Preparing for a Data Protection Audit
Your organisation may find itself subject to a Data Protection Audit by the Data Protection Commission (“DPC”) in compliance with GDPR and the Data Protection Acts 1988 – 2018. These audits can be conducted at very short notice to the data controller or data processor and do not have to be carried out on foot of a complaint received by the DPC.
Remember: data protection compliance is not the same in every organisation and it may need to be adapted based on the type of business that you operate.
Here are 5 practical steps you can take:
Review your data protection policies and procedures to ensure they are up to date and GDPR compliant
As part of this you should ensure that:
- your policies are relevant to your organisation’s data processing activities and organisational structure;
- you should include policies on:
-
- data subjects’ rights;
- privacy policies;
- employee handbook; and
- a data retention policy.
Provide staff with training and awareness
All staff need to be trained on their data protection obligations and on the organisation’s policies.
It is important that you can show that an appropriate level of training has been provided. You can do this by maintaining records, such as:
- sign-in sheets;
- records of online assessments; and
- circulating relevant and up to date literature to your staff.
Know your data
It is important to have an up to date data processing log to show the range of ways in which your organisation processes personal data. If you process personal data, you need to be clear on:
- what data you process;
- why; and
- on what basis.
This is particularly important if you process “sensitive personal data”. This includes:
- medical data;
- financial data; and
- details of religious memberships.
There are more stringent security and processing requirements for sensitive data, and it is essential that these are followed.
Be ready
An effective way to prepare for an audit is to carry out an annual mock audit.
This will involve reviewing your policies to make sure they are up to date and to ensure your organisation can deal with a breach within the 72-hour time frame.
All potential security breaches need to be reviewed such as:
- open files on desks;
- unlocked computers and electronic devices; and
- notes left in open spaces with passwords and third-party information displayed on them.
During an audit, the DPC will require evidence that the appropriate security requirements are in place and working properly.
You need to check that there is a good reporting system in place so that organisations are aware that it must any issues or problems report to the Data Protection Officer or the person responsible for Data Protection within the organisation.
Is your data secure?
During your mock audit, check that the security system is sufficient.
As a data controller, you must prevent unauthorised access to personal data held by you and by data processors who work for you.
Consider technologies like encryption and physical safeguards such as locked storage within company, which seem like obvious items, but can be easily overlooked.
If you store data in the cloud, check that you have appropriate protections in place with your cloud service provider and what the remedies are in case the data is breached in any way.
How we can help?
If you have any queries or concerns, or are the subject of a Data Protection Audit, please feel free to contact Aideen Shanley, Brian Baily, or any member of the BHSM team to discuss how best to prepare for, and navigate, the process.
This article is for general information purposes. Legal advice must be obtained for individual circumstances. Whilst every effort has been made to ensure the accuracy of this article, no liability is accepted by the author for any inaccuracies.