Skip to main content
tutorial

Preparing for a GDPR review: build the evidence trail first

Prepare for a customer, regulator, or internal GDPR review by connecting policies to data maps, contracts, controls, and tested procedures.

GDPR.Direct Editorial Team
January 15, 2025
7 min read

There is no universal folder that guarantees you will “pass a GDPR audit.” A regulator, enterprise customer, certification body, and internal reviewer can ask different questions.

The stable requirement is accountability. Article 5(2) of the GDPR says the controller is responsible for and must be able to demonstrate compliance with the principles. Article 24 requires measures appropriate to the nature, scope, context, purposes, and risks.

Prepare a trace from every statement to operational evidence.

1. Define the review

Ask for the scope, period, systems, entities, jurisdictions, evidence format, timetable, and communication channel. Confirm whether the reviewer will examine processor activity, special-category data, AI, profiling, international transfers, or security controls.

Do not send an entire data room before you know the question. Apply access controls and redact unrelated personal data.

2. Reconcile the core records

The following should tell the same story:

  • data inventory and flow map;
  • record of processing activities, where required;
  • privacy and cookie notices;
  • lawful-basis and legitimate-interest assessments;
  • retention schedule and deletion evidence;
  • vendor register, Article 28 terms, and subprocessor records;
  • transfer assessments and safeguards;
  • DPIAs and DPO or EU-representative decisions;
  • rights-request procedure and completed test records;
  • security controls, access reviews, and training;
  • breach log and notification decisions; and
  • change approvals for material processing.

Choose a sample purpose and trace it from collection to deletion. If the notice names a 30-day period but the database keeps the record indefinitely, fix the operation or the statement before presenting it.

3. Test the procedures

Run evidence-producing exercises:

  1. Export a test user’s data.
  2. Correct and delete that account.
  3. Withdraw an optional consent and confirm downstream suppression.
  4. Restore a backup and verify the deletion handling.
  5. Review a current vendor and its subprocessors.
  6. Tabletop a breach, including the Article 33 timing decision.
  7. Confirm who can approve a high-risk feature.

Record dates, owners, inputs, outcomes, defects, and remediation. A procedure document without a test result is weak evidence.

4. Maintain an issues register

An honest gap with an owner and deadline is more useful than a claim of perfection. For each issue, record severity, affected processing, interim control, owner, target date, and verification method.

Do not hide a known material gap or alter evidence. Keep communications factual and answer the precise request. If the review could lead to enforcement, litigation, contractual liability, or mandatory notification, involve qualified counsel or a data-protection professional.

What GDPR.Direct contributes

GDPR.Direct can generate editable public documents and structured internal drafts from your answers. Its public-page checker can identify a limited set of visible notice issues. It cannot inspect private systems, prove that controls operate, determine all legal duties, or guarantee an audit outcome.

Use the product as one documentation input. Keep the data map, contracts, technical evidence, risk decisions, and human approvals alongside it.

This article is educational information, not legal advice.

GDPR.Direct Editorial Team

GDPR.Direct Editorial Team

Source-led product guidance. No legal or professional review is implied.

Ready to Create Your First Draft?

Answer the questions, verify the text, and publish only what you approve

Get Started Free

No credit card required • Free forever plan available