A data protection audit - whether from a supervisory authority, an enterprise client or an investor - is won or lost on whether you can produce documents quickly. Authorities don't test whether you understand GDPR; they ask for evidence that you follow it, usually on a short deadline. This guide covers exactly what gets requested, how to assemble it in advance, and how to run a mock audit so the real one holds no surprises. For the overview and a self-score, see the GDPR compliance checklist pillar.
- Authorities request documents - a coherent paper trail is the whole defence.
- Deadlines are short; assemble the pack before you're asked, not after.
- A mock audit surfaces gaps while they're still cheap to fix.
What Triggers a Data Protection Audit?
Why might we get audited?
Audits arrive three ways: a complaint (from a customer, employee or competitor), a reported breach, or routine/sector activity by the authority. Increasingly there's a fourth - an enterprise client or investor running due diligence before signing. The trigger differs, but the request is the same: show your documentation.
What Authorities Typically Request
What's in the request?
| Document | What it proves |
|---|---|
| <a href="/en/resources/records-of-processing-activities" data-kind="site">ROPA</a> | You know what data you process and why |
| <a href="/en/resources/privacy-notice-template" data-kind="site">Privacy notice</a> | Transparency toward data subjects (Art. 13-14) |
| <a href="/en/resources/data-processing-agreement-template" data-kind="site">DPAs</a> | Lawful use of processors (Art. 28) |
| <a href="/en/resources/tom-data-protection-checklist" data-kind="site">TOM</a> | Appropriate security (Art. 32) |
| Breach records | A working 72-hour process (Art. 33) |
| Training records | Staff competence and accountability |
| DPIAs | Risk assessment for high-risk processing (Art. 35) |
A company that produces these consistently is in a strong position. One that can't has no line of defence, regardless of how careful its actual practices are.
How to Assemble Your Audit Pack
What do I prepare in advance?
1. Keep a single, current index of the seven documents above, each with an owner and a last-reviewed date.
2. Resolve the obvious gaps first - a missing DPA or an outdated ROPA is the fastest finding.
3. Pre-write your breach narrative - even with no breaches, document that the process exists and was tested.
4. Store it where it can be exported in a day - the deadline after a request is short.
Audit Preparation Checklist (PDF)
Run a Mock Audit
How do I test readiness before the real thing?
Pick a recent processing activity and trace it end to end: is it in the ROPA, named in the privacy notice, covered by a DPA, protected by documented TOM, and - if high-risk - assessed in a DPIA? If any link is missing, that's a real-world finding you've caught early. Run this quarterly on a different activity each time; it's the cheapest insurance there is.
ETHYX keeps your audit pack assembled and current in one place, and ETHYX clients get a certified external DPO who owns audit readiness - so a request comes with a ready answer, not a scramble.