By Marta Lukovic, Attorney at Law, Data Protection, Zunic Law Firm (Legal 500 recognised). Reviewed by Tamara Zavisic, AI Governance Consultant.
In this article: What a GDPR audit actually examines, the 12-area readiness checklist, what gets organisations into trouble, how to maintain audit readiness year-round, and FAQ.
Most organisations find out what a GDPR audit actually looks at the moment an investigation begins. That is the worst possible time to find out.
European DPAs issued €7.1 billion in cumulative fines since May 2018, with €1.2 billion issued in 2025 alone (DLA Piper GDPR Fines and Data Breach Survey, January 2026). The cases behind those numbers share a following pattern, not a single catastrophic failure, but an accumulation of documentation gaps, process inconsistencies, and control weaknesses that looked manageable individually and were devastating in combination.
What I see, working with organisations preparing for DPA enquiries, is that the gap is rarely in intent. Most controllers take GDPR seriously. The gap is in readiness, the ability to produce the right document, the right evidence, and the right explanation at the moment a regulator asks for it. Preparation that starts when the letter arrives is not preparation at all.
This checklist covers the 12 areas regulators examine in a GDPR audit. For each area, it sets out what you need to have ready, not just what you need to have done. For the full GDPR compliance framework underlying these requirements, see our GDPR compliance guide.
What a GDPR Audit Actually Examines
TL;DRTL;DR: A GDPR audit, whether conducted internally or triggered by a DPA inquiry, examines whether your data processing activities comply with the regulation in practice, not just on paper. The terms "GDPR audit" and "data protection audit" are used interchangeably; both refer to the same structured review. Regulators check documentation, processes, technical measures, and evidence that controls are working. Having a privacy policy is not the same as having a compliant programme. The audit asks whether what you documented matches what you actually do.
The word "audit" covers several different situations. An internal audit is a planned review your DPO or compliance team conducts. A supervisory authority audit is a formal investigation, triggered by a complaint, a breach notification, or a DPA initiative programme. Both examine the same evidence, but the stakes are different.
Regulators do not arrive expecting perfection. They arrive expecting accountability, evidence that the controller knows what it processes, why, on what legal basis, with what safeguards, and with what outcome when things go wrong. The absence of that evidence, more than the underlying issue, is what drives enforcement.
The GDPR Enforcement Tracker maintained by CMS Law records over 2,800 enforcement actions. The recurring triggers in the largest cases are not exotic technical failures. They are based on the breach of some of the essential rules, such as:
- 1.Insufficient legal basis for data processing
- 2.Non-compliance with general data processing principles
- 3.Insufficient technical and organisational measures to ensure information security
- 4.Insufficient fulfilment of information obligations
- 5.Insufficient fulfilment of data subjects' rights
This is by no means an exhaustive list. Other reasons for penalties (such as insufficient cooperation with the supervisory authority, inadequate fulfillment of data breach notification obligations, or insufficient involvement of the data protection officer) have been used, although less frequently.
The GDPR Audit Readiness Checklist: 12 Areas
TL;DRTL;DR: The GDPR audit checklist below maps to the obligations regulators examine most consistently: records of processing, legal bases, privacy notices, data subject rights, DPAs with processors, DPIAs for high-risk activities, security measures, breach response, international transfers, DPO designation and independence, staff training, and retention and deletion. Each area requires both operational practice and documentary evidence.
1. Records of Processing Activities (RoPA)
What regulators ask for first. Article 30 GDPR requires controllers to maintain records of all processing activities.
The record must cover: purposes, data categories, data subject categories, recipients, international transfers, retention periods, and security measures in place.
Before an audit, verify whether every active processing activity is documented, the legal basis for each is specified and defensible, retention periods are stated, and the record was last reviewed within 12 months. A RoPA that was completed once and not maintained is a liability, not an asset.
See our guide to maintaining your Records of Processing Activities for the full Article 30 field requirements.
2. Legal Bases for Every Processing Activity
For each entry in your RoPA, you must be able to state the specific legal basis you relied on and explain why it applies. A DPA investigation into Meta's advertising practices found that "legitimate interests" was claimed without any documented balancing test. The fine was €1.2 billion. The lesson is not that legitimate interests is unusable. It is that the assessment must be documented before the processing starts, not reconstructed after the investigation begins.
