GDPR diagnostic & compliance assessment GDPR audit — complete assessment of your personal data compliance

We deliver a complete GDPR audit to identify your non-compliance risks: processing mapping, legal basis analysis, gap analysis and compliance report. Result: you know exactly where you stand and what to fix first.

You get a clear snapshot of your compliance at a given point in time — with the corrections to make and their priority. GDPR compliance then has to be maintained: documentation and compliance actions must be reviewed and updated regularly.

Report delivered in 3 to 5 weeks
DPO / IAPP certified consultants
Prioritised action plan included

What you get

At the end of the GDPR audit

A clear view of your GDPR compliance level at a given point in time, identified and ranked gaps, and a concrete action plan.

360° Scope assessed
Gaps Qualified & prioritised
Roadmap Concrete actions

An audit your leadership, DPO and operational teams can actually use.

What is a GDPR audit?

A GDPR audit consists of examining an organisation’s personal data processing, practices, contracts and documentation to identify gaps between how it actually operates and the applicable data protection requirements.

It produces a structured diagnostic, identifies risks and prioritises the necessary actions.

Map

Understand which data is processed, why, by whom and with which tools.

Verify

Review legal bases, notices, rights, retention periods, contracts and existing measures.

Assess

Qualify the gaps and risks.

Prioritise

Turn findings into a realistic action plan.

The audit is not just about checking whether you have a privacy policy: it examines how your organisation actually works.

What is the difference between a GDPR audit and a CNIL inspection?

A GDPR audit is not a CNIL inspection. Both relate to data protection, but they do not have the same author, purpose or consequences.

GDPR audit CNIL inspection
Voluntary or internal exercise Inspection by the data protection authority
Diagnostic purpose — gap identification — recommendations Powers and procedures specific to the authority
Preparation and improvement May lead to corrective measures or sanctions depending on the findings

Complianz carries out a compliance audit: we obviously do not perform a “CNIL audit”.

Compliance report within 5 weeks Full confidentiality of data Zero jargon, 100% operational

+150 GDPR audits completed

0 CNIL sanctions post-audit

4.9/5 client satisfaction

Which points do we check during a GDPR compliance audit?

The audit examines how the organisation actually works, not just whether documents exist. These are the structural points we review.

Records of processing

Completeness, updates, purposes, data categories, recipients, retention periods and associated measures.

The records of processing required by Article 30 are a tool for inventorying and documenting compliance.

Legal bases

Consent, contract, legal obligation, legitimate interest or another appropriate ground depending on the processing.

Information of individuals

Information notices, privacy policies and transparency.

Exercise of rights

Access, rectification, erasure, objection, restriction and other applicable requests.

Data retention

Defined, consistent and actually applied retention periods.

Processors

Contracts, safeguards, responsibilities, onward processing and practices.

The controller must in particular ensure that processors provide the necessary safeguards and frame the relationship in accordance with Article 28. See the GDPR processor audit.

Security

Access, backup, incident management, confidentiality and organisation.

Data breaches

Procedure, internal register and ability to handle a notification when required.

When a breach poses a risk to rights and freedoms, notification to the CNIL must take place without undue delay and, where feasible, within 72 hours.

DPIA

Identification of processing likely to require a data protection impact assessment, and review of existing analyses.

A DPIA applies in particular to processing likely to result in a high risk to rights and freedoms.

GDPR governance

Responsibilities, possible DPO, internal procedures, awareness and compliance evidence.

Being compliant on paper is not enough

The GDPR audit compares documentation with actual practice. An up-to-date register only has value if it reflects what really happens in the organisation.

Documents

  • Register
  • Policies
  • Contracts
  • Procedures
  • DPIA

Practices

  • Who actually accesses the data?
  • Are deletions actually carried out?
  • Are data subject requests handled?
  • Are new tools assessed?
  • Are incidents documented?
  • Are vendors monitored?

