Data Protection Audit

Knowing where you really stand

Independent audit of your data protection organization with a report, assessment, and a list of actions sorted by urgency.

  • BenefitsConcrete result instead of a report – German: Audit report with evaluation and prioritized list of measures.
  • BenefitsTested by professionals: Certified data protection officers, lawyers and IT experts.
  • BenefitsRegular or occasional audits: From the individual topic to the entire organization – completely according to your wishes.
Example audit report: seven areas of testing, such as the processing inventory, deletion concept, and technical measures, each with a color rating from compliant to urgent.
ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany

✓ ISO 9001 certified

✓ on the market since 2003 ✓ from Berlin, active worldwide

The occasion

Most audits begin with one of these three situations:

Hardly anyone orders a data protection audit out of pure interest. There is almost always a specific trigger – and that determines what we look at first.

1

Someone demands proof

A large customer, an investor, or the parent company wants to see that your data protection system works. They have documents, but nothing that they can present to you.

2

Data protection grew organically rather than by design

The list of processing activities dates back to the introduction phase; since then, new tools, new service providers, and AI applications have been added. No one knows what is still true.

3

Something has happened

A data breach, a complaint, or a request from the supervisory authority. Now it must be clear quickly and reliably where the gaps are and which ones need to be closed first.

The result

What you get at the end

An audit is only worth something if it leads to action. That’s why ours doesn’t end with a description of the situation, but with a list that you can work through.

  • BenefitsAudit report with evaluation
    Each area that has been examined receives a comprehensible classification with a reason, not just a grade.
  • BenefitsPrioritized list of measures
    Sorted by risk and effort. You can see at a glance what’s on this week and what time you have.
  • BenefitsFinal interview
    We are going through the report with your managers so that the measures are understood and not just filed away.
Example audit report: seven areas of testing, such as the processing inventory, deletion concept, and technical measures, each with a color rating from compliant to urgent.

The process

Four steps – not a project marathon

The most common concern about an audit is not the result, but the expense. Therefore, we keep your share as small as possible.

Step 01

Analysis

We will jointly determine what is being reviewed, what the reason behind it is, and which areas are prioritized.

free of charge · approx. 45 min.

Step 02

Documents & Interviews

They provide existing documents; we speak with the responsible parties from IT, HR, and specialist departments. On-site or remotely.

about 4–6 hours of your time

Step 03

Analysis & Evaluation

We compare the current situation with the legal requirements and recommend concrete measures.

about 2 weeks

Step 04

Report & debrief

You will receive the audit report and we will go through it together. Including a recommendation on the order in which you can address the issues.

Closure

Step 01

Scoping discussion

We will jointly determine what is being reviewed, what the reason behind it is, and which areas are of priority. After that, you will receive a quote with a fixed scope.

free of charge · approx. 45 min.

Step 02

Documents & Interviews

They provide existing documents; we speak with the responsible parties from IT, HR, and specialist departments. On-site or remotely.

about 4–6 hours of your time

Step 03

Analysis & Evaluation

We compare the current situation with the requirements of the GDPR, assess each area and propose concrete measures. We are responsible for this part alone.

about 2 weeks

Step 04

Report & debrief

You will receive the audit report and we will go through it together – including a recommendation on the order in which you should address the issues.

Closure

The cut

Three packages – you choose the audit scope

In all packages

Multilingual support

Personal contact person

Certified Data Protection Officers

Individual topic

Data protection audit for a single topic – depending on your individual requirements and needs.

individual

Offer

upon request

  • Examination of the current state of the implemented data protection measures in the selected topic
  • Audit report documenting the current state of the data protection situation
  • Drawing appropriate measures from identified deficiencies, risks, and weaknesses
  • Occasional implementation

Sub-area

Popular

Data protection audit for selected areas of your organization – tailored to your requirements.

individual

Offer

upon request

  • Examination of the current state of the implemented data protection measures in the selected sub-area
  • Audit report documenting the current state of the data protection situation
  • Drawing appropriate measures from identified deficiencies, risks, and weaknesses
  • Occasional or regular implementation

Entire organization

Data protection audit for the entire organization – as a starting point for continuous improvement processes.

individual

Offer
upon request

  • Examination of the current state of the implemented data protection measures throughout the organization
  • Data protection review or audit report documenting and certifying the current state
  • Drawing appropriate measures from identified deficiencies, risks, and weaknesses
  • Occasional or regular implementation

Who is checking

An audit is only as good as the people who carry it out.

Data protection is rarely just a legal issue. When it comes to deletion routines, log data, or AI systems, you need someone who understands the technology behind it. At us, both perspectives are in the same house.

2003

Specializing in data protection for over two decades

TÜV

Certified Data Protection Officers on the team

5

Disciplines under one roof: Data protection, law, information security, artificial intelligence and software development

What customers ask before the audit

How much does a data protection audit cost?

The price depends on the size of the piece. After the free initial consultation, you will receive a quote.


How much work is involved for us?

We take on most of the work. On your side, we need existing documents and around four to six hours for discussions with the responsible parties.


What happens if the audit finds serious deficiencies?

Then you have achieved exactly what an audit is intended to achieve. You decide what to implement in what order; if desired, we can accompany you in the process.

Is a data protection audit legally required?

An audit as such is not required. However, GDPR it includes various requirements for auditing and verification, in particular accountability and the review and, if necessary, updating of the measures taken. For the security of processing, Article 32(1)(d GDPR) explicitly requires a procedure for the regular review, assessment and evaluation of the effectiveness of technical and organizational measures. An audit can contribute to this, but is neither the most practical nor the legally prescribed way. If a data protection officer has been appointed, the monitoring of compliance with GDPR their statutory duties is also part of their responsibilities.


Do you also audit AI applications used internally?

Yes. The use of AI systems is now one of the most common checkpoints. – from customer service chatbots to assistance features in office software. We look at GDPR both the requirements and the obligations under the AI Act.

Jan Käding • Senior Consultant

Clarity begins with a conversation

Non-binding · 15 minutes · Free

more SERVICES

Data protection services that are available
It fits your company.