GDPR Audit Step by Step — What Does It Look Like?
Many companies know that they should periodically review their GDPR compliance. Far fewer organisations, however, know what such an audit looks like in practice. The same questions usually arise. How long does an audit take? What documents should be prepared? Who should participate? And most importantly — what does the company receive at the end?
A well-conducted audit is not limited to reviewing documentation. Its purpose is to determine whether the organisation’s actual data processing practices comply with the GDPR. It therefore helps identify gaps before they emerge during an inspection, a personal data breach or a complaint from a data subject. In this article, I explain the practical side of a GDPR audit. I describe its main stages, the preparation required and the results and recommendations an organisation should receive.
Why Conduct a GDPR Audit?
An audit can be treated as a compliance review carried out on the organisation’s own terms. Instead of waiting for questions from the supervisory authority, the organisation reviews its own processes. This allows it to identify risks earlier and plan how to address them.
A good audit should provide three main outcomes. First, it shows the organisation’s actual level of compliance. Second, it identifies areas that require improvement. Third, it helps determine which actions should have the highest priority. This is particularly important when a company develops new services, changes systems or works with many suppliers and subcontractors. An audit also helps organise documentation. In practice, the problem is often not the complete absence of procedures, but outdated documents or procedures that no longer reflect reality.
Step 1. Initial Discussion and Defining the Scope
The audit begins with understanding the organisation. At the first stage, the auditor identifies the business profile, scale of processing, number of employees, systems used and main categories of personal data. It is also important to understand how many entities receive data from the organisation or provide services to it. Only then can the scope of the audit be properly defined.
In some cases, the audit will cover the entire organisation. In others, it may focus only on selected areas, such as HR, marketing, monitoring or e-commerce. At this stage, it is also useful to identify contact persons and agree how documents will be shared. If necessary, the parties may also enter into a confidentiality undertaking.
Step 2. Inventory and Mapping of Processing Activities
This is one of the most important stages of the audit. First, it is necessary to determine what personal data the organisation actually processes. The next step is to establish where the data come from, why they are used and to whom they are disclosed. The way data are stored and the applicable retention periods should also be reviewed.
Information may be collected through questionnaires, interviews with employees and analysis of the systems used. It is important to involve people who genuinely understand the relevant process. A discussion with management or the legal department alone is often not enough. The result of this stage should be a structured map of processing activities. This becomes the reference point for the rest of the audit.
Step 3. Review of GDPR Documentation
The next stage involves reviewing existing documentation. The auditor checks, among other things, the records of processing activities, privacy notices, data processing agreements and authorisations. Procedures concerning personal data breaches, data subject rights, retention and the use of systems and devices are also reviewed.
However, the purpose is not simply to determine whether a document exists. It is equally important to check whether the document is current and reflects how the organisation actually operates. A gap between documentation and practice is one of the most common issues identified during audits. A company may have an extensive data protection policy while applying completely different operational rules.
Step 4. Legal Bases and Compliance of Processing Activities
Once the actual processing activities have been identified, their compliance with the GDPR can be assessed. The key question is whether each processing operation has an appropriate legal basis. This may include performance of a contract, compliance with a legal obligation, legitimate interests or consent. Where special categories of personal data are involved, the conditions under Article 9 GDPR must also be considered.
The audit also reviews how consent is obtained and whether individuals can withdraw it effectively. Where the organisation relies on legitimate interests, it is worth checking whether an appropriate balancing test has been carried out.
Transparency obligations and the handling of data subject rights should also be verified. The aim is to establish whether individuals can effectively access their data, correct them, request deletion or object to processing.
Step 5. Data Security and Measures Under Article 32 GDPR
The audit should also cover data security. However, this does not mean only a technical review of IT infrastructure. The GDPR requires organisations to implement technical and organisational measures appropriate to the level of risk. The audit may therefore review access controls, password management, encryption, backups and the use of mobile devices.
Incident response procedures and the handling of personal data breaches are also important. The assessment should reflect the organisation’s actual risk profile. Different measures will be appropriate for a small service company and for a large organisation processing health data.
At this stage, it is also worth determining whether any processing activities require a Data Protection Impact Assessment.
Step 6. Areas of Particular Risk
Every organisation has areas that require more detailed analysis. In one company, this may be employee monitoring. In another, it may be marketing, profiling or the use of artificial intelligence. The audit may also cover transfers outside the EEA, employee data, cookies, cloud services or cooperation with processors.
If the organisation has a DPO, it is also worth reviewing the officer’s role and independence. Sector-specific legislation may also be relevant. For this reason, an audit should not look identical in every organisation. Its scope should reflect the actual processing activities and risks.
