Certix

GDPR audit: what it is, what it is for and how to carry it out step by step

Certix
Certix®
· 9 Oct 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

Having your data protection documents signed does not mean you comply with the GDPR. It means you have them signed. A GDPR audit is the review that separates one thing from the other: it checks whether what your company has on paper matches what it actually does with the data of customers, employees and providers. This guide explains what it is, when it is worth doing, what phases it has and what documentation it must leave you with when it is finished.

In 20 seconds

  • A GDPR audit reviews whether your real data protection matches what is documented.
  • The GDPR does not require an audit with a fixed date, but it does require you to demonstrate compliance (art. 5.2 and 24 GDPR).
  • It is not the same as the initial adaptation: the audit reviews what already exists.
  • Its phases run from the inventory of processing activities to the report with a prioritised action plan.
  • It is reviewed continuously and based on risk, not on fixed intervals.

What a GDPR audit is and what the Regulation requires

A GDPR audit is the review of an organisation's real situation in data protection matters: what data it processes, on what legal basis, who accesses it, what contracts it has with its providers, how its website is adapted and how it would respond to a breach or a claim. Its purpose is to detect the distance between what the company believes it does and what it actually does.

It is worth clearing up a frequent misconception. The GDPR does not impose a formal periodic audit by that name, as the old 1999 LOPD did with its biennial security audit. The Regulation replaced that approach with one of accountability (art. 5.2 GDPR): complying is not enough, you must be able to demonstrate it at any time. Art. 24.1 GDPR reinforces this by requiring appropriate measures to be applied and to be reviewed and updated where necessary.

From that obligation to demonstrate and review, the audit arises as a practical tool. And art. 32 GDPR adds the security piece: the level of technical and organisational protection must be proportionate to the risk of each processing operation. Auditing is, at heart, checking that this triple mandate —demonstrate, review and protect according to risk— is met on the ground and not just in a folder.

A GDPR audit and the initial adaptation are not the same

These are two distinct jobs that are often confused. The initial adaptation is the first implementation: you start from scratch, analyse the activity and build all the data protection documentation and measures. The audit is the review of what already exists: it verifies whether that adaptation is still alive or whether it has become outdated compared with how the company works today.

The difference matters because many organisations adapted their data protection years ago and have not touched it since. In the meantime they have changed software, hired new providers, launched a new website or opened new lines of business. The documentation signed back then describes a company that no longer exists. That is where the audit adds value: it does not build again, it contrasts.

"Most companies do not have a documents problem: they have a lag problem. They signed correctly and carried on working. An audit does not look for pretty paperwork, it looks for the truth: whether what is written describes what actually happens every day with the data."

Mario P. Talamillo · Managing Partner, Certix®

When it is worth auditing your data protection

There is no fixed interval imposed by the rules. The GDPR relies on a continuous, risk-based assessment: data protection is reviewed when something relevant changes and in proportion to the volume and sensitivity of the data you handle. Chasing a calendar date is less useful than watching for the changes that genuinely alter your processing operations.

These are the usual triggers that call for a review:

  • A new system or software that processes personal data: a CRM, an ERP, a booking or e-learning platform.
  • A new provider that accesses your data and acts as a data processor.
  • A new or redesigned website, with forms, analytics or e-commerce.
  • A security breach or an incident that has put the data at risk.
  • A relevant regulatory change or a new line of business with different processing operations.
  • The time elapsed since the last review, when enough has passed for the activity to have changed without the documentation reflecting it.

The phases of a GDPR audit step by step

Each consultant groups the stages somewhat differently, but a serious audit always travels the same path: understand the company, inventory what it processes, compare it with what the rules require and translate the findings into actions. These are the phases.

1. Initial analysis of the activity

The first step is to understand the reality of the organisation: what it does, how it is structured, how many people access data, which systems it works with and what relationship it has with providers and third parties. Without this starting picture, any later review stays on the surface.

2. Inventory and Record of Processing Activities

All data processing operations are identified: what data is collected, for what purpose, for how long and to whom it is disclosed. This inventory is the backbone of the audit and is captured in the Record of Processing Activities (art. 30 GDPR). If the record does not reflect the real processing operations, everything else fails.

3. Review of the legal bases

Each processing operation needs a valid legal basis under art. 6 GDPR: consent, performance of a contract, legal obligation or legitimate interest, among others. The audit checks that each activity rests on the correct basis and that, where consent is used, it has been collected validly.

4. Contracts with data processors

The providers that access your data (cloud software, the gestoría, the marketing agency, IT maintenance) and the data processor contracts required by art. 28 GDPR are reviewed. A point that is often overlooked: when the relationship ends, the processor must return the data to you or allow you to export it so that you can keep it for as long as the law requires; destruction only follows afterwards.

