We verify compliance with the personal data protection legislation applicable to specific obligations and business processes, with an integrated legal and technical/IT approach. Content and method vary according to the Client’s operational needs and the service may cover individual processing activities, processes or business functions. We offer an independent, documented check that delivers concrete evidence on the state of compliance and on the corrective action required.
The service is delivered through:
- Definition of the audit scope and of the compliance obligations to be verified;
- Examination of the data protection documentation adopted (records, notices, appointments, procedures);
- Interviews with the business functions involved in the processes verified;
- On-site verification of the technical and organisational security measures;
- Identification of gaps against the legislation and internal policies;
Indication of corrective action, ranked by risk priority.
The service ends with an audit report setting out the evidence gathered, the gaps identified and the plan of suggested corrective action.