Data Protection Audit:
do you really comply, or just have paperwork?
Having signed folders is not complying. A Certix expert reviews your real situation, shows you where you are exposed and tells you clearly what is missing. The initial assessment is free.
0€
initial assessment
24 h
response to your enquiry
Art. 5.2
GDPR — accountability principle
3 min
online self-assessment test
What it is
What is a data protection audit?
A data protection audit is a review of your company's real standing against the GDPR and the LOPDGDD. It is not filling in a template. It is answering an uncomfortable question with facts: if a complaint or an AEPD inspection landed tomorrow, would you hold up?
It reviews what data you process, on what legal basis, who accesses it, what you have signed with your providers, the state of your website and what you would do in the event of a breach. The goal is not to pile up documents: it is to know where you are exposed before someone else finds out.
Most of the market analyses nothing. It copies, pastes, charges and disappears. The result is a company with folders full of generic PDFs that do not match what it actually does. Certix does not work that way.
That is why the assessment is always the first step, and it is free and with no commitment: first you know where you stand; then you decide.
Your real situation
We analyse what you actually do, not what a standard template says.
Paperwork vs reality
We check whether the documentation you have matches your activity.
An expert, not a salesperson
You speak with someone who understands the regulation, not a rep with a script.
Free assessment
Knowing where you stand costs nothing. We only charge for the adaptation work.
Warning signs
How to tell if your data protection is not done right
If you recognise yourself in any of these points, it is time for an assessment. None of them is unusual: they are the most common problems we find.
You were given a generic pack
You received a folder of documents that looks the same as any other company's, without anyone analysing your specific activity.
Your adviser disappeared
You signed years ago, you paid, and since then no one has reviewed anything or warned you of any regulatory change.
You do not know what you have signed
If you cannot say for sure what contracts you have with the providers that access your data, they are probably missing.
Your website raises doubts
Legal notice, privacy policy and cookies added "because the template had them", without adapting them to what you actually collect.
You would not know how to react
If you suffer a security breach tomorrow, you are not clear on who to notify, within what deadline or how to document it.
You do not handle rights requests
If a customer asks to access or delete their data, you do not have a clear procedure to respond in time.
What we review
What an expert looks at in the assessment
The assessment is not an automated questionnaire. It is a conversation with an expert who, based on your activity, reviews the points where a company is usually exposed:
- Record of Processing Activities (RoPA): whether it exists and whether it reflects what you actually do.
- Legal bases: the legal grounds on which you process each type of data (contract, consent, legal obligation).
- Data processors: which providers access your data and whether you have the art. 28 GDPR contract signed with each one.
- Website and legal texts: legal notice, privacy and cookies adapted to what you actually collect.
- Security and breaches: whether you have a protocol to detect, document and notify a breach within the deadline.
- Data subjects' rights: whether you know how to handle an access, rectification or erasure request.
By the end, you know clearly what is fine, what is missing and what is urgent. No jargon and no small print.
Areas of the assessment
How it works
From doubt to knowing where you stand, in three steps
01
Online self-assessment
Start with our free test. In three minutes you get a first snapshot of your situation, without providing any mandatory contact details.
02
Call with an expert
A Certix expert asks you the key questions about your activity and spots what a test cannot see. Free and with no commitment.
03
We tell you what is missing
We explain clearly what is fine, what is missing and what is urgent. If you want us to fix it, we send you a proposal. If not, you keep the assessment anyway.
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Want to know where your company stands?
Tell us about your case and an expert will tell you, at no cost, where you are exposed and what you need to fix.
Request a free assessmentResponse within 24 h · +34 611 030 124
FAQ
Frequently asked questions about the data protection audit
What is a data protection audit?
It is a review of an organisation's real standing on data protection: what data it processes, on what legal basis, who accesses it, what contracts it has signed with its providers, how it manages its website and what it would do in the event of a breach or a complaint. The aim is to detect where it is exposed before the AEPD or a customer does. At Certix this assessment is the starting point of every project and the initial consultation is free.
Is a data protection audit mandatory?
The GDPR does not impose a periodic formal audit as such. It replaced that approach with the accountability principle (art. 5.2 and art. 24 GDPR): the company must be able to demonstrate at all times that it complies. In practice, that requires reviewing the state of data protection on an ongoing, risk-based basis rather than on fixed dates. An honest review is the only way to know whether you are really in order or just have signed paperwork.
How much does a data protection audit cost?
The initial assessment with a Certix expert is free and with no commitment: we analyse your situation and tell you clearly what is missing. If from there you need an adaptation project, we send you a personalised proposal based on the size and complexity of your activity. We never charge to tell you where you stand.
How often should a company review its data protection?
There is no fixed frequency imposed by the regulation. The GDPR is based on ongoing, risk-based assessment: data protection is reviewed when something relevant changes in the company (new processing activities, new providers, a new website, a regulatory change) and periodically, in proportion to the volume and sensitivity of the data handled.
What is the difference between an LOPD audit and a GDPR audit?
They are the same thing in everyday language. The applicable framework in Spain is the GDPR (European regulation) together with the LOPDGDD (Organic Law 3/2018). Many people still call it an "LOPD audit" out of habit, but the framework in force is the GDPR + LOPDGDD. The review covers both regulations together.
How do I know whether my previous data protection adviser did a good job?
It is one of the most common reasons companies contact us. A large part of the market delivers a pack of generic documents, charges and disappears, without genuinely analysing the specific activity. In the assessment we review whether what you have matches what you actually do: whether the Record of Activities reflects your real processing, whether you have contracts with your providers, whether your website complies. If it is well done, we will tell you; if not, we will tell you too.
First you learn where you stand.
Then you decide.
No salespeople, no small print. A data protection expert analyses your case and tells you the truth about your situation.
Free assessment · Response within 24 h · info@certix.es