Checklist as a tool for conducting audits by the Data Protection Officer (DPO)

31 October 2016

The DPO, in the course of their supervisory role, must conduct checks of the personal data protection system. Each check or audit requires the adoption of a specific methodology. One DPO may place greater emphasis on site visits, while another may focus on personal interviews with participants in the personal data processing activities. Each of these methods requires pre-prepared tools. In the case of personal interviews, this will most often be a list of questions tailored to a specific department of the organization, and in the case of site visits, a list of safeguards that should be implemented in relation to the identified threats in the area of processing.

When preparing for the planned audit, the DPO should prepare work tools tailored to the specific data controller. The best document for preparing potential checklists is the organizational structure. It is from this that the scopes of responsibilities of individual departments or independent positions within the organization arise, referred to as the organizational context. Based on the organizational structure, we can identify the processes of personal data processing and adapt the work tools to these processes. Below is an example of the organizational structure of a limited liability company (sp. z o.o.).

List of Questions for Personal Interview - Human Resources and Payroll. Creating a list of questions for personal interviews is not a straightforward task, and the final shape of the questions depends on the actual processes occurring in the respective departments of the organization. Therefore, it is advisable to conduct a brief survey among individuals in higher positions before the actual check to learn about the processes they have in place. We can do this in the form of a meeting with management, where, based on the organizational structure, we determine whose personal data is being processed by the respective departments and to what extent. Below is a sample diagram.
Organizational chart – division of positions.
 
By applying the above solution, we are able to determine how the data of individual categories of persons flows between departments within the organization. In this way, we obtain two valuable pieces of information. Firstly, what and how many sets of personal data are held by the data controller, and secondly, what the scope of authorization for processing personal data by individual employees must be. It is important to remember that a set of personal data can be distributed and functionally divided.
In summary, the preparation of the "ABI workshop," understood as a tool for conducting audits, is currently a key element of effective checks of the personal data protection system. Without a systematic methodology, audits are often conducted in a chaotic manner, and their results do not reflect reality. You can read more about creating a legally compliant personal data protection system in my book "Creating a Personal Data Protection System Step by Step"

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.