The Privacy Audit service will validate that your data privacy practices meet your applicable regulatory requirements for either the GDPR (General Data Protection Regulation) and Data Protection Act 2018 (DPA), the PECR (Privacy and Electronic Communications Regulations), or both.
Regulatory compliance is not a one-off exercise. True compliance involves consistently identifying and managing emerging privacy and security risks. An internal audit, conducted by a privacy expert, can help you validate whether your practices are in line with the GDPR and/or PECR (as applicable).
Get independent assurance that your data privacy policies and practices meet the relevant legal requirements.
Identify and resolve operational and systemic weaknesses in your organisation’s handling of personal data and direct marketing practices.
Gain stakeholder confidence in your data privacy processes.
Demonstrate your organisation’s commitment to data security and privacy, and protecting individuals’ rights and freedoms.
Our experienced data privacy team will assess your organisation’s data privacy and information security practices through an on-site compliance audit, checking them against relevant regulatory requirements, ICO (Information Commissioner’s Office) guidance and IT Governance best practice.
We will:
After the audit, you’ll receive a report that records the consultant’s observations and findings, as well as a separate audit tool workbook that contains the detailed audit results.
This is not a legal service, but our sister company GRCI Law Limited can offer legal advice where potential legal issues are identified.
GDPR Audit | PECR audit |
---|---|
|
|
For more information, download the service description
Gap analysis | Audit |
---|---|
Exclusively question-based (‘Do you do X?’). | Evidence-based: the consultant needs to be able to see X is done (so must be on site). |
Typically conducted at an early stage in the compliance programme. | Typically conducted when the organisation believes it is already compliant. |
The price is applicable for organisations with up to 500 employees, based at a single main site.
For larger or more complex organisations, please contact us for a custom quote by emailing servicecentre@itgovernance.co.uk.
The fee excludes any necessary travel, accommodation and subsistence expenses. Expenses will be assessed and charged in arrears.
Discounts for multi-year audits only apply when a two- or three-year contract is agreed at the purchase of the first audit; discounts cannot be backdated.