The accountability principle requires being able to demonstrate compliance through effective internal mechanisms and procedures.

GDPR processor audit: are your vendors properly framed?

A processor GDPR audit checks that your vendors are listed, contracted and actually able to protect the data you entrust to them.

List of processors

Up-to-date inventory of vendors that process data on your behalf.

Actual role of each actor

Distinguish controller, processor and recipient based on how things actually work, not only the contract.

Article 28 clauses

Check that the contract covers instructions, confidentiality, assistance and processor obligations.

Onward processors

Framing of your vendors’ sub-processors, authorisation and information.

Location / transfers

Know where data is hosted and whether a transfer outside the EU must be framed.

Security safeguards

Technical and organisational measures actually in place at the vendor.

Incident procedures

Ability to detect, notify and cooperate in the event of a data breach.

Return or deletion

What happens to the data at the end of the contract: return, deletion and associated evidence.

Your GDPR audit can also include your website

The website is not the core of this page: it is a possible scope of the organisational audit, like internal tools or vendors. If useful, we can review:

  • forms
  • data collected
  • notices
  • consents
  • cookies and trackers
  • third-party tools
  • marketing forms
  • data transfers
  • retention

For notices, cookies and website information texts, see our GDPR compliance services.

See GDPR compliance

What is your current GDPR maturity level?

Six questions to identify your gaps and prioritise an action plan — in the spirit of maturity self-assessment tools.

GDPR maturity

Maturity 48 / 100
Risk Moderate
Priorities 4 workstreams
  • Register60 %
  • Contracts40 %
  • Rights70 %
  • Security50 %
  • DPIA30 %
  • Documentation40 %

Main potential gaps

  • DPIA analysis to be qualified
  • incomplete processor contracts
  • retention rules to be formalised
  • security measures to be documented

Recommended assignment

Full GDPR audit

Request my GDPR diagnostic

Indicative result. This questionnaire is neither a legal audit nor a validation of compliance.

How do we classify identified gaps?

Each point reviewed is qualified, then prioritised. The aim is not to “score” the company, but to make corrections actionable.

Compliant

No significant gap identified on the point reviewed.

To improve

Practice exists, but documentation or operation can be strengthened.

Non-compliance

Requirement insufficiently covered.

Critical priority

Significant risk requiring prompt action.

Indicative example of a GDPR audit scoring grid — fictitious, to illustrate the method.
Control Status Risk Priority
Register Partial Medium 2
Processors Incomplete High 1
Rights Compliant Low
DPIA To be qualified High 1

Example of a finding from a GDPR audit

After the GDPR audit questionnaire, interviews and document review, each gap is delivered in a usable format — not a theoretical paragraph.

Fictitious finding example

Processing : Sales prospecting

Finding
Prospects are kept in the CRM with no erasure period configured.
Gap
Retention period not operationalised.
Risk
Excessive data retention.
Priority
High
Deadline
30 days
Recommended action
Define the applicable rule, configure archiving/deletion and document the mechanism.
Proposed owner
Marketing / DPO

Fictitious example intended to illustrate the reporting format.

What you receive at the end of the GDPR audit

A pack the board, DPO and operational teams can actually use — not a theoretical document that ends up in a drawer.

Processing mapping

Inventory of processing activities, purposes, data, recipients and tools.

Updated processing register

Depending on scope: update of the register or concrete recommendations for Article 30.

Compliance matrix

Applicable requirements, observed status and gaps, point by point.

Risk mapping

Risks identified per processing activity, impact on rights and freedoms, criticality level.

Processor audit

Depending on scope: listed vendors, clauses, safeguards and watchpoints. See the GDPR processor audit.

Full report

Debrief pack: findings, evidence reviewed, gaps and recommendations.

Executive summary

Short document for management: priorities, major risks and decisions to take.

Prioritised action plan

Roadmap ranked by priority (critical / high / medium), with timelines and owners.

Tracking matrix

Action, owner, deadline, status — to steer corrections after the audit.

