Audit Scoping & Criteria
Define the entities, jurisdictions, processes, internal standards and legal requirements that form the audit criteria.
- Applicable-law and entity scoping
- Audit objectives and materiality
- Evidence request and sampling plan
Independent GDPR audit and data protection compliance review of an existing privacy framework against the laws, internal standards and control criteria relevant to the business — with evidence-based findings and clear remediation priorities.
A GDPR compliance audit is different from programme build-out: the purpose is to test what already exists, assess whether controls are implemented in practice, identify material gaps and give management a defensible view of current maturity.
A privacy audit provides management with an independent view of whether the organisation’s privacy framework is appropriately designed, implemented and evidenced against the legal and control criteria relevant to its operations. The review can cover the whole programme or a defined theme, entity, product, jurisdiction or regulatory concern.
We distinguish policy existence from operational effectiveness. Interviews, document review, process walkthroughs, selected evidence testing and sample-based checks are used where appropriate to determine whether stated controls are actually operating. Findings are then prioritised by legal, operational and business impact.
The scope is agreed before fieldwork and mapped to the applicable privacy regimes, internal standards and client objectives. Full-programme and thematic reviews are both available.
Define the entities, jurisdictions, processes, internal standards and legal requirements that form the audit criteria.
Assess privacy ownership, reporting lines, policies, decision rights, management oversight and evidence of accountability.
Test whether the organisation’s existing maps, inventories, purposes, transparency materials and processing conditions reflect actual operations. The audit tests evidence; it does not build the underlying programme.
Review whether rights and complaint processes are correctly designed, consistently operated and supported by evidence.
Test whether the existing third-party privacy framework is designed and operating effectively, including due diligence evidence, contractual governance, ownership and periodic review.
Review cross-border transfer mapping, applicable transfer rules, safeguards, assessments and monitoring records.
Assess whether retention rules are legally grounded, internally consistent and translated into operational deletion or archival controls.
Test the organisation’s existing incident-governance process, decision records, notification assessment and remediation evidence. The audit reports findings rather than operating the incident response process.
Assess whether higher-risk processing is identified and whether DPIA, PIA or equivalent assessments are complete, current and used in decision-making.
Test selected controls and records to determine whether documented procedures are being followed in practice.
Provide clear findings, materiality assessment and remediation priorities designed for management and control owners.
Re-test agreed findings after remediation and report whether actions are implemented, partially implemented or remain open.
Where EU GDPR or UK GDPR forms part of the audit criteria, the review tests both the design of the privacy framework and evidence that key controls operate in practice.
Test governance, processing records, transparency, lawful processing, rights handling, retention, processor oversight and incident documentation against the agreed EU/UK criteria.
Review DPIA governance, privacy-by-design, DPO arrangements where applicable, escalation, management reporting and evidence of remediation.
Review processor/data-sharing arrangements and the EU or UK transfer controls relevant to the sampled data flows.
An international privacy audit should not apply GDPR criteria to entities governed by a different law. The audit matrix is therefore adjusted to the applicable national framework and agreed scope.
Build the audit criteria from the law, regulator guidance and sector obligations applicable to the relevant entity and processing activity.
Trace policies into actual workflows, selected records, contracts, notices, incident handling, vendor controls and management oversight.
Where multiple jurisdictions are reviewed, report findings on a common risk scale while identifying which obligations are global and which are local.
For group audits, a single reporting framework can be used across jurisdictions, but the legal test behind each finding must remain tied to the applicable regime. This makes the report comparable without creating false legal uniformity.
Define entities, jurisdictions, processes, applicable requirements, internal standards and audit objectives.
Review documents, interview control owners and trace selected processes from policy to actual execution.
Test selected evidence, identify design or implementation gaps and rate findings by materiality and risk.
Deliver management findings, remediation priorities, ownership recommendations and optional validation follow-up.
An independent view of privacy maturity, unresolved risk and whether governance evidence supports management representations.
Pre-examination review where a supervisory interaction, licensing process, remediation programme or compliance concern makes evidence quality important.
Privacy review before investment, acquisition, strategic partnership or major banking / enterprise due diligence.
Independent follow-up testing to determine whether previously identified actions have been implemented and whether residual gaps remain.
The audit is led by senior legal and compliance practitioners and designed for regulated, data-intensive and cross-border operating models where privacy controls interact with wider regulatory obligations.
The review is separated from day-to-day control ownership and focused on evidence, implementation and material findings rather than defending existing documentation.
Privacy controls are assessed alongside AML/KYC, payments, digital assets, AI governance, outsourcing and technology-risk requirements where they affect the same processes.
Criteria are mapped to the privacy regimes that actually apply to each entity and processing activity instead of forcing every audit into a GDPR-only checklist.
Findings are written for decision-makers, with clear remediation priorities, owners and next steps rather than a document-only compliance score.
BOOK A CONSULTATION
Share the business context, jurisdiction and support you need. We will reply with a practical next step.