Select your language

+49 800 / 27 00 001
We are thrilled to serve you

Mo-Th.: 08:00 - 18:00
Friday: 08:00 - 14:00

Data protection audits and gap analyses

Data protection measures must not only be documented but also implemented effectively in day-to-day operations. Through our audits and gap analyses, we assess the current maturity of your data protection organisation and identify areas in which improvements are required.

The GDPR requires controllers to demonstrate compliance with the data protection principles and to review and update appropriate measures where necessary. Regarding the security of processing, it also requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures.

Graphic Data protection audits and gap analyses

Possible areas of assessment

Depending on the agreed scope, we review areas including:

  • data protection governance, roles and responsibilities
  • involvement of executive management and the Data Protection Officer
  • records of processing activities
  • legal bases and legitimate interests assessments
  • privacy notices and consent procedures
  • handling of data subject rights
  • deletion and retention arrangements
  • data processing agreements and service provider management
  • international data transfers
  • technical and organisational measures
  • personal data breaches and notification procedures
  • data protection impact assessments
  • data protection by design and by default
  • training and awareness measures
  • data protection relating to websites, cloud services, employee data and artificial intelligence systems

Difference between an audit and a gap analysis

During a data protection audit, we assess against defined criteria whether legal and internal requirements have been appropriately implemented and are operating effectively in practice.

A gap analysis compares the current state with a defined data protection target state. It is particularly suitable when establishing a data protection management system for the first time, following organisational changes or when preparing for customer audits or inspections by supervisory authorities.

The assessment may include document reviews, interviews, sample-based testing and the evaluation of available evidence.

Clear and actionable results

Depending on the agreed scope, you will receive:

  • a structured overview of the areas assessed
  • identified strengths and opportunities for improvement
  • identified deviations and documentation gaps
  • an assessment of their respective criticality
  • specific recommendations for action
  • a prioritised action plan
  • an executive summary upon request

Where we have previously been involved in the operational implementation of individual data protection measures, the scope of the assessment and the allocation of roles are defined in a way that avoids inappropriate self-review.

Data protection audits and gap analyses with consulting and training

Our audits and gap analyses provide transparency regarding the maturity of your data protection management and identify the areas in which targeted improvements are required.

Address

Frommel Datenschutz GmbH
Akazienstr. 6a
61352 Bad Homburg
Germany

Contact

Opening hours

Mo.-Th.: 08:00 a.m. – 06:00 p.m.
Friday: 08:00 a.m. – 02:00 p.m.
Saturday: on appointment
In case of emergencies at any time

Our strengths

  • Free and non-binding initial consultation
  • Competent, individual and ongoing support
  • Practical and illustrative use cases
  • Pragmatic solutions
  • Many years of experience