How frequently should an audit be conducted?
ANSWER
Audits should be conducted on a cyclical basis. No specific timeframe is prescribed by GDPR; however, we recommend that they take place at least once a year. It is worth noting that among the PUODO questions to data protection officers there appeared a question about how frequently and in what manner the DPO communicates the results of audits conducted to the controller, which indicates precisely the necessity of repeating audits on a cyclical basis. Moreover, the audit schedule/plan should be established in advance within the organisation.


