Privacy and data protection

Privacy audit

Assess your GDPR compliance and manage your privacy risks

Does your organization demonstrably comply with the GDPR? With a privacy audit, our lawyers and in-house counsel map out your processing activities, risks, and shortcomings – from international corporations to the baker on the corner – and deliver a report with clear priorities.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

An organization is obliged to comply with the obligations incumbent upon it arising from privacy legislation. Failure to comply with the relevant obligations may result in enforcement action by the supervisory authority. Within our Privacy and Data Protection practice group, our privacy specialists can conduct a privacy audit. This allows for an analysis of the risks an organization faces with regard to privacy and data protection.

In addition, our practice group advises on the drafting of a privacy protocol. A privacy protocol sets out, for example, the course of action to be taken in the event of a data breach.

Questions about a privacy audit? Please contact us.

What is a privacy audit?

A privacy audit is a systematic assessment of how your organization processes personal data, compared against the requirements of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the GDPR Implementation Act. The audit reveals where your organization is compliant and where it is not, and provides a concrete report with findings, risks, and recommendations prioritized. Consequently, a privacy audit is not an end in itself, but the basis for informed choices: you know which measures to take first and which can wait. For our clients – ranging from international corporations to the baker around the corner – our lawyers and in-house counsel tailor the depth of the audit to the size and risks of your organization.

Accountability: why a privacy audit?

The GDPR establishes an accountability obligation. Pursuant to Article 5(2) of the GDPR, you must not only comply with the principles of data processing but also be able to demonstrate that you do so. A privacy audit provides precisely that documentation and evidence: a substantiated picture of your factual situation. If you fail to comply, the Dutch Data Protection Authority (AP) can take enforcement action, including imposing a penalty payment or an administrative fine. Under Article 83 of the GDPR, that fine can amount to up to €20 million or 4% of the worldwide annual turnover. In addition to the risk of fines, reputational damage and liability towards data subjects (Article 82 of the GDPR) also play a role. An audit helps to identify and manage these risks in a timely manner.

What do we investigate during a privacy audit?

During a full privacy audit, our specialists assess the following components, among others:

  • Processing register – is an up-to-date register of processing activities required under Article 30 GDPR, and does it cover all processing operations?
  • Legal bases – does every processing operation rely on a valid legal basis under Article 6 of the GDPR (consent, contract, statutory obligation, vital interest, public task, or legitimate interest)? For special categories of personal data, the stricter regime of Article 9 of the GDPR applies.
  • Transparency – does the privacy statement comply with the information obligation of Articles 13 and 14 of the GDPR?
  • Data Processing Agreements – have agreements been established with all processors in accordance with Article 28 of the GDPR?
  • Security – have appropriate technical and organizational measures been taken (Article 32 GDPR)?
  • Data breaches – is there a procedure for reporting a data breach to the DPA and data subjects (Articles 33 and 34 GDPR)?
  • Retention periods – is data not retained longer than necessary and is a retention policy in place?
  • Data subject rights – can the organization handle requests for access, rectification, erasure, and data portability (Articles 15 to 22 GDPR) in a timely manner?
  • DPIA and DPO – has a DPIA (Article 35 GDPR) been carried out for high-risk processing operations and has a Data Protection Officer been appointed where necessary ?

Our approach: this is how the audit proceeds

A privacy audit at MKB Juristen proceeds in clear steps. First, we map out the scope: which processes, departments, and systems process personal data? Next, we inventory the processing activities and the associated legal bases, data flows, suppliers, and retention periods. Subsequently, we assess the actual situation against the GDPR and the UAVG and record the findings in a report with a priority list. Finally, we discuss the outcomes and, if you wish, assist in addressing any shortcomings – for example, with a privacy protocol, amended data processing agreements, or an improvement plan. Because our teams are mixed (lawyers and in-house counsel), we combine the legal assessment with practical implementation.

Privacy audit, cookie scan and DPIA

A privacy audit rarely stands alone. For websites and online services, a cookie scan useful, as cookie usage falls under telecommunications regulations and the GDPR. If the audit identifies high-risk processing activities, a DPIA the logical next step. If you process a large amount of employee data, the audit also touches upon privacy in employment law. These topics all fall within our core expertise of Privacy and Data Protection, so you can turn to a single team.

Frequently asked questions about the privacy audit

For whom is a privacy audit useful? For any organization that processes personal data, regardless of size. The level of detail differs: a large corporation with international data flows requires a more in-depth investigation than a local entrepreneur, but the accountability obligation applies to both.

How long does a privacy audit take? That depends on the size and complexity of your processing activities. A quick scan for a smaller organization is often completed within a few weeks; a full audit at a larger organization takes more time.

What are the benefits? A report with concrete findings, a risk assessment, and a priority list, so that you can work on your GDPR obligations in a targeted and demonstrable manner.

Is an audit mandatory? The GDPR does not prescribe a periodic audit, but it does require the accountability obligation of Article 5(2) of the GDPR. An audit is the instrument by which you fulfill that obligation.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

What our privacy specialists do for you

A privacy audit is custom-made. We tailor the depth to your organization and also assist with the follow-up.

  • Conducting a full privacy audit or quick scan
  • Drawing up or reviewing the processing register (Article 30 GDPR)
  • Assessing legal bases and processor agreements (Articles 6 and 28 GDPR)
  • Drafting a privacy protocol and data breach procedure
  • Assisting with a DPIA and appointing a Data Protection Officer

Risks of non-compliance

Anyone who cannot demonstrate compliance with the GDPR risks enforcement by the Dutch Data Protection Authority. In addition to a penalty payment order, a fine may be imposed that, pursuant to Article 83 of the GDPR, can amount to up to €20 million or 4% of the worldwide annual turnover. Furthermore, reputational damage and liability towards data subjects (Article 82 of the GDPR) also play a role.

  • Fine or penalty payment order from the Dutch Data Protection Authority
  • Liability towards data subjects under Article 82 of the GDPR
  • Reputational damage following a data breach or complaint
  • No valid legal basis or missing processor agreement
  • No demonstrable compliance with the accountability obligation

Our strategy

We start with the facts: what data do you process, why, and with what risks? Based on this inventory, we assess compliance with the GDPR and the UAVG and translate the findings into a priority list. Because our teams combine lawyers and in-house counsel, it does not stop at a report: we help you demonstrably eliminate shortcomings, tailored to the size and risk profile of your organization.

This is how a privacy audit works

In clear steps from scope to report and follow-up.

01

Intake and initial assessment

We will briefly discuss the situation, the available documents, and your primary interests.

02

Analysis of position and risks

We assess your legal position, supporting documents, deadlines, and possible next steps.

03

Strategic advice

You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.

04

Execution

We assist with correspondence, negotiation, litigation strategy, or further legal assistance.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.

Frequently Asked Questions

The most frequently asked questions about the privacy audit.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

Request a privacy audit?

Would you like to know if your organization demonstrably complies with the GDPR? Contact our privacy specialists for a no-obligation introductory meeting.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation