Understanding the Work of Data Controllers
The key not only to preparing for an audit but also, in essence, to properly implementing and maintaining compliance with the GDPR is the ability to put oneself in the shoes of the auditors from the Polish Data Protection Authority (UODO) and to implement solutions that indicate the fullest possible compliance with data protection regulations.
In addition to knowledge of the regulations, which we explain in the articles mentioned above, it is important to be aware that auditors will want to perform their job well, primarily by:
- firstly – addressing all aspects of the audit – thus obtaining answers to every aspect of the authorization to conduct the audit,
- secondly – documenting all findings – thus obtaining the most comprehensive audit evidence – documents and prints of photographs from inspections,
- thirdly – preparing complete audit reports.
Awareness of what could potentially be the subject of an audit and what its scope may be is very important not only for direct preparation for the audit but, above all, for achieving and maintaining compliance with the GDPR. Through further reading, you will learn what to pay attention to in relation to each of the objectives that the auditor will want to achieve.
Addressing All Aspects of the Audit
Receive a package of free GDPR guides and micro-training sessions
During the inspection, all facts and circumstances that may be relevant for assessing compliance with personal data protection regulations will be examined. The assessment of compliance will be carried out by the President of the Polish DPA after the completion of the inspection activities – based on the collected information and materials. The inspectors will investigate facts pertinent to each aspect of the authorization for inspection, as this authorization will serve as the starting point for the structure of the inspection report.
Example: A typical authorization for inspection includes the determination of:
- the legal bases for processing personal data,
- the sources from which personal data is obtained,
- the categories of individuals whose data is concerned, as well as the categories of processed personal data,
- the purposes for which the data is processed,
- the recipients to whom the data is disclosed, as well as the details of sharing (legal basis, purpose, scope, and manner),
- the manner of fulfilling the information obligation,
- the manner of exercising the rights of individuals whose data is concerned,
- the principles of data processing delegation,
- authorizations for data processing,
- the implementation of data protection policies and procedures (including their formal validity and the awareness and training of staff members),
- whether a Data Protection Officer has been appointed,
- whether personal data is not stored for too long,
- whether technical and organizational measures have been implemented to ensure an appropriate level of data security,
- whether a records of processing activities and a record of all categories of processing activities are maintained,
- whether all data breaches are adequately documented.
Tip: Since the inspection involves personal interviews, evidence collection, and inspections, it is crucial to prepare responses in advance to potential questions from the inspectors. The most comprehensive answers are obtained by conducting an audit of the location to be inspected. As interviews may be conducted with any employee, it is advisable to ensure that they possess adequate knowledge of data processing principles.
Documentation of All Arrangements
Data controllers very rarely rely solely on verbal agreements. Almost all arrangements will need to be documented by attaching originals or certified copies of the requested documents to the protocol, as well as prints of photographs that the auditors may specifically request during inspections. Failure to present evidence of compliance with the GDPR may be considered a violation of the obligation to ensure accountability (Article 5(2) and Article 24(1) GDPR).
Example: When examining the issue of employee obligations, auditors may request not only the document granting authorization but also a document confirming employees' commitment to confidentiality and their awareness of the data protection principles they should adhere to (i.e., confirming familiarity with the data protection documentation).
Tip: It is crucial to gather the documents that auditors may request in advance. This will enable us to provide more accurate explanations and rectify any potential discrepancies. To avoid preparing documents just before the audit, the best approach is to take a comprehensive stance, i.e., to prepare and formally adopt policies, procedures, and records that cover those aspects of the GDPR that relate to a typical authorization for inspection (see the list above). Having such procedures, as well as proof that employees have familiarized themselves with them (and preferably that they have been trained on them), will indicate compliance with the GDPR. Since it is impossible to predict all materials that auditors will request, it is advisable to ensure continuous access to a color printer.
Preparation of Complete Audit Protocols
Working with Good GDPR Tools is not work!
Example: It may happen that the auditors, who receive a lot of information and explanations from us, forget to include favorable findings in the report, such as the use of encryption or the implementation of a clean desk and screen policy. The auditors may also misunderstand our explanations, which we will only learn about from the content of the report.
Tip: If necessary, especially in the case of findings in the report with which we disagree, it is advisable to make use of Article 88(4) of the Personal Data Protection Act, which grants the audited party the right to submit written objections to the content of the report within 7 days from the date it is presented for signature.
Summary
Preparation for the audit can be seen as a last resort – this will be the case if we do not ensure compliance with the GDPR until the notification of its conduct. It is much better if preparation for the audit becomes a kind of philosophy for implementing and maintaining compliance with the GDPR. Since the audit is one of the final forms of verifying compliance with the GDPR, preparing the organization for it will also be the best way to ensure a smoothly functioning data protection system.


