Conducting a Privacy Audit Print

  • 0

Checking whether practice matches policy.

WHAT AN AUDIT ESTABLISHES

Whether what you claim is what you do.

WHAT TO EXAMINE

The inventory, against reality Forms, against stated purposes Systems, against the access list Retention, against the schedule Processors, against agreements Notices, against practice

HOW TO CHECK THE INVENTORY

Pick a system and list what it holds, then compare.

WHAT THAT USUALLY REVEALS

Data nobody recorded.

HOW TO CHECK RETENTION

Query the oldest record in each system.

WHAT THAT USUALLY REVEALS

Nothing has ever been deleted.

HOW TO CHECK ACCESS

List who has access to each system, and compare against roles.

WHAT THAT USUALLY REVEALS

Departed staff, and permissions nobody remembers granting.

HOW TO CHECK MARKETING

Opt out, and see whether messages stop.

HOW TO CHECK RIGHTS HANDLING

Submit a request yourself.

WHY

It reveals whether the process exists in practice.

WHAT TO PRODUCE

A list of findings, ranked by risk.

WHAT TO DO WITH IT

Fix the top ones, with dates and owners.

WHAT TO RECORD

The audit, the findings, and the remediation.

WHAT TO SCHEDULE

The next one.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot