Analysis

A GDPR audit is not a legal audit

Compliance is not settled in the paperwork but in what is actually done with data. An audit that looks only at the former reassures without protecting.

Three European flags fly in front of the glass façade of an office building
The regulation sets the frame; the audit looks at what is actually processed

Plenty of organisations have had a GDPR audit. Few can say what it changed. That is the symptom of a misunderstanding about the exercise: it was commissioned as a document review, and delivered as one.

The result is a report comparing your paperwork with the text of the regulation. It is accurate. It says nothing about what your organisation actually does.

The gap that matters

Compliance is not established from the record of processing. It is established from the gap between what that record describes and what actually happens:

  • data collected by a form nobody declared
  • an export file sitting on a laptop for four years, outside any deletion policy
  • a tool bought directly by one department, going through neither the framework agreement nor anyone else
  • a retention period stated as three years, applied indefinitely for want of any deletion mechanism

None of these four appears in a document review. All of them appear as soon as you ask teams about what they actually do.

What to insist on as a deliverable

An audit whose conclusion is a compliance percentage cannot be acted on. What can be acted on is a set of qualified gaps:

  • the list of undeclared processing, with the purpose observed
  • how each processor is classified, and the state of the corresponding data processing agreement
  • retention periods, together with the mechanism that enforces them — or the finding that there is none
  • for every gap: the action, the person accountable, the deadline
An audit that produces a percentage reassures. An audit that produces a list of dated actions commits someone.

The lawyer’s role, and its limit

Legal analysis remains necessary: establishing a lawful basis, assessing a transfer outside the European Union, weighing legitimate interest. But it works on facts, and facts are not gathered from legal texts.

That is why an audit given only to a law firm produces an excellent analysis of an incomplete scope, and an audit given only to a technician produces an inventory with no legal reading. The exercise needs both, in that order: establish the facts, then classify them.

Where to start

In a company with no designated officer, this work looks like it has no starting point. It has one: four workstreams, in a precise order, the first of which is documentary rather than legal.

Qualifying processors is only half the subject. The other half is contractual: what the data processing agreement must contain.

With the processing that touches the most people and the most sensitive data — not with whatever is best documented. The natural instinct is to start where you are on firm ground; do the opposite, because that is precisely where there is nothing to find.

Common questions

How do you carry out a useful GDPR audit?

By comparing what the record of processing describes with what teams actually do. The gaps — an undeclared form, an export kept for years, a tool signed up for directly, a retention period never applied — only show up in interviews, not in a document review.

Who can carry out a GDPR audit?

It takes two skills, in this order: establish the facts, then qualify them. An audit left to a lawyer alone analyses an incomplete scope; left to a technician alone, it produces an inventory with no legal qualification. Legal analysis works on facts that must be gathered first.

What should a GDPR audit deliver?

Qualified gaps rather than a compliance percentage: undeclared processing and its purpose, the status of each processor and its processing agreement, retention periods and the mechanism that enforces them, and for each gap an action, an owner and a deadline.


Next article

The exit clause you will wish you had written

Read

A transformation to support?