Regulatory stakes: Article 6 legal basis failures. Violations of lawful basis for processing accounted for 90% of total fine value in 2025 (Surfshark, GDPR Enforcement Tracker analysis, January 2026). Every processing activity without a documented and defensible legal basis is a material enforcement risk. Article 83(5) GDPR sets the maximum fine at €20 million or 4% of global annual turnover.
3. Privacy Notices and Transparency Documentation
Privacy notices are a frequent audit trigger because they are publicly visible and easy for regulators to check before contacting you. Article 13 GDPR requires you to provide specific information at the point of data collection. Article 14 sets equivalent requirements when data is collected from third parties.
The notice should comprehensively cover all processing activities recorded in your RoPA, clearly identify the applicable legal bases, specify retention periods or the criteria used to determine them, explain data subject rights and how they can be exercised, and confirm that it has been reviewed and updated following the most recent change in processing activities.
4. Data Subject Rights: Process and Evidence
Regulators look for two things here:
- A documented process for handling requests, and
- A record showing it was followed.
Having a process written in a policy is not the same as having evidence that requests were handled within the 30-day window, that identity verification was conducted correctly, and that exemptions were applied with documented reasoning.
Before an audit, review the last 12 months of data subject requests. Confirm each was completed on time. Confirm refusals were documented with legal grounds. If you have no record of any requests, consider whether your intake process is functioning or simply invisible to the people whose data you hold.
5. Data Processing Agreements with Processors
Every processor you use must be covered by a written Data Processing Agreement meeting the requirements of Article 28 GDPR. The agreement must specify the subject matter, duration, nature, and purpose of the processing, the type of personal data, the obligations of the processor, and your right to audit.
The vendor landscape has expanded significantly. Cloud infrastructure, SaaS tools, marketing platforms, HR systems, and analytics providers are all processors if they handle personal data on your behalf. See our GDPR vendor management guide for the full DPA requirements. Every live processor relationship must be documented, the DPA is signed, and your sub-processor list must be current.
A signed DPA is necessary, but it is not sufficient. The McDonald's Poland case settled this point at a cost of €4 million. In July 2025, Poland's UODO fined McDonald's Polska €4,022,773 for failures in processor oversight. The company had a DPA with its employee scheduling vendor, 24/7 Communication, but had not assessed whether that vendor had adequate technical and organisational measures in place before entrusting it with sensitive employee data, including PESEL numbers and passport details. The data became publicly accessible through a misconfigured server. The fine was imposed not because the DPA was absent, but because it was never verified.
Enforcement: McDonald's Poland, UODO, July 2025: €4,022,773. UODO found that McDonald's failed to conduct a risk analysis before selecting its processor, did not verify the vendor's technical and organisational measures, and did not involve the DPO in the processor selection process. The penalty was imposed under Articles 24, 25, 28, 32, and 38 GDPR. The processor received a separate fine of €43,680. Source: EDPB, Polish SA decision, July 2025.
Confirm you have not only signed DPAs but have also conducted a vendor assessment for every processor handling sensitive or high-volume data. That assessment must cover:
- The processor's technical measures (encryption, access controls, vulnerability management),
- Organisational measures (staff training, incident response procedures, sub-processor oversight), and
- Documented evidence that those measures were in place before processing began.
Self-attestation by the vendor is not sufficient. You need to request evidence such as security certifications, penetration test summaries, audit reports, or completed security questionnaires against a recognised framework such as SIG or CAIQ.
For the full vendor assessment framework, see our GDPR vendor management guide. Whisperly's vendor assessment module automates the questionnaire workflow, collects evidence, and generates a documented assessment record that satisfies the Article 28(1) obligation to verify processor suitability.
6. Data Protection Impact Assessments for High-Risk Processing
A DPIA is mandatory for processing that is likely to result in a high risk to individuals, including systematic profiling, large-scale sensitive data processing, and systematic monitoring of public spaces (Article 35 GDPR). The EDPB has published a list of processing types that always require a DPIA.
