Companies processing personal data
Organisations processing data of employees, clients or users.
A GDPR audit is the first step if you need to know where your organisation stands on personal data protection. We go through your processes, documentation and systems and pinpoint where the risk arises.
You are preparing an e-shop, an app or a service that handles personal data.
You cannot tell whether your GDPR documentation matches how the company actually operates.
You expect an inspection by the data protection authority and want to be ready.
After a security incident or a data subject complaint you need to review the overall position.
Mapping of processing activities and personal data flows across the company.
Review of the legal bases for processing and of how information duties are met.
Review of processor agreements and transfers to third countries.
Assessment of data security and internal access rules.
A report with findings and recommendations ordered by priority.
Organisations processing data of employees, clients or users.
Clients who need a clear overview of what still has to be done.
We define the scope of the audit and agree a timeline.
We gather documentation and interview the people responsible.
We evaluate the findings and propose corrective measures.
We present the final report and a remediation plan.
Bratislava, Banská Bystrica, Košice
Mainly when you are unsure whether your documentation is up to date, you are launching a new product or system, changing how you process data, you have dealt with an incident, or you are preparing for an inspection.
The audit reviews the actual personal data processing operations, legal bases, information duties, processor agreements, data transfers and whether internal rules and measures are adequate.
The output is an overview of findings and specific recommendations on what needs to be changed or added, ideally ranked by priority and risk.
An audit as such is not a universal obligation for every company. In practice, however, it helps verify that processes and documentation match how the organisation actually operates.
The scope of materials depends on the company. Typically it includes existing GDPR documentation, contracts, information about systems and suppliers, and an overview of the processes in which personal data are processed.
Get in touch and we will agree the scope of the audit based on the size and activity of your company.
Contact us to schedule a consultation
Please briefly describe what you need help with.
We will contact you and suggest the best course of action.
Kamera na rodinnom dome: kedy je jej používanie legálne?
Kamera na rodinnom dome: kedy je jej používanie legálne?