Contact Deutsch

ISiCO GmbH
Skip navigation
  • Privacy

    Get a head start with our optimal data protection consultancy

    Secure your competitive advantage with our business-focused data protection expertise.

    • Data Protection Consulting
      • Data Protection Impact Assessment (DPIA)
      • Threat Modelling
      • Data Breaches
      • Records of Processing Activities (ROPA)
      • Communication & Procedures with Authorities
      • Employee Data Protection
      • Data Protection Management System
      • Erasure and Archiving Policies
    • External Data Protection Officer
    • Data Protection Audits
    • EU Representative
    • Whistleblower Protection Act
  • IT Security

    Reliable protection for your company

    Make use of our expertise and customised IT security solutions to protect your digital assets.

    • External Information Security Officer (ISO)
    • ISMS
      • ISMS Service Package
      • ISMS Service Package NIS2
      • ISMS Service Package ISO 27001
      • ISMS Service Package TISAX
    • ISO 27001 Certification
    • Ransomware Protection
    • Risk Management
    • IT Compliance
    • NIS2
    • DORA
    • TISAX Certification
    • IT Forensics
    • Cyber Resilience Act
    • Aerospace & Defense
  • AI Consulting

    Gain a competitive edge with the best AI advice

    Secure your competitive advantage with our business-focused AI expertise.

    • ISO 42001 Certification
    • External AI Officer
  • Data Strategy

    Make the most of your data

    We will show you how to unlock the full potential of your company's data.

    • Develop Data Strategy
    • Maturity Assessment
    • Data Governance
    • Data Product
  • Solutions

    We create solutions for all challenges

    Whether you need advice on data protection management, its implementation, or employee training, we can provide the solution you need as part of a corporate network.

    • Downloads
    • Workshops
    • DPO Coaching
    • Privacy Solution Software caralegal
    • E-Learning from lawpilots
  • Company

    Customised, efficient and business-oriented

    ISiCO is one of the top addresses in Germany for management consultancy in data protection, information security, AI and data strategies.

    • About ISiCO
    • Team
    • Offices
    • News
    • Contact
  • Make an appointment

21.09.2026

GDPR Data Protection Audit: Audit-ready in 7 Steps

A data protection audit systematically checks whether your organisation processes personal data in accordance with the GDPR. Whilst the GDPR does not explicitly require such an audit, its obligations regarding evidence and verification make it, in practice, indispensable. We outline the process, provide a questionnaire and a self-assessment checklist including a guide available for download.

Download the guide and checklist now
Your ISiCO-Expert:
Jacqueline Neiazy
Partner Data Protection, Managing Director

What is a data protection audit?

A data protection audit, also referred to as a GDPR audit or data protection auditing, is a structured analysis and assessment of a company’s data protection compliance: it identifies where your data processing meets the requirements of the GDPR and where gaps exist.

The audit covers three levels: documentation, such as the record of processing activities, policies and data processing agreements; lived processes, such as handling data subject requests, data breaches and training; and the technical and organisational measures (TOMs) under Article 32 GDPR.

Depending on the focus, there are special forms of audit: a TOM audit specifically assesses the level of protection provided by security measures, a DPO audit assesses the effective involvement of the data protection officer, and a software audit examines individual applications. A full data protection audit brings these perspectives together.

The result is not an end in itself: the audit report forms the basis for your data protection concept and makes data protection manageable — with prioritised measures instead of isolated individual actions. The data protection audit is therefore an assessment of your current data protection level and the starting point for any robust data protection organisation.

Is a data protection audit mandatory?

The GDPR does not contain a provision that expressly requires a “data protection audit” — but in practice, an obligation to review nevertheless exists. It follows from the interaction of three provisions:

  • Article 5(2) GDPR, accountability: you must not only ensure compliance with the data protection principles, but also be able to demonstrate it.
  • Article 24 GDPR: the controller must implement appropriate measures and review and update them.
  • Article 32(1)(d) GDPR: companies need a process for regularly testing, assessing and evaluating the effectiveness of their technical and organisational measures.

Anyone who never conducts a structured review will simply be unable to prove, in the event of an authority request, that their own measures are effective. A documented audit fulfils precisely this evidentiary function — and supervisory authorities take the technical and organisational measures implemented into account when calculating fines under Article 83(2) GDPR.

An example to draw the distinction: an online retailer that never carries out an audit does not automatically violate the GDPR. However, if a data breach occurs, it has no audit reports to show and will hardly be able to counter an allegation of negligence.

No express requirement, but a factual obligation: anyone who takes accountability seriously cannot avoid regular data protection audits.