GDPR audit and bringing into compliance: two different steps

The audit identifies. Implementation corrects. The DPO maintains. These are three distinct assignments — you choose how far to go.

The audit

Analysis, findings, risks and recommendations.

Bringing into compliance

Changing contracts, processes, documents, settings and tools.

The DPO

Ongoing steering of data protection.

You can engage us for the audit only, or continue with a compliance implementation assignment and/or DPO support.

When should you repeat a GDPR audit?

There is no single generic deadline that would turn a complete annual GDPR audit into a universal obligation. The audit remains a snapshot at a given point in time.

A new audit or review can be relevant when the organisation changes significantly.

New processing activities

New tool

New activity

Reorganisation

Acquisition

New processors

Sensitive processing

Incident

Major change in practices

The CNIL mainly emphasises a logic of ongoing compliance and the regular updating of documents and measures.

Between two audits, DPO support keeps the register, procedures and evidence alive — without waiting for a new full audit.

How does a GDPR audit work?

A structured, collaborative approach that requires little time from your teams while ensuring an exhaustive diagnostic.

01

Scoping & collection

Kick-off meeting, GDPR audit questionnaire and review of existing documents. Low-disruption phase for your teams.

  • scope
  • entities
  • activities
  • documentation
  • systems
1 week
02

Field mapping

Interviews with department heads (HR, marketing, IT, management…) and identification of personal data processing as it actually operates.

  • processing
  • owners
  • tools
  • vendors
  • data flows
1 to 2 weeks
03

Compliance analysis & risks

Gap analysis, risk assessment and comparison of practices against applicable requirements — legal bases, retention, transfers, security.

  • requirements
  • gaps
  • risks
  • priority level
1 week
04

Debrief & roadmap

Compliance report, prioritised action plan and oral debrief with your management.

  • report
  • management summary
  • action plan
  • owners
  • timeline
1 week

What happens after your GDPR audit?

The audit identifies and prioritises. Corrections, documentation and checks then follow — internally, with Complianz, or both.

  1. Audit
  2. Prioritisation
  3. Corrections
  4. Documentation
  5. Deployment
  6. Review
  7. Continuous improvement

How much does a GDPR audit cost?

The cost of a GDPR audit depends on the depth of the assignment — not only on company size. A precise quote is provided within 48 hours.

GDPR diagnostic

€1,500 – 2,900 excl. VAT

Targeted scope

  • Targeted scope
  • Priority processing
  • Main gaps
  • Summary report
Request a quote

Complex / multi-entity GDPR audit

€7,500 excl. VAT+

On quote

  • Multi-site
  • Numerous activities
  • Significant processors
  • Complex IT landscape
  • High volumes
  • Multiple interviews
Request a quote

Indicative pricing — a tailored quote is provided within 48 hours based on your exact scope.

What factors determine the price of a GDPR audit?

The cost of a GDPR audit is calculated from the actual scope — not a single flat fee. These points are clarified in the first discussion.

Number of processing activities

Number of entities

Number of sites

Volume of documentation

Number of processors

Sensitive data

High-risk processing

Applications / software used

Possible international transfers

Number of interviews

Current state of the register

Expected depth of the audit

Your questions about the GDPR audit

Our GDPR experts respond within 24 hours to any question about your compliance audit.

Contact us
What is a GDPR audit?

A GDPR audit is a structured assessment of an organisation’s GDPR compliance. It reviews processing, documents, legal bases, processors, security and actual practices to identify gaps and produce a prioritised action plan. It is a snapshot at a given point in time — not a permanent compliance certificate.

How do you carry out a GDPR audit?

To carry out a GDPR audit, we scope the assignment, collect documentation (often via a GDPR audit questionnaire), map processing in the field, analyse gaps with a GDPR audit scoring grid, then deliver a report and roadmap. That is the 4-phase method we use.

Who can carry out a GDPR audit?

