GDPR and LOPDGDD compliance audit for businesses

Having a privacy policy isn't the same as being able to prove your data processing complies with GDPR. We audit what data you process, on what legal basis, who you share it with, and whether your security measures meet what the regulation requires.

Complying with GDPR on paper isn't the same as being able to prove it

Most companies have a privacy policy on their website, drafted by a lawyer, and assume that's equivalent to GDPR compliance. In practice, it's common to find behind that document a non-existent or outdated Record of Processing Activities, unsigned data processing agreements with cloud providers or payment gateways, and Article 32 GDPR technical measures that nobody has actually verified. The problem shows up when someone asks for proof: an enterprise client, an insurer before underwriting a cyber policy, an investor in due diligence, or a public administration in a tender. A GDPR/LOPDGDD audit gives you the real picture of your compliance, not the one you assume you have.

What the audit covers

  • Data processing mapping and verification or creation of the Record of Processing Activities (RoPA)
  • Review of the legal basis for each processing activity: consent, contract, legitimate interest or legal obligation
  • Review of data processing agreements with cloud providers, payment gateways and third-party SaaS
  • Assessment of the technical and organizational measures required by Article 32 GDPR: encryption, access control, backups
  • Review of retention periods and data deletion procedures
  • Assessment of international data transfers, where applicable

How we approach it

  1. Scoping meeting: We understand what data your company processes, from whom, for what purpose and through which systems.
  2. Processing mapping: We inventory processing activities, legal bases and data flows between your own systems and third parties.
  3. Documentation review: We review the privacy policy, RoPA, vendor contracts and the breach notification procedure.
  4. Technical measures assessment: Encryption, access control, retention and backups against what Article 32 GDPR requires.
  5. Report and roadmap: Findings prioritized by real risk and a concrete action plan to close each gap.

What you get

  • GDPR/LOPDGDD compliance report with findings classified by risk level
  • Record of Processing Activities (RoPA), updated or built from scratch
  • Map of data processors and the status of their contracts/DPAs
  • Remediation roadmap prioritized by impact
  • Report valid as compliance evidence for clients, insurers or public administrations
  • Closing meeting to explain the findings to the responsible team

Who is this for?

  • Companies that have never gone beyond their website's privacy policy for GDPR
  • Companies that need to evidence GDPR compliance to a client, an investor or a public administration
  • Companies that have grown their tool and vendor stack without reviewing their processor agreements
  • Companies in sectors with especially sensitive data: healthcare, legal, financial or education
  • Companies that want to take out cyber insurance and need to evidence security measures
  • Companies with a Data Protection Officer who need a periodic, independent technical review

Frequently asked questions

Does this replace having a Data Protection Officer (DPO)?

Not necessarily. If your company is required to have a DPO, this audit is complementary: it assesses the real state of compliance, and the DPO can use the report to prioritize their work. If you don't have a DPO, the audit gives you an independent snapshot without needing to hire that role permanently.

Do I need this audit if a lawyer already wrote my website's privacy policy?

The privacy policy is the user-facing document; it doesn't evidence that internal processing, vendor contracts or technical measures are actually in order. It's common to find companies with a flawless privacy policy and no real Record of Processing Activities behind it.

How long does the process take?

Between 2 and 4 weeks for a mid-sized company, depending on the number of processing activities and vendors to review. For a scope narrowed to a single product or system it can be faster.

Is the report valid for submission in a public tender?

Yes, if the tender asks for a GDPR compliance review as part of the accreditation documentation. If it also requires a penetration test of the tendered system, see our public tenders audit service, which combines both in a single report on express timelines.

Do you also audit third-party vendor compliance (cloud, third-party SaaS)?

We review the contracts and DPAs you have signed with them and how data flows to those vendors, but we don't audit the vendor's internal infrastructure unless it's part of a separately contracted pentest.

What happens if you find a serious non-compliance issue?

We classify it by real risk, not just formal risk, and give you a prioritized roadmap. How and when to remediate it is your call; we can support the implementation if you need it.

Related resources

Request a GDPR audit