When preparing for the planned audit, the DPO should prepare work tools tailored to the specific data controller. The best document for preparing potential checklists is the organizational structure. It is from this that the scopes of responsibilities of individual departments or independent positions within the organization arise, referred to as the organizational context. Based on the organizational structure, we can identify the processes of personal data processing and adapt the work tools to these processes. Below is an example of the organizational structure of a limited liability company (sp. z o.o.).
|
|
| By applying the above solution, we are able to determine how the data of individual categories of persons flows between departments within the organization. In this way, we obtain two valuable pieces of information. Firstly, what and how many sets of personal data are held by the data controller, and secondly, what the scope of authorization for processing personal data by individual employees must be. It is important to remember that a set of personal data can be distributed and functionally divided. |
| In summary, the preparation of the "ABI workshop," understood as a tool for conducting audits, is currently a key element of effective checks of the personal data protection system. Without a systematic methodology, audits are often conducted in a chaotic manner, and their results do not reflect reality. You can read more about creating a legally compliant personal data protection system in my book "Creating a Personal Data Protection System Step by Step" |

