Should one be concerned about a personal data audit?

29 August 2014

Although the concept of personal data protection has been present in Polish reality for some time, it still raises many doubts and concerns. On one hand, there are declarations of compliance with all requirements related to data protection or the certainty that "this issue does not concern us," while on the other hand, it often turns out that there is a lack of understanding of what it is really about. The lack of awareness regarding the requirements for securing personal data causes entrepreneurs to simply fear this topic and, as much as possible, avoid related activities, including conducting audits. Is there really something to be afraid of? What deficiencies are most commonly identified in audits? What benefits can an audit provide to an entrepreneur?

Documentation of Personal Data Protection (ODO)

The first element examined during the audit is the documentation of personal data protection – its existence and content. The aim is to have at least basic documentation describing the actual security measures or procedures in place. Sometimes, a document circulation procedure, office instructions, or a more comprehensive work regulation is sufficient. The situation is somewhat more complicated in the case of IT systems. Often, attention is not paid to the formal rules for granting permissions to individual users, as well as whether backup copies are created in the case of having an internal server room. However, it may happen that the person responsible for these matters, an IT specialist, prepares various types of user records, descriptions, or diagrams of the IT system for their own needs.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay up to date.
RECEIVE PACKAGE

It turns out that the lack of proper documentation of personal data protection is one of the most common deficiencies in audited entities.

Implementation of ODO Documentation

Another issue is the actual implementation of the procedures described in the documentation. It happens that the audited entity, despite having personal data protection documentation, does not apply it in practice. The most common reason is simply a lack of familiarity with the approved documentation – in many companies, it is often known only to the person who prepared it and possibly the management that signed it.

During audits, there are often attempts to prove to the auditors that the procedures described in the documentation are indeed functioning. However, just a few conversations with employees and a site visit are enough to ascertain the truth. It is worth emphasizing that even if entrepreneurs manage to deceive the auditors, in practice, it serves no purpose. The audit aims to identify the deficiencies present and suggest appropriate changes so that the documentation of personal data protection meets both legal requirements and reflects the actual state of affairs.

FREE

GDPR Audit Step by Step – Based on Audits Conducted by ODO 24

Watch the webinar

Data Processing Agreements

Audits often reveal a lack of appropriate agreements regarding the entrustment of personal data to external entities, for example, in the case of outsourcing. Most frequently, the audited entity does not have separate data processing agreements or any additional provisions in service contracts.

It must be acknowledged that this is a rather sensitive topic, especially in the case of long-term collaborations – outsourcing agreements are most often concluded for an indefinite period. Any proposals for changes during the term of the agreement naturally raise some distrust from the other party. This distrust is heightened by the fact that external entities often lack any documentation and do not meet legal requirements regarding personal data protection, and consequently, do not understand the purpose of additional regulations.

Personal Data Protection Training

During audits, it often turns out that the weakest link in data protection is the human factor. Employees do not know how to protect the processed data, what the company's policy is in this regard, or how they should act in situations of heightened risk. The natural consequence is various types of incidents – data breaches or loss, disclosure of data to unauthorized persons, etc.

The best protection against such threats is appropriate training for employees. However, it turns out that for many entrepreneurs, this is quite a challenge. In cases where many individuals authorized to process data work in a given company or where there is a high employee turnover, meticulous cost counting begins. Unfortunately, the result of such counting is most often a decision to save on training and to limit oneself to collecting statements from employees acknowledging their familiarity with the company's personal data protection documentation and committing to adhere to the principles contained therein. This is ineffective to the extent that many individuals sign such documents without reading them or without understanding the content they have read. From there, it may only be a step to problems.

GDPR E-learning is already a standard!

Applications to the Polish DPA

A large portion of the audited entities is convinced that the purpose of preparing personal data protection documentation is to effectively register applications with the Polish DPA, and if the collection of personal data does not require registration, it does not need to be described in the documentation, which in fact means it does not need to be secured. As practice shows, violations of regulations most often occur in the processing of employee personal data collections that do not require registration with the Polish DPA, e.g.: violation of an employee's right to privacy by placing their photo on a website without their consent or failing to delete the work email address containing the employee's name after the employment relationship has ended.

Data Security

Audits also reveal shortcomings in data security. The most common of these are inadequate physical security measures for data collections (e.g., an archive in a basement with a leaking sewage pipe or a server placed next to a sink in the staff kitchen) and granting electronic access to data to individuals who do not need it to perform their job duties (excessive access rights).

Professional auditors are able to identify all such threats and present various solutions for proper data protection.

***

Implementing a personal data protection system in an enterprise is a process that requires the involvement of all individuals authorized to process data. This requires both time and appropriate preparation. A personal data protection audit is one of the main tools of this process. It is worthwhile to conduct it in order to properly identify all areas of data processing, potential threats, and adequately assess the risks of the actions taken. In each of the elements presented above, auditors are simply partners and advisors to the entrepreneur. They indicate what should be improved so that the company operates more efficiently and securely in the area of data processing.

Do you also prefer prevention over treatment?

The post-audit report includes, among other things, a general assessment of the audited entity, an analysis of physical and IT security measures, an evaluation of the granting and revocation of permissions, an assessment of employee awareness, as well as guidelines regarding suggested changes that should or could be implemented within the company. Based on this, the audited entity can independently choose the most appropriate method for protecting the processed data. Instead of fear and distrust, it is therefore advisable to view the audit with optimism and simply adhere as closely as possible to its guidelines.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.