Plenty of organisations have had a GDPR audit. Few can say what it changed. That is the symptom of a misunderstanding about the exercise: it was commissioned as a document review, and delivered as one.
The result is a report comparing your paperwork with the text of the regulation. It is accurate. It says nothing about what your organisation actually does.
The gap that matters
Compliance is not established from the record of processing. It is established from the gap between what that record describes and what actually happens:
- data collected by a form nobody declared
- an export file sitting on a laptop for four years, outside any deletion policy
- a tool bought directly by one department, going through neither the framework agreement nor anyone else
- a retention period stated as three years, applied indefinitely for want of any deletion mechanism
None of these four appears in a document review. All of them appear as soon as you ask teams about what they actually do.
What to insist on as a deliverable
An audit whose conclusion is a compliance percentage cannot be acted on. What can be acted on is a set of qualified gaps:
- the list of undeclared processing, with the purpose observed
- how each processor is classified, and the state of the corresponding data processing agreement
- retention periods, together with the mechanism that enforces them — or the finding that there is none
- for every gap: the action, the person accountable, the deadline
An audit that produces a percentage reassures. An audit that produces a list of dated actions commits someone.
The lawyer’s role, and its limit
Legal analysis remains necessary: establishing a lawful basis, assessing a transfer outside the European Union, weighing legitimate interest. But it works on facts, and facts are not gathered from legal texts.
That is why an audit given only to a law firm produces an excellent analysis of an incomplete scope, and an audit given only to a technician produces an inventory with no legal reading. The exercise needs both, in that order: establish the facts, then classify them.
Where to start
With the processing that touches the most people and the most sensitive data — not with whatever is best documented. The natural instinct is to start where you are on firm ground; do the opposite, because that is precisely where there is nothing to find.