What is a data protection audit?
A data protection audit, also referred to as a GDPR audit or data protection auditing, is a structured analysis and assessment of a company’s data protection compliance: it identifies where your data processing meets the requirements of the GDPR and where gaps exist.
The audit covers three levels: documentation, such as the record of processing activities, policies and data processing agreements; lived processes, such as handling data subject requests, data breaches and training; and the technical and organisational measures (TOMs) under Article 32 GDPR.
Depending on the focus, there are special forms of audit: a TOM audit specifically assesses the level of protection provided by security measures, a DPO audit assesses the effective involvement of the data protection officer, and a software audit examines individual applications. A full data protection audit brings these perspectives together.
The result is not an end in itself: the audit report forms the basis for your data protection concept and makes data protection manageable — with prioritised measures instead of isolated individual actions. The data protection audit is therefore an assessment of your current data protection level and the starting point for any robust data protection organisation.
Is a data protection audit mandatory?
The GDPR does not contain a provision that expressly requires a “data protection audit” — but in practice, an obligation to review nevertheless exists. It follows from the interaction of three provisions:
- Article 5(2) GDPR, accountability: you must not only ensure compliance with the data protection principles, but also be able to demonstrate it.
- Article 24 GDPR: the controller must implement appropriate measures and review and update them.
- Article 32(1)(d) GDPR: companies need a process for regularly testing, assessing and evaluating the effectiveness of their technical and organisational measures.
Anyone who never conducts a structured review will simply be unable to prove, in the event of an authority request, that their own measures are effective. A documented audit fulfils precisely this evidentiary function — and supervisory authorities take the technical and organisational measures implemented into account when calculating fines under Article 83(2) GDPR.
An example to draw the distinction: an online retailer that never carries out an audit does not automatically violate the GDPR. However, if a data breach occurs, it has no audit reports to show and will hardly be able to counter an allegation of negligence.
No express requirement, but a factual obligation: anyone who takes accountability seriously cannot avoid regular data protection audits.
Free expertise in your e-mail inbox
All the important news on data protection, information security, AI and data strategy conveniently delivered to your e-mail inbox once a month - free of charge, of course. (Currently only available in German)
When should you conduct a data protection audit?
A data protection audit is useful whenever you do not have a reliable picture of the current state of your data protection and in certain situations it is particularly urgent.
Checklist: These occasions indicate that an audit is advisable:
- There has never been a structured review, or the last one was more than a year ago.
- There are doubts about the effectiveness of the data protection management system, the record of processing activities, the erasure concept or the processes for data subject requests.
- Extensive processing by processors – many service providers, unclear responsibilities.
- Introduction of new systems or AI applications that process personal data.
- Indications of security gaps or a past data protection incident.
- Upcoming corporate transaction, due diligence or certification project.
- Data-intensive areas without specific safeguards such as HR, marketing or sales.
If several points apply, an audit is worthwhile in the near term – the earlier you know the current state, the more systematically you can act. The rule of thumb is: at least annually, and immediately where there is a specific occasion.
How does a data protection audit work? The 7-step process
A professional data protection audit follows a clear seven-step process. From preparation through to the review loop.
- Preparation and scoping: define the objective and scope, the entire company or individual areas? Internal audit, external review or certification preparation? The audit plan follows from the scope.
- Kick-off and responsibilities: appoint contacts in each specialist department, agree the timeline, compile relevant documents, such as the record of processing activities, policies, data processing agreements, TOM documentation and training records.
- Current-state analysis: the core element. The auditor works with questionnaires, conducts interviews with key people from IT, HR, marketing and sales, and reviews samples such as consent declarations or erasure runs. In an on-site data protection inspection, physical controls are added: server rooms, access controls and clean-desk practice. Every finding is documented in the audit record.
- Analysis and assessment: the results are compared with the GDPR target state. Risks are classified according to likelihood and severity from “low” to “critical”.
- Audit report with catalogue of measures: the report documents the status quo, identifies gaps and prioritises specific recommendations for action. It also serves as your evidence document vis-à-vis the supervisory authority.
- Implementation of measures: the catalogue of measures becomes an action plan with owners and deadlines — covering legal adjustments, such as consent wording, as well as technical measures, such as access concepts.
- Review loops and follow-up: a follow-up audit checks whether the measures are effective. This closes the loop with the regular review required under Article 32(1)(d) GDPR.
Seven steps and at the end, a documented, prioritised roadmap instead of a vague assessment.