Every high-risk processing activity in your RoPA has a corresponding completed DPIA, the DPIA identifies the risks and mitigation measures, and the measures were implemented before processing began. A DPIA completed after the fact does not satisfy the obligation. For the full process, see our DPIA guide.
Also, be especially careful with the DPIA for the use of AI Systems, as this is where most gaps occur lately.
7. Technical and Organisational Security Measures (TOMs)
Article 32 GDPR requires controllers and processors to implement appropriate technical and organisational measures, calibrated to the risks associated with the processing activities. Regulators do not expect identical controls from a ten-person company and a ten-thousand-person enterprise; however, they do expect clear evidence that risks have been properly assessed and that proportionate measures have been implemented.
What does that evidence look like in practice during an audit? Typically, it includes documented security policies, access control logs, encryption standards and specifications, vulnerability assessment reports, as well as established procedures for regularly testing, assessing, and evaluating the effectiveness of these measures. Certifications such as ISO 27001 or SOC 2 may serve as supporting evidence, but they do not replace the need for robust, underlying documentation. Companies are increasingly expecting vendors to maintain a dedicated Trust Page, along with a structured system that enables easy access to relevant policies and compliance documentation.
8. Breach Notification: Process, Records, and Response History
The 72-hour notification requirement under Article 33 GDPR is one of the most consistently enforced provisions. Regulators examine whether you have a functional process for detecting, assessing, and notifying breaches, not just a policy that says you do.
Audit-readiness check means:
- 1.You have a documented breach response procedure.
- 2.You can identify who is responsible at each stage.
- 3.You have a record of all breaches detected in the past 36 months (including those below the notification threshold, which must also be documented under Article 33(5)).
- 4.Your breach log shows the reasoning behind notification decisions.
See our GDPR data breach notification guide for the 72-hour rule in full.
9. International Data Transfers
Cross-border data transfers are the category that produced the largest individual fines in 2025. The Irish DPC fined TikTok €530 million for transferring EEA user data to China without adequate safeguards. The fundamental requirement has not changed since the Schrems II ruling: standard contractual clauses alone are not sufficient if the legal environment in the destination country creates risks the clauses cannot address.
Audit-readiness check requires every transfer of personal data outside the EEA or to a country without an adequacy decision is documented, covered by an appropriate transfer mechanism, and supported by a transfer impact assessment that was completed before the transfer began.
10. DPO Designation, Independence, and Involvement
If you are required to designate a Data Protection Officer under Article 37 GDPR, auditors examine three things:
- Designation is documented and notified to the DPA.
- The DPO has sufficient resources and access to carry out their role.
- The DPO is involved in data protection decisions before they are made, not consulted after the fact.
The EDPB Guidelines 07/2020 on the role of the DPO make clear that a DPO who is not consulted until a decision is already implemented is not fulfilling the statutory function. Document DPO involvement in high-risk processing decisions, DPIA reviews, and breach assessments.
Independence is not a formality. It is a structural requirement, and regulators are testing it.
In October 2024, Austria's DSB fined a company for appointing its managing director as DPO. The authority found no dedicated working hours, no separate budget, and no direct reporting line to the supervisory board for the DPO function.
A similar case in Poland resulted in a €132,000 fine against a company whose DPO simultaneously headed the internal audit department. The UODO concluded that overlapping functions undermine the DPO's ability to act autonomously without influence.
What genuine DPO impartiality requires. Regulators now examine DPO contracts and reporting lines, budget allocations dedicated to the DPO function, whether the DPO holds any role that defines the purposes or means of data processing (marketing, IT, legal, finance, HR all create conflicts), and whether the DPO was actually consulted before processing decisions were made.
The EDPB's 2024 Coordinated Enforcement Framework report, covering 25 supervisory authorities across the EEA, found that limited independence and restricted access to senior management were among the most common DPO failures.
In practice, if your DPO also holds a line management role, a commercial function, or any position that shapes how data is used, you face a conflict of interest that a formal title cannot resolve. The question regulators ask is whether the DPO could tell senior management to stop a processing activity and survive the conversation. If the answer is no, the independence requirement is not met.
