Map
Understand which data is processed, why, by whom and with which tools.
We deliver a complete GDPR audit to identify your non-compliance risks: processing mapping, legal basis analysis, gap analysis and compliance report. Result: you know exactly where you stand and what to fix first.
You get a clear snapshot of your compliance at a given point in time — with the corrections to make and their priority. GDPR compliance then has to be maintained: documentation and compliance actions must be reviewed and updated regularly.
What you get
At the end of the GDPR audit
A clear view of your GDPR compliance level at a given point in time, identified and ranked gaps, and a concrete action plan.
An audit your leadership, DPO and operational teams can actually use.
Understand
A GDPR audit consists of examining an organisation’s personal data processing, practices, contracts and documentation to identify gaps between how it actually operates and the applicable data protection requirements.
It produces a structured diagnostic, identifies risks and prioritises the necessary actions.
Understand which data is processed, why, by whom and with which tools.
Review legal bases, notices, rights, retention periods, contracts and existing measures.
Qualify the gaps and risks.
Turn findings into a realistic action plan.
The audit is not just about checking whether you have a privacy policy: it examines how your organisation actually works.
GDPR audit ≠ CNIL inspection
A GDPR audit is not a CNIL inspection. Both relate to data protection, but they do not have the same author, purpose or consequences.
| GDPR audit | CNIL inspection |
|---|---|
| Voluntary or internal exercise | Inspection by the data protection authority |
| Diagnostic purpose — gap identification — recommendations | Powers and procedures specific to the authority |
| Preparation and improvement | May lead to corrective measures or sanctions depending on the findings |
Complianz carries out a compliance audit: we obviously do not perform a “CNIL audit”.
What the audit checks
The audit examines how the organisation actually works, not just whether documents exist. These are the structural points we review.
Completeness, updates, purposes, data categories, recipients, retention periods and associated measures.
The records of processing required by Article 30 are a tool for inventorying and documenting compliance.
Consent, contract, legal obligation, legitimate interest or another appropriate ground depending on the processing.
Information notices, privacy policies and transparency.
Access, rectification, erasure, objection, restriction and other applicable requests.
Defined, consistent and actually applied retention periods.
Contracts, safeguards, responsibilities, onward processing and practices.
The controller must in particular ensure that processors provide the necessary safeguards and frame the relationship in accordance with Article 28. See the GDPR processor audit.
Access, backup, incident management, confidentiality and organisation.
Procedure, internal register and ability to handle a notification when required.
When a breach poses a risk to rights and freedoms, notification to the CNIL must take place without undue delay and, where feasible, within 72 hours.
Identification of processing likely to require a data protection impact assessment, and review of existing analyses.
A DPIA applies in particular to processing likely to result in a high risk to rights and freedoms.
Responsibilities, possible DPO, internal procedures, awareness and compliance evidence.
Documentary compliance vs actual compliance
The GDPR audit compares documentation with actual practice. An up-to-date register only has value if it reflects what really happens in the organisation.
The accountability principle requires being able to demonstrate compliance through effective internal mechanisms and procedures.
GDPR processor audit
A processor GDPR audit checks that your vendors are listed, contracted and actually able to protect the data you entrust to them.
Up-to-date inventory of vendors that process data on your behalf.
Distinguish controller, processor and recipient based on how things actually work, not only the contract.
Check that the contract covers instructions, confidentiality, assistance and processor obligations.
Framing of your vendors’ sub-processors, authorisation and information.
Know where data is hosted and whether a transfer outside the EU must be framed.
Technical and organisational measures actually in place at the vendor.
Ability to detect, notify and cooperate in the event of a data breach.
What happens to the data at the end of the contract: return, deletion and associated evidence.
Optional scope
The website is not the core of this page: it is a possible scope of the organisational audit, like internal tools or vendors. If useful, we can review:
For notices, cookies and website information texts, see our GDPR compliance services.
See GDPR complianceMini pre-diagnostic
Six questions to identify your gaps and prioritise an action plan — in the spirit of maturity self-assessment tools.
GDPR maturity
Full GDPR audit
Indicative result. This questionnaire is neither a legal audit nor a validation of compliance.
GDPR audit scoring grid
Each point reviewed is qualified, then prioritised. The aim is not to “score” the company, but to make corrections actionable.
No significant gap identified on the point reviewed.
Practice exists, but documentation or operation can be strengthened.
Requirement insufficiently covered.
Significant risk requiring prompt action.
| Control | Status | Risk | Priority |
|---|---|---|---|
| Register | Partial | Medium | 2 |
| Processors | Incomplete | High | 1 |
| Rights | Compliant | Low | — |
| DPIA | To be qualified | High | 1 |
GDPR audit example
After the GDPR audit questionnaire, interviews and document review, each gap is delivered in a usable format — not a theoretical paragraph.
Fictitious finding example
Fictitious example intended to illustrate the reporting format.
Audit deliverables
A pack the board, DPO and operational teams can actually use — not a theoretical document that ends up in a drawer.
Inventory of processing activities, purposes, data, recipients and tools.
Depending on scope: update of the register or concrete recommendations for Article 30.
Applicable requirements, observed status and gaps, point by point.
Risks identified per processing activity, impact on rights and freedoms, criticality level.
Depending on scope: listed vendors, clauses, safeguards and watchpoints. See the GDPR processor audit.
Debrief pack: findings, evidence reviewed, gaps and recommendations.
Short document for management: priorities, major risks and decisions to take.
Roadmap ranked by priority (critical / high / medium), with timelines and owners.
Action, owner, deadline, status — to steer corrections after the audit.
What the audit does not automatically include
The audit identifies. Implementation corrects. The DPO maintains. These are three distinct assignments — you choose how far to go.
Analysis, findings, risks and recommendations.
