There is no universal folder that guarantees you will “pass a GDPR audit.” A regulator, enterprise customer, certification body, and internal reviewer can ask different questions.
The stable requirement is accountability. Article 5(2) of the GDPR says the controller is responsible for and must be able to demonstrate compliance with the principles. Article 24 requires measures appropriate to the nature, scope, context, purposes, and risks.
Prepare a trace from every statement to operational evidence.
1. Define the review
Ask for the scope, period, systems, entities, jurisdictions, evidence format, timetable, and communication channel. Confirm whether the reviewer will examine processor activity, special-category data, AI, profiling, international transfers, or security controls.
Do not send an entire data room before you know the question. Apply access controls and redact unrelated personal data.
2. Reconcile the core records
The following should tell the same story:
- data inventory and flow map;
- record of processing activities, where required;
- privacy and cookie notices;
- lawful-basis and legitimate-interest assessments;
- retention schedule and deletion evidence;
- vendor register, Article 28 terms, and subprocessor records;
- transfer assessments and safeguards;
- DPIAs and DPO or EU-representative decisions;
- rights-request procedure and completed test records;
- security controls, access reviews, and training;
- breach log and notification decisions; and
- change approvals for material processing.
Choose a sample purpose and trace it from collection to deletion. If the notice names a 30-day period but the database keeps the record indefinitely, fix the operation or the statement before presenting it.
3. Test the procedures
Run evidence-producing exercises:
- Export a test user’s data.
- Correct and delete that account.
- Withdraw an optional consent and confirm downstream suppression.
- Restore a backup and verify the deletion handling.
- Review a current vendor and its subprocessors.
- Tabletop a breach, including the Article 33 timing decision.
- Confirm who can approve a high-risk feature.
Record dates, owners, inputs, outcomes, defects, and remediation. A procedure document without a test result is weak evidence.
4. Maintain an issues register
An honest gap with an owner and deadline is more useful than a claim of perfection. For each issue, record severity, affected processing, interim control, owner, target date, and verification method.
Do not hide a known material gap or alter evidence. Keep communications factual and answer the precise request. If the review could lead to enforcement, litigation, contractual liability, or mandatory notification, involve qualified counsel or a data-protection professional.
What GDPR.Direct contributes
GDPR.Direct can generate editable public documents and structured internal drafts from your answers. Its public-page checker can identify a limited set of visible notice issues. It cannot inspect private systems, prove that controls operate, determine all legal duties, or guarantee an audit outcome.
Use the product as one documentation input. Keep the data map, contracts, technical evidence, risk decisions, and human approvals alongside it.
This article is educational information, not legal advice.