Free expertise in your e-mail inbox

All the important news on data protection, information security, AI and data strategy conveniently delivered to your e-mail inbox once a month - free of charge, of course. (Currently only available in German)

Please add 8 and 9.

By clicking on the button, you consent to receiving our newsletter and to the aggregated usage analysis (opening rate and link clicks). You can revoke your consent at any time, e.g. via the unsubscribe link in the newsletter. More information: Privacy policy.

When should you conduct a data protection audit?

A data protection audit is useful whenever you do not have a reliable picture of the current state of your data protection and in certain situations it is particularly urgent.

Checklist: These occasions indicate that an audit is advisable:

  • There has never been a structured review, or the last one was more than a year ago.
  • There are doubts about the effectiveness of the data protection management system, the record of processing activities, the erasure concept or the processes for data subject requests.
  • Extensive processing by processors – many service providers, unclear responsibilities.
  • Introduction of new systems or AI applications that process personal data.
  • Indications of security gaps or a past data protection incident.
  • Upcoming corporate transaction, due diligence or certification project.
  • Data-intensive areas without specific safeguards such as HR, marketing or sales.

If several points apply, an audit is worthwhile in the near term – the earlier you know the current state, the more systematically you can act. The rule of thumb is: at least annually, and immediately where there is a specific occasion.

How does a data protection audit work? The 7-step process

A professional data protection audit follows a clear seven-step process. From preparation through to the review loop.

  1. Preparation and scoping: define the objective and scope, the entire company or individual areas? Internal audit, external review or certification preparation? The audit plan follows from the scope.
  2. Kick-off and responsibilities: appoint contacts in each specialist department, agree the timeline, compile relevant documents, such as the record of processing activities, policies, data processing agreements, TOM documentation and training records.
  3. Current-state analysis: the core element. The auditor works with questionnaires, conducts interviews with key people from IT, HR, marketing and sales, and reviews samples such as consent declarations or erasure runs. In an on-site data protection inspection, physical controls are added: server rooms, access controls and clean-desk practice. Every finding is documented in the audit record.
  4. Analysis and assessment: the results are compared with the GDPR target state. Risks are classified according to likelihood and severity from “low” to “critical”.
  5. Audit report with catalogue of measures: the report documents the status quo, identifies gaps and prioritises specific recommendations for action. It also serves as your evidence document vis-à-vis the supervisory authority.
  6. Implementation of measures: the catalogue of measures becomes an action plan with owners and deadlines — covering legal adjustments, such as consent wording, as well as technical measures, such as access concepts.
  7. Review loops and follow-up: a follow-up audit checks whether the measures are effective. This closes the loop with the regular review required under Article 32(1)(d) GDPR.

Seven steps and at the end, a documented, prioritised roadmap instead of a vague assessment.

Data protection audit questionnaire: the audit questions you can expect

The questionnaire is the central tool of every data protection audit it translates the GDPR requirements into specific audit questions. This selection shows what you can expect:

Audit area Audit questions
Data protection organisation and documentation

Has a data protection officer been appointed and is the appointment required at all?

Is the record of processing activities complete and up to date?

Are documented data protection policies in place, and are employees familiar with them?

Legal bases and consent

Is there a documented legal basis for each processing activity?

Is consent obtained in a demonstrable way and can it be withdrawn just as easily?

Processing by processors

Are current data processing agreements under Article 28 GDPR in place with all service providers?

Are third-country transfers safeguarded, for example through standard contractual clauses and a transfer impact assessment?

Technical and organisational measures

Are access rights assigned and documented according to the need-to-know principle?

Are data stored and transmitted in encrypted form, and are tested backups in place?

When was the effectiveness of the TOMs last reviewed?

Data subject rights and erasure

Is there a defined process for responding to access and erasure requests within the applicable deadlines?

Is there an erasure concept with specific deadlines and is it technically implemented?

Data breaches and training

Is it defined who reports a data breach to the authority within 72 hours?

Are employees trained regularly, and is this documented?

If you cannot confidently answer “yes” to several of these questions, you have already found your first audit findings. The full questionnaire with assessment matrix is included in our guide for download.

The questionnaire makes the audit concrete. Anyone who goes through the questions in advance knows their weaknesses before the auditor does.

Who may conduct a data protection audit?

The question remains: who conducts the audit? A data protection audit may be carried out by internal or external auditors. The decisive factors are qualification and independence. The auditor must not be responsible for the processes they assess.

