Map the real data flows
Identify where personal data enters sales, marketing, recruitment, HR, finance, monitoring and user support; who uses it; where it is stored; and to whom it is disclosed. Interviews with process owners are essential.
1. Roles and ownership
Determine when the business acts as controller, joint controller or processor, and assign internal responsibility for decisions, requests and incidents.
2. Purposes and legal bases
Record the genuine purpose and legal basis for each activity. Consent is not the default answer and data collected for one purpose cannot automatically be reused for another.
3. Privacy information
Check that employees, candidates, customers, users and website visitors receive the right information at the right time and through the correct channel.
4. Records and accountability
Records should reflect current purposes, data categories, recipients, transfers, retention and safeguards. The company should also preserve evidence of decisions and periodic reviews.
5. Suppliers and processing agreements
Review accounting, hosting, CRM, cloud, mailing and support providers. Confirm roles, processing terms, sub-processors and any transfers outside the EEA.
6. Access management
Limit access to job requirements, remove it when roles change and review shared accounts, administrator privileges, authentication and periodic access checks.
7. Risk and security
Match technical and organisational measures to the data, scale and likely impact of a breach. Cover backups, patching, encryption, remote work, personal devices, physical records and business continuity.
8. Retention and deletion
Set realistic periods and verify that systems can delete or anonymise data when those periods expire. A retention policy that cannot be implemented does not solve the problem.
9. Data-subject rights
Create a route for identifying, verifying and answering access, erasure, rectification, restriction, objection and portability requests within the applicable period.
10. Personal-data breaches
The team must recognise an incident, contain it, gather facts and assess risk quickly enough to meet any regulatory and notification deadlines.
11. Website, cookies and marketing
Review forms, analytics, advertising pixels, newsletters and consent records. A cookie banner must correspond to the technologies that actually start on the website.
12. Training and recurring review
Training should reflect each role. Test and update the main procedures, permissions and safeguards as systems and business processes change.
The audit must produce an action plan
Prioritise findings by impact and likelihood, assign owners and deadlines, and distinguish urgent operational risks from lower-priority documentation improvements.
How the issue appears in practice
Hypothetical example: the policy and system disagree
A recruitment record states that unsuccessful applications are deleted after a set period, but CVs remain indefinitely in shared mailboxes. A document-only review would miss the real retention problem.
Matters to determine or verify before proceeding
- Map the real data flows
- Roles and ownership
- Purposes and legal bases
- Privacy information
- Records and accountability
- Suppliers and processing agreements
- Access management
Key issues at a glance
| Issue | Key information |
|---|---|
| Map the real data flows | Identify where personal data enters sales, marketing, recruitment, HR, finance, monitoring and user support; who uses it; where it is stored; and to whom it is disclosed. |
| Roles and ownership | Determine when the business acts as controller, joint controller or processor, and assign internal responsibility for decisions, requests and incidents. |
| Purposes and legal bases | Record the genuine purpose and legal basis for each activity. |
| Privacy information | Check that employees, candidates, customers, users and website visitors receive the right information at the right time and through the correct channel. |
| Records and accountability | Records should reflect current purposes, data categories, recipients, transfers, retention and safeguards. |
Legal basis
- Regulation (EU) 2016/679 (GDPR)
- Polish Entrepreneurs' Law of 6 March 2018
- Polish Act of 6 March 2018 on participation of foreign entrepreneurs and other foreign persons in economic activity in Poland
This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.
Summary
A useful audit compares documents with reality and ends with a prioritised remediation plan. Data flows, suppliers, access, retention and incident readiness usually deserve particular attention.