11. Staff Training and Awareness
Staff training is a frequently overlooked audit area because it does not produce a single document that regulators can examine. What they ask for instead is training completion records by role, the date of the most recent training cycle, whether training covers the specific processing activities the organisation conducts, and whether there is a process for training new joiners before they access personal data.
A training policy that says "all staff complete annual GDPR training" with no completion records is not evidence of compliance. Completion records with no evidence that the training content covered relevant processing activities are incomplete. Both are examined.
12. Data Retention and Deletion
Retention periods must be documented in the RoPA and enforced in practice. The two questions a regulator asks are:
- How long do you hold personal data?
- How do you ensure it is deleted when that period ends?
The honest answer in most organisations involves a manual process that is inconsistently followed, a deletion log that does not exist, and data held for years beyond the documented period.
Audit-readiness check requires retention periods to be stated per processing activity, a deletion or anonymisation process exists and is documented, and you have evidence that it runs. If you cannot demonstrate that data is actually deleted, the policy is not in compliance.
Whisperly enables companies to track deadlines for data deletion and never miss any deadline again.
What Gets Organisations Into Trouble in GDPR Audits
TL;DRTL;DR: The most common audit failures are not dramatic technical breaches. They are: RoPA entries that do not match actual processing, legal bases documented in a policy but not reviewed against reality, DPAs that are unsigned or outdated, DPIAs that were drafted after processing began, and breach records that are absent because no one thought sub-threshold breaches needed to be logged. Each of these is a documentation failure, not a processing failure.
Most enforcement actions that produce large fines involve documentation failures, not processing failures. The organisation was often doing something defensible. They just could not prove it.
A 400-person SaaS company I worked with during a GDPR audit preparation had ISO 27001 certification, a well-maintained security programme, and privacy notices that had been drafted by a specialist firm. What they lacked is signed DPAs with three of their twelve processors, a deletion log for customer data (retention was 12 months per the policy; the actual data went back 4 years), and any evidence that the DPO had been consulted before the introduction of a behavioural analytics tool 18 months earlier. None of those issues was fatal individually. Together, they produced a finding that required 6 months of remediation under regulatory scrutiny.
The table below maps the most common audit failure points to the checklist area they belong to.
| Common failure | Checklist area | What the regulator sees |
|---|---|---|
| RoPA not updated after product change | Area 1: RoPA | Processing without documented legal basis |
| Legitimate interests used without balancing test | Area 2: Legal bases | Unlawful processing under Art. 6 |
| Privacy notice not updated after new use case | Area 3: Notices | Failure of transparency under Art. 13 |
| No record of DSARs received | Area 4: Data subject rights | Cannot demonstrate compliance with Art. 12 to 23 |
| DPA unsigned with SaaS vendor | Area 5: Processor agreements | Processor instruction not documented per Art. 28 |
| DPIA missing for profiling activity | Area 6: DPIAs | Mandatory pre-processing assessment not completed |
| No sub-threshold breach log | Area 8: Breach response | Failure of Art. 33(5) documentation obligation |
| Data held beyond stated retention period | Area 12: Retention | Storage limitation violation under Art. 5(1)(e) |
Maintaining GDPR Audit Readiness Year-Round
TL;DRTL;DR: Audit readiness is not a project with an end date. It is a state maintained through four recurring processes: quarterly RoPA reviews to catch processing changes, annual DPA reviews to ensure processor contracts are current, a breach log that is actively maintained between incidents, and a training cycle that produces completion records. Organisations that maintain these four processes are audit-ready as a byproduct of their operations, not because they scrambled before a review.
The checklist above is most useful as a point-in-time assessment. For organisations with a DPO, a quarterly GDPR internal audit review using this GDPR audit checklist is the most practical cadence. The goal is to reach a state where working through it produces no surprises, not because you prepared for the audit but because your programme runs that way every quarter.
