Budapest, Benczúr utca 28., Hungary |
The GDPR (European General Data Protection Regulation) has applied since 25 May 2018. The Regulation applies to everyone who processes personal data, be it a sole proprietorship, a business entity or a public authority.
Many do not realise it, but image recordings captured by a security camera, the CV of a job applicant and the data provided by a user filling in a contact form on a website also qualify as personal data.
Given that there is no company or organisation that does not, in some way, process the data of natural persons in the course of its activities (consider, for example, the data of clients or employees), no one is exempt from establishing a data-processing practice that complies with the legislation in force and from having the mandatory documentation prepared.
The aim of the data protection audit is to map the data-processing activities of the business, paying particular attention to the scope of the data processed, the scope of the data subjects and the transfer of data. During the audit, we examine whether the business complies with the relevant legislation in the course of processing data.
During the data protection audit, we review the company's current data protection documents, check the existence of the necessary records, as well as the document templates and documents used by the business. Beyond the documents, we uncover the actual practice and details of the data-processing activities through questionnaires and interviews.
As a result of the audit, the client obtains an accurate picture of the current situation of the business and of the areas requiring regulation. On the basis of the audit, it can be determined which documents are necessary to ensure the lawfulness of the business.
The GDPR and sector-specific legislation prescribe the existence of numerous documents and records for data controllers. In addition, the existence of written documentation is also the basis for ensuring the right to information, with particular regard to the principle of accountability. The list of the necessary documents can be determined precisely only in the course of a data protection audit; however, the following records and documents are in most cases indispensable for the purpose of legal compliance:
Data protection documentation is only the first step of legal compliance; however, good practice must be built into every data-processing process of the business. This requires informing and training the staff involved in data processing, as well as the use of appropriate document templates and forms.