risk, making decisions and documenting the entire response.
We help limit the impact, preserve evidence and establish the sequence, scope and time at which the breach became known. We identify the systems, data, individuals, recipients and entities involved in the event.
We assess whether a personal data breach has occurred and analyse the likelihood and severity of consequences for individuals’ rights and freedoms. We document the criteria, available facts and reasons supporting the assessment.
We prepare a draft notification to the competent supervisory authority where the breach is likely to result in risk, and communications to individuals where the risk is high. We support coordination with processors, recipients and other parties involved.
We complete the breach register, define corrective actions and monitor their implementation. We analyse root causes, update procedures and safeguards, and prepare evidence demonstrating an appropriate response.
Data protection by design
We help design solutions in accordance with data protection principles throughout conception, implementation and subsequent development.
We define project objectives, participant roles, data categories, sources, recipients, systems, data flows and retention periods. We assess legal bases, data necessity and requirements concerning data subject rights.
We perform a risk analysis for individuals’ rights and freedoms, considering the nature, scope, context and purposes of processing. We also assess whether the project requires a data protection impact assessment — DPIA.
We select legal, organisational and technical measures such as data minimisation, access restriction, retention controls, pseudonymisation and privacy-protective defaults. Recommendations become project requirements and acceptance criteria.
We verify the implementation and effectiveness of agreed safeguards before launch and following material changes. We document decisions, test results, residual risks and accountability for continued monitoring.
Control areas
Legal bases, consent, transparency notices, data minimisation and data subject rights.
Records of processing, authorisations, retention, disclosures, processors, transfers and change management.
Organisational and technical measures, risk analysis, breach registers, implementation evidence and corrective-action oversight.
Frequently asked questions
A GDPR audit assesses actual processing against the GDPR and applicable national law. It should identify specific nonconformities, assess risk and define a prioritised action plan.
No. The requirement depends on the criteria in Article 37 GDPR, including the nature of activities and the scale of regular monitoring or processing of special-category data. Each case requires an individual assessment.
The DPO informs and advises, monitors compliance, supports impact assessments, cooperates with the supervisory authority and acts as a contact point. The controller’s responsibility is not transferred to the DPO.
Where a personal data breach is likely to result in a risk to individuals, the controller must generally notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Every event requires a documented assessment.
Yes, to the extent required to assess risk and the adequacy of safeguards. We combine legal analysis with verification of processes, access, backups, incident response and supplier oversight.
Related areas
Systematic management of risk, assets, access, incidents and business continuity.
Learn more →Cyber resilience, management accountability, suppliers and incident reporting.
Learn more →Read the official text of the General Data Protection Regulation on EUR-Lex.
Learn more →Official information from the Polish supervisory authority about breaches, DPOs, inspections and controller obligations.
Learn more →Contact us for a free 30-minute initial consultation.
Book a consultation ↗