Four processes make the difference between organisations that are routinely audit-ready and those that are perpetually catching up:
| Activity | Frequency | Description | Key Evidence / Output |
|---|---|---|---|
| Quarterly RoPA Review | Quarterly | Set a calendar trigger. The DPO or compliance lead verifies whether new processing activities have started, existing ones changed in scope/purpose, or any have ceased. Update the RoPA before the quarter closes. | Updated RoPA reflecting current processing activities |
| Annual DPA Review | Annually | Review the full list of processors. Verify signature status, ensure clauses are up to date (including correct SCC versions), and check sub-processor notifications. | Signed and current DPAs; record of sub-processor notifications |
| Active Breach Logging | Ongoing | Maintain a breach log continuously. Assess and document every personal data incident, including those not qualifying as notifiable breaches. | Breach log with documented assessments (Article 33(5) evidence) |
| Training Cycle with Completion Records | Annually (minimum) | Conduct training with role-specific modules. Ensure new joiners complete training before accessing personal data. Maintain detailed completion records. | Training records (employee, date, module) |
How Whisperly Automates the GDPR Internal Audit so you are always ready for the DPA Audit
TL;DRTL;DR: Whisperly's internal audit feature gives compliance teams and their consultants a structured, agent-driven audit workflow that covers the same 12 areas in this checklist. AI agents run automated questionnaires across departments, generate auditor findings with evidence references, flag confidence gaps where documentation is absent or inconsistent, and classify each gap by risk level. The result is an audit report that would take a consultant weeks to produce manually, completed in hours.
Identifying compliance gaps before a regulator does is the purpose of every internal audit. The obstacle is not usually willingness; it is the time and expertise required to work through the full scope of what needs to be examined. A DPO at a 300-person company is rarely in a position to run a structured 12-area audit while simultaneously managing data subject requests, reviewing DPAs, and handling ongoing legal queries.
Whisperly's internal audit feature is designed precisely for this scenario. It combines AI agents with a structured audit workflow that mirrors the approach of an experienced data protection professional: systematic, evidence-driven, and focused on producing clear, actionable findings rather than merely descriptive observations.
Automated Audit Questionnaires Across Departments
The audit begins with structured questionnaires distributed automatically across the relevant parts of the organisation. Rather than a DPO manually interviewing the HR team, the IT department, and the marketing function in sequence, Whisperly's agents send targeted, role-specific questionnaires drawn from the GDPR's requirements and calibrated to the department's processing activities.
Each questionnaire maps directly to one or more of the 12 audit areas above. The HR questionnaire covers lawful bases for employee data, retention periods, and training records. The IT questionnaire covers security measures, access controls, and breach detection procedures. The procurement questionnaire covers processor identification and DPA status. Responses feed directly into the audit workspace; no manual collation required.
AI-Generated Auditor Findings with Evidence References
Once questionnaire responses are collected, Whisperly's agents cross-reference them against the organisation's existing compliance documentation: the RoPA, signed DPAs, completed DPIAs, breach logs, and training records. Where a response claims a control is in place, the agent checks whether the corresponding documentation exists and whether it is current.
Each finding is generated with an evidence reference: the specific document, record, or response that supports or contradicts the finding. This is the difference between an audit observation that says "DPA status is unclear" and one that says "DPA with Vendor X is unsigned as of March 2026; RoPA entry 14 identifies this vendor as processing customer data under contractual necessity." The second version is what regulators expect. It is also what makes remediation actionable and direct.
Confidence Gap Scoring: Knowing What You Cannot Prove
Not every compliance gap is a clear failure. Many are confidence gaps: situations where the control probably exists, but the documentation does not prove it. A deletion procedure that runs automatically but has never been tested and logged is not a missing control; it is an unverified one. The distinction matters because the remediation is different.
Whisperly assigns a confidence score to each audit finding. High confidence means the control exists and is documented. Low confidence means the control may exist but cannot be demonstrated from available evidence. Unverified findings are flagged separately from confirmed gaps, giving DPOs and consultants a clear view of where documentation work is needed versus where the underlying process needs to be fixed.
This matters specifically in the context of a DPA investigation. A regulator does not accept "we do this but we have not documented it." The confidence gap score identifies exactly those situations before a regulator does. That is the point.
Risk Classification: Prioritising What to Fix First
Every finding produced by the audit is classified by risk level: critical, high, medium, or low. The classification combines the severity of the GDPR obligation implicated, the likelihood that the gap would be identified in a DPA investigation, and the potential fine exposure under Article 83. A missing legal basis for a core processing activity is critical. An outdated privacy notice section that does not affect any current data subject relationship is low.