An internal GDPR audit can be run by the organisation if it has the skills. It can also be entrusted to a GDPR audit firm. At Complianz, the audit is carried out by data protection specialists with recognised DPO certifications (CNIL, IAPP CIPM).

How much does a GDPR audit cost?

The price of a GDPR audit depends on the depth of the assignment: targeted diagnostic (€1,500 – 2,900 excl. VAT), complete GDPR audit (€4,500 – 8,500 excl. VAT) or a complex / multi-entity assignment (from €7,500 excl. VAT, on quote). A quote is provided within 48 hours.

How long does a GDPR audit take?

Generally 2 to 3 weeks for a targeted scope and 3 to 5 weeks for a fuller audit or an organisation with complex processing. Duration follows the depth of the assignment, not only company size.

What does a GDPR audit report contain?

A usable GDPR audit report typically includes processing mapping, a compliance matrix, risk mapping, an executive summary, a prioritised action plan and a tracking matrix (action, owner, deadline, status). See the deliverables.

What is the difference between a GDPR audit and a GDPR diagnostic?

A GDPR diagnostic is a targeted assignment: priority processing, main gaps, summary report. A complete GDPR audit goes further: mapping, register, contracts, risks and a prioritised roadmap. Both assess compliance; they do not have the same depth. See the packages.

What is the difference between a GDPR audit and bringing into compliance?

The audit identifies gaps, risks and recommendations. Bringing into compliance means changing contracts, processes, documents, settings and tools. These are two different steps: the audit does not automatically include implementation.

What is the difference between a GDPR audit and a CNIL inspection?

A GDPR audit is a voluntary diagnostic. A CNIL inspection is carried out by the authority, with its own powers and procedures, and may lead to corrective measures or sanctions. Complianz carries out a compliance audit: we do not perform a “CNIL audit”. See GDPR audit vs CNIL inspection.

Should you audit your processors?

Yes, when vendors process data on your behalf. The controller must in particular ensure that its processors provide sufficient GDPR safeguards. A GDPR processor audit checks the list, contracts, safeguards and actual practices.

What is a GDPR register?

The records of processing required by Article 30 list processing activities and help document compliance. The audit checks completeness and whether they are up to date. To build or maintain them: processing register.

What is a DPIA?

A DPIA (data protection impact assessment) evaluates processing likely to present a high risk to rights and freedoms. The audit identifies relevant processing and reviews existing assessments. See the DPIA checkpoint.

Is a DPIA mandatory for all processing?

No: it applies in particular to processing likely to result in a high risk. Not every processing activity requires a DPIA.

Is a GDPR audit mandatory?

The GDPR mainly requires organisations to implement and be able to demonstrate their compliance. A “complete GDPR audit” under that name is not a general formality imposed periodically on all companies; it is a particularly useful way to assess gaps and organise compliance.

How often should you carry out a GDPR audit?

There is no single generic deadline, and no universal obligation to run a complete annual audit. A new audit or review can be relevant when the organisation changes significantly. The CNIL mainly emphasises ongoing compliance and the regular updating of documents and measures. See when to repeat a GDPR audit.

Can you audit only a website?

Yes, a website GDPR audit can be a targeted scope (cookies, forms, consents, third-party tools). It is not the core of this page: the website is a possible scope of the audit.

Can you audit only our processors?

Yes. A processor GDPR audit can be limited to vendors: inventory, Article 28 clauses, safeguards, onward processing and actual practices.

What is the difference between a GDPR audit and a DPO?

The GDPR audit is a one-off diagnostic. An outsourced DPO is an ongoing function that steers and maintains compliance over time. Both are complementary: the audit often precedes DPO appointment.

Ready to assess your GDPR compliance level?

Our GDPR experts deliver a complete audit and provide a compliance report within 3 to 5 weeks. First conversation free, no obligation.

Request my GDPR audit
First conversation free Report within 5 weeks DPO-certified consultants
Innovation hub