Internally, the data protection officer is the main option: monitoring compliance with the GDPR is part of their duties under Article 39 GDPR in any event. Internal audits reach their limits where operational blindness or conflicts of interest may arise for example, where the DPO helped design the processes they are supposed to audit.

Externally, a specialised consultancy or an external data protection officer audits with a neutral perspective and experience from many companies and industries. This increases the evidential value of the report also vis-à-vis customers and business partners who want to see independent evidence.

Certification under Article 42 GDPR plays a special role: if the audit is intended to lead to an official data protection certificate, this is issued by an accredited certification body under Article 43 GDPR or by the competent supervisory authority.

An internal audit is therefore possible; an external audit is more independent and for an official certificate, the route is through an accredited body or the supervisory authority.

Self-audit: conducting a data protection audit yourself

A self-audit under the GDPR is the structured self-check of your data protection organisation useful as a status assessment and preparation, but limited as sole evidence.

This is how to proceed: use a checklist, sample or template as an audit grid, such as the questionnaire above, work through the audit areas department by department, document every answer with supporting evidence and derive a measure with an owner and deadline from every “no”. Even a properly documented self-audit is more evidence than most companies can provide.

The limits lie in objectivity: anyone assessing their own processes will systematically overlook the gaps they have created themselves. For robust results for example before certification, after an incident or in due diligence, an external perspective is needed.

The combination has proven effective: a self-audit as preparation, an external audit as validation. This gives the external auditors a clean basis to start from, and the audit becomes significantly more efficient.

The self-audit is the right first step but it does not replace an independent review where evidence matters.

Conclusion: the GDPR audit makes data protection manageable

A data protection audit is not a bureaucratic mandatory appointment, but the instrument with which you fulfil your accountability obligation and make data protection plannable. Although the GDPR does not require an audit by name, it does require evidence of effective measures and only a structured, documented review provides that evidence.

The path to get there is clear: seven steps and a specific questionnaire. With a self-audit, you lay the foundation; with an external GDPR audit, you make the result robust vis-à-vis authorities as well as customers, who increasingly make data protection a selection criterion.

Your solution for the best data protection

Trust is the foundation of every good business relationship. Strengthen your relationships with customers by leveraging our expertise in data protection. This will give your company a strong competitive advantage, allowing you to focus fully on your business.

Book your appointment now

Frequently asked questions

#1 How often should a data protection audit take place?

As a rule of thumb: one full data protection audit per year; for low-risk processing activities, at least every two years. In addition, you should carry out event-driven reviews for example when new systems are introduced, AI is implemented, data breaches occur or significant processes change. The GDPR does not specify a deadline, but requires “regular” testing and evaluation under Article 32(1)(d) GDPR.

#2 What is the difference between a data protection audit and an ISO 27001 audit?

A data protection audit examines the GDPR compliance of the processing of personal data; an ISO 27001 audit examines the information security of all company assets. The two overlap in relation to technical measures, but pursue different objectives: legal compliance in data protection versus certifiable security management. In practice, both audits complement each other and can be conducted in a coordinated manner.

#3 What is the Data Protection Audit Act?

There is no standalone Data Protection Audit Act in Germany. Section 9a of the old German Federal Data Protection Act did envisage such a law, but it was never adopted. Today, certification under Article 42 GDPR performs this function: it enables companies to have their data protection compliance officially confirmed.

#4 What belongs in the audit report?

The audit report documents the audit scope, methodology, findings and prioritised recommendations for action. Specifically: which areas and processes were audited, which deviations were identified with which risk classification, and which measures must be implemented in which order. It therefore also serves as evidence for supervisory authorities and business partners.

#5 Can I have a data protection audit certified?

Yes through certification under Article 42 GDPR, issued by an accredited certification body under Article 43 GDPR or by the competent supervisory authority. The certificate officially confirms the GDPR compliance of audited processing activities, is voluntary and is valid for a maximum of three years. A regular data protection audit by an external consultant is the typical preparation for this, but does not replace official certification.

Back to the news overview

Berlin
Köln
München

Ready for the next step?

+49 30 21300285-0
info@isico.de

Directly to get to know us

 

Outstanding work

ISiCO is also an active member of the German Association for Data Protection and Data Security (GDD) and the German Association for Information Technology, Telecommunications and New Media (Bitkom).

Top-Links
Skip navigation
  • External Data Protection Officer
  • Data Protection Management System
  • Data Strategy
  • Data Breaches
  • ISMS
Find out more
Skip navigation
  • About ISiCO
  • Contact

Language

DE EN

© ISiCO GmbH | Contact | Imprint | Privacy | Privacy Settings