5. Security measures

It is verified that the technical and organisational measures are proportionate to the risk, in line with art. 32 GDPR: role-based access control, individual passwords, backups, encryption where appropriate and a clear device-use policy. It is not about having everything, but about having what is adequate for the data you handle.

6. Rights, information and breach management

Finally, the audit reviews how you inform individuals (clauses and privacy policy), how you handle their rights of access, rectification, erasure, objection and portability, and what protocol you have to notify a breach to the supervisory authority within a maximum of 72 hours where appropriate. The training of staff with access to data is also checked.

What documentation the audit must produce

An audit that leaves nothing in writing is of no use for demonstrating anything. When it finishes, it must deliver three pieces that, together, evidence the work and set out the way forward.

Document What it is for
Findings report Sets out the real state by area: what complies, what is missing and what is urgent. It is the honest picture of the situation.
Prioritised action plan Translates the findings into concrete tasks, ordered by risk and impact. It is the roadmap.
Updated record Brings the Record of Processing Activities up to date, reflecting the real activity verified.

This documentation is also the proof of accountability that the GDPR requires: it shows that you have reviewed your situation and that you act on what you have detected. It is not paperwork to file away, it is the evidence that you take people's data seriously.

Internal or external audit

An internal audit costs less, but it has a clear limit: whoever designed the system rarely detects their own blind spots. Objectivity suffers. In addition, data protection demands up-to-date knowledge of the GDPR, the LOPDGDD and the AEPD's criteria, which change over time.

An external, specialised review brings independence and judgement, and usually finds gaps that go unnoticed from within. If your organisation does not have a Data Protection Officer or its own legal profiles, external support is the usual way to audit with guarantees. The final decision depends on the size and maturity of each company, and each case requires an individual analysis.

GDPR audit checklist

These are the minimum points that a serious audit must cover. It serves as a reference to check that the review genuinely reaches every area and does not stop halfway.

  • Complete inventory of processing operations and an up-to-date Record of Processing Activities.
  • A valid legal basis identified for each processing operation.
  • Information clauses and a privacy policy consistent with the real activity.
  • Data processor contracts signed with every provider that accesses data.
  • Security measures proportionate to the risk (access, passwords, backups, encryption where appropriate).
  • A procedure to handle individuals' rights on time.
  • A response protocol for security breaches, with the 72-hour notification deadline.
  • Documented training of staff with access to personal data.
  • Findings report and action plan prioritised by risk.

Frequently asked questions

Does the GDPR require a data protection audit?

The GDPR does not impose a formal periodic audit by that name, as the old 1999 LOPD did. Instead it introduced the principle of accountability (art. 5.2 GDPR) and the obligation to review and update the measures (art. 24.1 GDPR): your company must be able to demonstrate at all times that it complies. The audit is the practical instrument for checking this, not a formality with a mandatory date.

How long does a GDPR audit take?

It depends on the size of the organisation, the number of processing operations and the quantity of systems and providers involved. An SME with few processing operations can be reviewed in a few days; a company with several sites, a transactional website and many processors requires more time. There is no fixed legal deadline: what matters is that the review reaches every processing operation and does not stop at a superficial check.

Is an internal or external audit better?

An internal audit is cheaper, but it loses objectivity: whoever built the system can hardly detect their own blind spots. Data protection also demands up-to-date knowledge of the GDPR and the LOPDGDD. An external, specialised perspective brings independence and usually finds gaps that go unnoticed from within. Each case requires an individual analysis.

What is the difference between a GDPR audit and the initial adaptation?

The initial adaptation is the first implementation: you start from scratch and build all the documentation and measures. The audit is the review of what already exists: it checks whether that adaptation is still real and current, or whether it has become outdated compared with the current activity. You adapt once and audit each time something relevant changes.

In summary

A GDPR audit does not look for pretty paperwork: it looks for the truth about how you process data. It reviews whether what is documented matches reality, detects the distance between the two and translates it into an action plan ordered by risk. It is not imposed by a calendar date, but by the changes in your activity and the principle of accountability. If it has been a long time since you signed your adaptation and you have not looked at it again, an honest review is the only way to know whether you are still in order or simply keeping papers from another era.

Related reading


This content is purely informational and educational; it does not in any way constitute specialised legal advice. Applying the regulations to each specific case requires individual analysis. Spanish regional sectoral regulations may extend or modify the general requirements described.

Do you want to know whether your company really complies?

At Certix we review your real situation with a data protection expert and tell you clearly what you are missing. Discover our data protection audit: an initial diagnosis with no commercial intermediaries and no generic templates.

See the data protection audit

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →