Certix

Data Protection Audit:
do you really comply, or just have paperwork?

Having signed folders is not complying. A Certix expert reviews your real situation, shows you where you are exposed and tells you clearly what is missing. The initial assessment is free.

0€

initial assessment

24 h

response to your enquiry

Art. 5.2

GDPR — accountability principle

3 min

online self-assessment test

What it is

What is a data protection audit?

A data protection audit is a review of your company's real standing against the GDPR and the LOPDGDD. It is not filling in a template. It is answering an uncomfortable question with facts: if a complaint or an AEPD inspection landed tomorrow, would you hold up?

It reviews what data you process, on what legal basis, who accesses it, what you have signed with your providers, the state of your website and what you would do in the event of a breach. The goal is not to pile up documents: it is to know where you are exposed before someone else finds out.

Most of the market analyses nothing. It copies, pastes, charges and disappears. The result is a company with folders full of generic PDFs that do not match what it actually does. Certix does not work that way.

That is why the assessment is always the first step, and it is free and with no commitment: first you know where you stand; then you decide.

Your real situation

We analyse what you actually do, not what a standard template says.

Paperwork vs reality

We check whether the documentation you have matches your activity.

An expert, not a salesperson

You speak with someone who understands the regulation, not a rep with a script.

Free assessment

Knowing where you stand costs nothing. We only charge for the adaptation work.

Warning signs

How to tell if your data protection is not done right

If you recognise yourself in any of these points, it is time for an assessment. None of them is unusual: they are the most common problems we find.

You were given a generic pack

You received a folder of documents that looks the same as any other company's, without anyone analysing your specific activity.

Your adviser disappeared

You signed years ago, you paid, and since then no one has reviewed anything or warned you of any regulatory change.

You do not know what you have signed

If you cannot say for sure what contracts you have with the providers that access your data, they are probably missing.

Your website raises doubts

Legal notice, privacy policy and cookies added "because the template had them", without adapting them to what you actually collect.

You would not know how to react

If you suffer a security breach tomorrow, you are not clear on who to notify, within what deadline or how to document it.

You do not handle rights requests

If a customer asks to access or delete their data, you do not have a clear procedure to respond in time.

What we review

What an expert looks at in the assessment

The assessment is not an automated questionnaire. It is a conversation with an expert who, based on your activity, reviews the points where a company is usually exposed:

  • Record of Processing Activities (RoPA): whether it exists and whether it reflects what you actually do.
  • Legal bases: the legal grounds on which you process each type of data (contract, consent, legal obligation).
  • Data processors: which providers access your data and whether you have the art. 28 GDPR contract signed with each one.
  • Website and legal texts: legal notice, privacy and cookies adapted to what you actually collect.
  • Security and breaches: whether you have a protocol to detect, document and notify a breach within the deadline.
  • Data subjects' rights: whether you know how to handle an access, rectification or erasure request.

By the end, you know clearly what is fine, what is missing and what is urgent. No jargon and no small print.

Areas of the assessment

Real inventory of processing activities
Legal bases for each processing activity
Contracts with providers (art. 28 GDPR)
International data transfers
Website legal notice, privacy and cookies
Data breach response protocol
Procedure for handling rights requests
Duty to inform (art. 13 GDPR)
Security measures proportionate to the risk

How it works

From doubt to knowing where you stand, in three steps

01

Online self-assessment

Start with our free test. In three minutes you get a first snapshot of your situation, without providing any mandatory contact details.

02

Call with an expert

A Certix expert asks you the key questions about your activity and spots what a test cannot see. Free and with no commitment.

03

We tell you what is missing

We explain clearly what is fine, what is missing and what is urgent. If you want us to fix it, we send you a proposal. If not, you keep the assessment anyway.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Want to know where your company stands?

Tell us about your case and an expert will tell you, at no cost, where you are exposed and what you need to fix.

Request a free assessment

Response within 24 h · +34 611 030 124

FAQ

Frequently asked questions about the data protection audit

What is a data protection audit?

It is a review of an organisation's real standing on data protection: what data it processes, on what legal basis, who accesses it, what contracts it has signed with its providers, how it manages its website and what it would do in the event of a breach or a complaint. The aim is to detect where it is exposed before the AEPD or a customer does. At Certix this assessment is the starting point of every project and the initial consultation is free.

Is a data protection audit mandatory?

The GDPR does not impose a periodic formal audit as such. It replaced that approach with the accountability principle (art. 5.2 and art. 24 GDPR): the company must be able to demonstrate at all times that it complies. In practice, that requires reviewing the state of data protection on an ongoing, risk-based basis rather than on fixed dates. An honest review is the only way to know whether you are really in order or just have signed paperwork.

How much does a data protection audit cost?

The initial assessment with a Certix expert is free and with no commitment: we analyse your situation and tell you clearly what is missing. If from there you need an adaptation project, we send you a personalised proposal based on the size and complexity of your activity. We never charge to tell you where you stand.

How often should a company review its data protection?

There is no fixed frequency imposed by the regulation. The GDPR is based on ongoing, risk-based assessment: data protection is reviewed when something relevant changes in the company (new processing activities, new providers, a new website, a regulatory change) and periodically, in proportion to the volume and sensitivity of the data handled.

What is the difference between an LOPD audit and a GDPR audit?

They are the same thing in everyday language. The applicable framework in Spain is the GDPR (European regulation) together with the LOPDGDD (Organic Law 3/2018). Many people still call it an "LOPD audit" out of habit, but the framework in force is the GDPR + LOPDGDD. The review covers both regulations together.

How do I know whether my previous data protection adviser did a good job?

It is one of the most common reasons companies contact us. A large part of the market delivers a pack of generic documents, charges and disappears, without genuinely analysing the specific activity. In the assessment we review whether what you have matches what you actually do: whether the Record of Activities reflects your real processing, whether you have contracts with your providers, whether your website complies. If it is well done, we will tell you; if not, we will tell you too.

First you learn where you stand.
Then you decide.

No salespeople, no small print. A data protection expert analyses your case and tells you the truth about your situation.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →

Free assessment · Response within 24 h · info@certix.es