Step 7. Audit Report
Once the analysis is complete, the organisation should receive an audit report. A good report is not simply a list of identified errors. It should show which areas work properly, which require improvement and which create the greatest risk. For this reason, findings should be assigned an appropriate level of significance. Risks may, for example, be classified as high, medium or low. This allows management to set priorities more effectively.
The report should also clearly explain why a particular issue requires action. The aim is not to create another formal document, but to provide a practical compliance management tool.
Step 8. Remediation Plan
A report alone is not enough. The greatest value comes from translating findings into specific actions. For this reason, an audit should end with a remediation plan. The plan identifies what should be changed, in what order and which actions are most urgent. It may also include suggested deadlines and persons responsible for implementation.
This means that the organisation not only knows where the problem lies, but also how to resolve it. The audit then becomes a practical roadmap towards compliance.
Step 9. Discussing the Findings and Implementing Changes
The report should be discussed with the people responsible for decision-making. This helps explain the most important risks and agree a realistic implementation schedule. Some recommendations can be implemented quickly. Others may require changes to systems, procedures or contracts with suppliers.
In many cases, the audit therefore becomes the starting point for further work. This may include updating documentation, preparing new procedures or implementing additional safeguards. After some time, it is also worth checking whether the recommendations have actually been implemented.
What Does the Company Receive at the End of the Audit?
The final set of materials depends on the type of audit and the scope agreed with the client. The main deliverable should be an audit report. It presents the compliance status, identified gaps and an assessment of their significance. The second key element is a remediation plan. It explains what actions should be taken and in what order. It is also useful to identify quick corrective actions that can be implemented without significant cost or organisational change. Another benefit is greater readiness for a regulatory inspection. The organisation knows where gaps remain and can demonstrate that it is managing them consciously. If agreed, the next stage may also include preparing or updating missing documentation.
What Types of GDPR Audits Can Be Conducted?
A GDPR audit does not always have to involve a full review of the entire organisation. Its scope can be adjusted to a specific need.
An initial audit provides a comprehensive assessment of the current compliance status. A periodic audit checks whether previously implemented solutions still work effectively. An audit may also be carried out before introducing a new service, system or technology. Another option is an audit following a major organisational change or an audit aimed at preparing for a potential UODO inspection. In practice, the scope should reflect the scale of the organisation’s activities and its risk level.
How to Prepare for an Audit and How Long Does It Take?
The duration of an audit depends mainly on the size and complexity of the organisation. In a small company, the review may take a few days. In a large organisation, the audit may require several weeks. The number of processing activities, systems, external providers and locations all affect the timeframe.
The process is more efficient when key information is available from the beginning. It is worth preparing information about the number of employees, systems used, suppliers and existing documentation. It is also helpful to identify the people who know individual processes best. The better the organisation is prepared at the outset, the more precisely the scope and cost of the audit can be determined.
Common Mistakes Related to GDPR Audits
Postponing the audit until a problem occurs. A regulatory inspection or personal data breach is not the best moment for the first compliance review.
Treating an audit as a documentation purchase. A set of policies alone will not show whether the organisation’s processes actually work correctly.
A report without priorities. A long list of findings is not useful if the organisation does not know where to start.
Ignoring higher-risk areas. Monitoring, marketing, transfers or new technologies often require separate analysis.
Failing to implement recommendations. Even the best report will not improve compliance if it remains in a drawer.
GDPR Audit — Practical Checklist Before You Start
- Define the scope of the audit — the whole organisation or selected processes.
- Collect information about the main processing activities.
- Prepare a list of systems and suppliers, including cloud services, CRM systems, hosting and marketing tools.
- Gather current GDPR documentation, including records of processing activities, policies, privacy notices and data processing agreements.
- Identify contact persons who understand the relevant areas of the business.
- Identify areas of particular risk, such as monitoring, marketing, AI or transfers outside the EEA.
- Decide whether you also need support with implementing recommendations after the audit.
- Plan a follow-up review after remediation activities have been completed.
Do You Need a GDPR Audit for Your Company?
A GDPR audit allows an organisation to assess compliance before problems arise during an inspection, personal data breach or complaint. It also provides an opportunity to structure processes on the organisation’s own terms and according to clearly defined priorities.
At Dr Joanna Maniszewska-Ejsmont Law Firm, we conduct GDPR audits tailored to the scale, business profile and actual needs of each organisation. We analyse processing activities and documentation, review legal bases, security measures and cooperation with external entities. Depending on the organisation’s needs, we can also support the implementation of recommendations and prepare or update the required documentation.

Contact us — after a short discussion about your organisation, we will propose an appropriate audit scope and a transparent fee estimate.
