Search

How can we help?

Privacy and Data Protection

Audits

 

Audits help organisations to understand and meet their data protection obligations. The audit will check the effectiveness of controls in place and look at the suitability of your policies and procedures.

Our lawyers can conduct a full compliance privacy health check of your business including a review of any technical and organisational measures employed, providing clear and practical recommendations.

“Very professional, knowledgeable and accessible lawyers.” 

Chambers and Partners

FAQs – Audits

A data protection audit assists a business in understanding what personal data the organisation collects and processes. It is carried out to ascertain if the organisation is compliant with the data protection laws and it will usually assess the organisation’s procedures, systems, records and activities.

The UK GDPR includes an accountability principle which requires a controller to demonstrate compliance with the data protection principles of the UK GDPR. An audit is one of the ways in which a controller can demonstrate accountability. Although the UK GDPR does not directly apply to processors, both controllers and processors have compliance obligations and an audit is one of the ways which can demonstrate compliance.

This depends on the size and complexity of the organisation. At minimum, a data protection audit should be performed once each year. If there are several areas that need to be improved, you should consider working on those areas more regularly until the organisation is confident that it is compliant with the data protection regulation.

In summary, the data protection audit is likely to cover governance and accountability; security measures in place; whether data is transferred outside the UK and arrangements for such transfers; and whether there are procedures for data subjects’ rights, amongst other areas. The nature of the audit will depend on the specific organisation and method of audit.

If the organisation has a data protection officer (DPO), they will likely oversee the audit. If the organisation has no DPO or Compliance Manager, then the business must select an auditor. The auditor will then decide whether to use a customised questionnaire audit or conduct a personal interview or a blend of both methods.

Key contacts

Read, listen and watch our latest insights

Pub
  • 20 March 2023
  • Privacy and Data Protection

Data Subject Access Request: Advice for Employers

In this podcast Ciara Duggan and Oscar Poku members of the Data Protection team discuss what exactly a DSAR is, how one is made, and how companies should respond if they receive one.

art
  • 08 March 2023
  • Employment

International Women’s Day 2023 – Empowerment of all women and girls in technology

International Women’s Day celebrates women’s achievements and aims for a world free of bias, stereotypes and discrimination. 

art
  • 23 February 2023
  • Privacy and Data Protection

Artificial intelligence: an exciting technology, or a venture into unknown waters?

The Law Society states that ‘artificial intelligence’ (AI) involves computer systems which can replicate human cognitive functions, and that it includes algorithms detecting patterns in data, as well as applying these to automate certain tasks.

art
  • 13 February 2023
  • Privacy and Data Protection

Love is in the air: Is it data at first sight?

As we enter the week of Valentine’s Day, it is important to recognise the significance of data security, particularly where we have seen the number of cybersecurity breaches increase over the last few months.

Pub
  • 26 January 2023
  • Privacy and Data Protection

UK Data Protection: Development round-up 2022 and 2023 trends

In this podcast Oscar Poku and Ciara Duggan members of the Data Protection team at Clarkslegal will be discussing  the main developments in the UK Data Protection scene from 2022 and what trends to look out for in 2023.

art
  • 18 January 2023
  • Privacy and Data Protection

Remote working: How to stay Data Protection-Compliant

In recent years, there has been a very significant movement from office-based to remote working.