The risk classification produces a prioritised remediation plan, not a flat list of 40 items that leaves the DPO or consultant to guess what to address first. Critical and high findings include suggested remediation steps with references to the relevant GDPR article and the corresponding Whisperly module that addresses it.
For DPOs, Legal Teams, and External Consultants
The audit feature is designed to work for both internal teams and the external consultants they bring in. A consultant conducting a gap assessment for a new client can run the structured questionnaire workflow, review AI-generated findings against their own analysis, and export a full audit report with findings, confidence scores, and risk classifications in the format a client or regulator would expect.
For internal DPOs running a quarterly review, the same workflow serves as a structured point-in-time snapshot that can be compared against previous quarters, showing whether the compliance posture is improving, stable, or deteriorating. The audit trail itself becomes an accountability asset: evidence that the organisation conducts regular, structured, documented compliance reviews.
Whisperly's GDPR compliance platform and internal audit feature are available to organisations and their compliance consultants on the Advanced plan. The audit workflow, questionnaire builder, finding generation, confidence scoring, and risk classification are all included. Schedule a demo to walk through the internal audit feature with a member of the Whisperly team.
Further Reading on Whisperly
Questions & Answers
What is the difference between a GDPR audit and a DPA investigation?+
A GDPR audit (also called a GDPR compliance audit) is an internal review of your compliance programme, typically conducted by your DPO or an external assessor. A DPA investigation is a formal enforcement action initiated by a supervisory authority, usually following a complaint, a reported breach, or the authority's own initiative programme. Both examine the same evidence, but a DPA investigation carries enforcement powers including the ability to issue fines, corrective orders, and processing bans. The best preparation for a DPA investigation is a functioning internal audit programme.
How long does a GDPR audit take?+
An internal audit of a mid-sized organisation typically takes 6 to 12 weeks from scope definition to final report. The timeline depends on the number of processing activities, the maturity of existing documentation, and the availability of the teams being interviewed. Organisations with a maintained RoPA and current DPAs move significantly faster than those building the documentation base during the audit. A DPA investigation has no standard timeline; complex cases involving cross-border processing have taken 2 to 4 years to conclude.
Does a GDPR audit apply to small and medium-sized businesses?+
Yes. The GDPR applies to all controllers and processors who process personal data of EU residents, regardless of size. The exemption in Article 30(5) GDPR that allows organisations with fewer than 250 employees to maintain a more limited RoPA applies only to processing activities that are occasional, do not involve special category data, and are unlikely to risk the rights of individuals. Most organisations process data in ways that fall outside this exemption. The GDPR Enforcement Tracker shows that enforcement actions against SMEs are common, particularly from Spain's AEPD.
What documents should I have ready before a GDPR audit?+
The core documentary package: your Records of Processing Activities with legal bases documented for every activity, signed Data Processing Agreements with all processors, completed DPIAs for high-risk processing activities, your breach log covering the past 36 months (including sub-threshold incidents), privacy notices current as of your most recent processing change, training completion records for the current and previous year, and your DPO designation notice.
How often should a GDPR audit be conducted?+
Most data protection practitioners recommend an annual internal audit as the minimum. Organisations with material processing changes, a recent breach, or significant business changes (merger, new product line, new markets) should conduct an out-of-cycle review. The GDPR does not specify a frequency, but the accountability principle under Article 5(2) requires you to demonstrate ongoing compliance, which a single historical audit cannot achieve. For organisations without dedicated compliance staff, a quarterly readiness review using the checklist above is a practical alternative to a full annual audit.

Written by
Marta Lukovic
Marta Luković is an Attorney at Law specialising in Data Protection, IT Law, and AI Law. She advises companies across Southeast Europe on GDPR compliance, cross-border data transfers, and regulatory risk management. Recognised for her practical, commercially aware approach to privacy law, she works closely with technology companies navigating complex regulatory environments across multiple jurisdictions.
Reviewed by: Tamara Zavisic, AI Governance Consultant