Data protection audits are invaluable for organisations in assessing their current state of data protection compliance. They can identify where the organisation is getting things right, as well as reveal where there are weaknesses or risks of non-compliance which require action or changes to internal procedures.
Regular audits or compliance reviews can assist with risk management and accountability, as well as providing assurance to management and other stakeholders on data protection compliance within an organisation.
This course offers practical guidance on conducting data protection audits, and covers:
- the purpose of data protection audits
- how to decide on an audit methodology (including consideration of the ICO’s methodology)
- determining what areas to review, and preparing an audit plan
- practical guidance on how to undertake the audit, including reviews of documents, processes and systems, and interviews with staff members
- consideration of both policies and procedures which govern the processing of data, and the practical implementation of those policies and procedures
- how to assess processes against specific requirements of data protection law
- who to involve in the audit
- how to review the activities of third-party suppliers (including processors)
- how to report the results of an audit, and address the gaps
Delegates will work through a practical scenario, and sample checklists and audit templates will be provided.
It is recommended that delegates attending this course have some existing knowledge of data protection. Those with no existing knowledge should attend Data Protection Essential Knowledge – Level 1 before attending this course.
"Very useful textbook, well explained and great workshops. Overall an amazing course and well presented."