Who should be part of the audit team?
ANSWER
There are no guidelines as to who should be part of the audit team; however, the members must be persons with appropriate knowledge and qualifications in the field of personal data protection and security. For example, at ODO 24 the audit is divided into two parts: the formal and legal part is conducted by a lawyer, while the technical and organisational security part is conducted by an IT specialist. However, audits may also be conducted by other persons; in organisations this is often the data protection officer, but it may also be another designated person who, with support from the controller, will conduct the audit.