Changing contracts, processes, documents, settings and tools.
Ongoing steering of data protection.
You can engage us for the audit only, or continue with a compliance implementation assignment and/or DPO support.
When to repeat an audit
There is no single generic deadline that would turn a complete annual GDPR audit into a universal obligation. The audit remains a snapshot at a given point in time.
A new audit or review can be relevant when the organisation changes significantly.
The CNIL mainly emphasises a logic of ongoing compliance and the regular updating of documents and measures.
Between two audits, DPO support keeps the register, procedures and evidence alive — without waiting for a new full audit.
Our method
A structured, collaborative approach that requires little time from your teams while ensuring an exhaustive diagnostic.
Kick-off meeting, GDPR audit questionnaire and review of existing documents. Low-disruption phase for your teams.
Interviews with department heads (HR, marketing, IT, management…) and identification of personal data processing as it actually operates.
Gap analysis, risk assessment and comparison of practices against applicable requirements — legal bases, retention, transfers, security.
Compliance report, prioritised action plan and oral debrief with your management.
After the audit
The audit identifies and prioritises. Corrections, documentation and checks then follow — internally, with Complianz, or both.
Our pricing
The cost of a GDPR audit depends on the depth of the assignment — not only on company size. A precise quote is provided within 48 hours.
GDPR diagnostic
€1,500 – 2,900 excl. VAT
Targeted scope
Complete GDPR audit
€4,500 – 8,500 excl. VAT
Reference assignment
Complex / multi-entity GDPR audit
€7,500 excl. VAT+
On quote
Indicative pricing — a tailored quote is provided within 48 hours based on your exact scope.
What determines the price
The cost of a GDPR audit is calculated from the actual scope — not a single flat fee. These points are clarified in the first discussion.
A GDPR audit is a structured assessment of an organisation’s GDPR compliance. It reviews processing, documents, legal bases, processors, security and actual practices to identify gaps and produce a prioritised action plan. It is a snapshot at a given point in time — not a permanent compliance certificate.
To carry out a GDPR audit, we scope the assignment, collect documentation (often via a GDPR audit questionnaire), map processing in the field, analyse gaps with a GDPR audit scoring grid, then deliver a report and roadmap. That is the 4-phase method we use.
An internal GDPR audit can be run by the organisation if it has the skills. It can also be entrusted to a GDPR audit firm. At Complianz, the audit is carried out by data protection specialists with recognised DPO certifications (CNIL, IAPP CIPM).
The price of a GDPR audit depends on the depth of the assignment: targeted diagnostic (€1,500 – 2,900 excl. VAT), complete GDPR audit (€4,500 – 8,500 excl. VAT) or a complex / multi-entity assignment (from €7,500 excl. VAT, on quote). A quote is provided within 48 hours.
Generally 2 to 3 weeks for a targeted scope and 3 to 5 weeks for a fuller audit or an organisation with complex processing. Duration follows the depth of the assignment, not only company size.
A usable GDPR audit report typically includes processing mapping, a compliance matrix, risk mapping, an executive summary, a prioritised action plan and a tracking matrix (action, owner, deadline, status). See the deliverables.
A GDPR diagnostic is a targeted assignment: priority processing, main gaps, summary report. A complete GDPR audit goes further: mapping, register, contracts, risks and a prioritised roadmap. Both assess compliance; they do not have the same depth. See the packages.
The audit identifies gaps, risks and recommendations. Bringing into compliance means changing contracts, processes, documents, settings and tools. These are two different steps: the audit does not automatically include implementation.
A GDPR audit is a voluntary diagnostic. A CNIL inspection is carried out by the authority, with its own powers and procedures, and may lead to corrective measures or sanctions. Complianz carries out a compliance audit: we do not perform a “CNIL audit”. See GDPR audit vs CNIL inspection.
Yes, when vendors process data on your behalf. The controller must in particular ensure that its processors provide sufficient GDPR safeguards. A GDPR processor audit checks the list, contracts, safeguards and actual practices.
The records of processing required by Article 30 list processing activities and help document compliance. The audit checks completeness and whether they are up to date. To build or maintain them: processing register.
A DPIA (data protection impact assessment) evaluates processing likely to present a high risk to rights and freedoms. The audit identifies relevant processing and reviews existing assessments. See the DPIA checkpoint.
No: it applies in particular to processing likely to result in a high risk. Not every processing activity requires a DPIA.
The GDPR mainly requires organisations to implement and be able to demonstrate their compliance. A “complete GDPR audit” under that name is not a general formality imposed periodically on all companies; it is a particularly useful way to assess gaps and organise compliance.
There is no single generic deadline, and no universal obligation to run a complete annual audit. A new audit or review can be relevant when the organisation changes significantly. The CNIL mainly emphasises ongoing compliance and the regular updating of documents and measures. See when to repeat a GDPR audit.
Yes, a website GDPR audit can be a targeted scope (cookies, forms, consents, third-party tools). It is not the core of this page: the website is a possible scope of the audit.
Yes. A processor GDPR audit can be limited to vendors: inventory, Article 28 clauses, safeguards, onward processing and actual practices.
The GDPR audit is a one-off diagnostic. An outsourced DPO is an ongoing function that steers and maintains compliance over time. Both are complementary: the audit often precedes DPO appointment.
Our GDPR experts deliver a complete audit and provide a compliance report within 3 to 5 weeks. First conversation free, no obligation.
Quick, free estimate with no commitment — we usually reply within 24 hours.
By submitting this form, you accept our privacy policy.
Choose a day and then a time slot. We will confirm your appointment by email or phone.
Preferred time slot
Request sent successfully
We will get back to you shortly to confirm your time slot.
Availability shown is indicative; final confirmation is provided by our team.