Data protection audit questionnaire: the audit questions you can expect
The questionnaire is the central tool of every data protection audit it translates the GDPR requirements into specific audit questions. This selection shows what you can expect:
| Audit area | Audit questions |
|---|---|
| Data protection organisation and documentation |
Has a data protection officer been appointed and is the appointment required at all? Is the record of processing activities complete and up to date? Are documented data protection policies in place, and are employees familiar with them? |
| Legal bases and consent |
Is there a documented legal basis for each processing activity? Is consent obtained in a demonstrable way and can it be withdrawn just as easily? |
| Processing by processors |
Are current data processing agreements under Article 28 GDPR in place with all service providers? Are third-country transfers safeguarded, for example through standard contractual clauses and a transfer impact assessment? |
| Technical and organisational measures |
Are access rights assigned and documented according to the need-to-know principle? Are data stored and transmitted in encrypted form, and are tested backups in place? When was the effectiveness of the TOMs last reviewed? |
| Data subject rights and erasure |
Is there a defined process for responding to access and erasure requests within the applicable deadlines? Is there an erasure concept with specific deadlines and is it technically implemented? |
| Data breaches and training |
Is it defined who reports a data breach to the authority within 72 hours? Are employees trained regularly, and is this documented? |
If you cannot confidently answer “yes” to several of these questions, you have already found your first audit findings. The full questionnaire with assessment matrix is included in our guide for download.
The questionnaire makes the audit concrete. Anyone who goes through the questions in advance knows their weaknesses before the auditor does.
Who may conduct a data protection audit?
The question remains: who conducts the audit? A data protection audit may be carried out by internal or external auditors. The decisive factors are qualification and independence. The auditor must not be responsible for the processes they assess.
Internally, the data protection officer is the main option: monitoring compliance with the GDPR is part of their duties under Article 39 GDPR in any event. Internal audits reach their limits where operational blindness or conflicts of interest may arise for example, where the DPO helped design the processes they are supposed to audit.
Externally, a specialised consultancy or an external data protection officer audits with a neutral perspective and experience from many companies and industries. This increases the evidential value of the report also vis-à-vis customers and business partners who want to see independent evidence.
Certification under Article 42 GDPR plays a special role: if the audit is intended to lead to an official data protection certificate, this is issued by an accredited certification body under Article 43 GDPR or by the competent supervisory authority.
An internal audit is therefore possible; an external audit is more independent and for an official certificate, the route is through an accredited body or the supervisory authority.
Self-audit: conducting a data protection audit yourself
A self-audit under the GDPR is the structured self-check of your data protection organisation useful as a status assessment and preparation, but limited as sole evidence.
This is how to proceed: use a checklist, sample or template as an audit grid, such as the questionnaire above, work through the audit areas department by department, document every answer with supporting evidence and derive a measure with an owner and deadline from every “no”. Even a properly documented self-audit is more evidence than most companies can provide.
The limits lie in objectivity: anyone assessing their own processes will systematically overlook the gaps they have created themselves. For robust results for example before certification, after an incident or in due diligence, an external perspective is needed.
The combination has proven effective: a self-audit as preparation, an external audit as validation. This gives the external auditors a clean basis to start from, and the audit becomes significantly more efficient.
The self-audit is the right first step but it does not replace an independent review where evidence matters.
Conclusion: the GDPR audit makes data protection manageable
A data protection audit is not a bureaucratic mandatory appointment, but the instrument with which you fulfil your accountability obligation and make data protection plannable. Although the GDPR does not require an audit by name, it does require evidence of effective measures and only a structured, documented review provides that evidence.
The path to get there is clear: seven steps and a specific questionnaire. With a self-audit, you lay the foundation; with an external GDPR audit, you make the result robust vis-à-vis authorities as well as customers, who increasingly make data protection a selection criterion.
Your solution for the best data protection
Trust is the foundation of every good business relationship. Strengthen your relationships with customers by leveraging our expertise in data protection. This will give your company a strong competitive advantage, allowing you to focus fully on your business.
Frequently asked questions
#1 How often should a data protection audit take place?
As a rule of thumb: one full data protection audit per year; for low-risk processing activities, at least every two years. In addition, you should carry out event-driven reviews for example when new systems are introduced, AI is implemented, data breaches occur or significant processes change. The GDPR does not specify a deadline, but requires “regular” testing and evaluation under Article 32(1)(d) GDPR.
#2 What is the difference between a data protection audit and an ISO 27001 audit?
A data protection audit examines the GDPR compliance of the processing of personal data; an ISO 27001 audit examines the information security of all company assets. The two overlap in relation to technical measures, but pursue different objectives: legal compliance in data protection versus certifiable security management. In practice, both audits complement each other and can be conducted in a coordinated manner.
#3 What is the Data Protection Audit Act?
There is no standalone Data Protection Audit Act in Germany. Section 9a of the old German Federal Data Protection Act did envisage such a law, but it was never adopted. Today, certification under Article 42 GDPR performs this function: it enables companies to have their data protection compliance officially confirmed.
#4 What belongs in the audit report?
The audit report documents the audit scope, methodology, findings and prioritised recommendations for action. Specifically: which areas and processes were audited, which deviations were identified with which risk classification, and which measures must be implemented in which order. It therefore also serves as evidence for supervisory authorities and business partners.
#5 Can I have a data protection audit certified?
Yes through certification under Article 42 GDPR, issued by an accredited certification body under Article 43 GDPR or by the competent supervisory authority. The certificate officially confirms the GDPR compliance of audited processing activities, is voluntary and is valid for a maximum of three years. A regular data protection audit by an external consultant is the typical preparation for this, but does not replace official certification.