01

Map the real data flows

Identify where personal data enters sales, marketing, recruitment, HR, finance, monitoring and user support; who uses it; where it is stored; and to whom it is disclosed. Interviews with process owners are essential.

02

1. Roles and ownership

Determine when the business acts as controller, joint controller or processor, and assign internal responsibility for decisions, requests and incidents.

03

2. Purposes and legal bases

Record the genuine purpose and legal basis for each activity. Consent is not the default answer and data collected for one purpose cannot automatically be reused for another.

04

3. Privacy information

Check that employees, candidates, customers, users and website visitors receive the right information at the right time and through the correct channel.

05

4. Records and accountability

Records should reflect current purposes, data categories, recipients, transfers, retention and safeguards. The company should also preserve evidence of decisions and periodic reviews.

06

5. Suppliers and processing agreements

Review accounting, hosting, CRM, cloud, mailing and support providers. Confirm roles, processing terms, sub-processors and any transfers outside the EEA.

07

6. Access management

Limit access to job requirements, remove it when roles change and review shared accounts, administrator privileges, authentication and periodic access checks.

08

7. Risk and security

Match technical and organisational measures to the data, scale and likely impact of a breach. Cover backups, patching, encryption, remote work, personal devices, physical records and business continuity.

09

8. Retention and deletion

Set realistic periods and verify that systems can delete or anonymise data when those periods expire. A retention policy that cannot be implemented does not solve the problem.

10

9. Data-subject rights

Create a route for identifying, verifying and answering access, erasure, rectification, restriction, objection and portability requests within the applicable period.

11

10. Personal-data breaches

The team must recognise an incident, contain it, gather facts and assess risk quickly enough to meet any regulatory and notification deadlines.

12

11. Website, cookies and marketing

Review forms, analytics, advertising pixels, newsletters and consent records. A cookie banner must correspond to the technologies that actually start on the website.

13

12. Training and recurring review

Training should reflect each role. Test and update the main procedures, permissions and safeguards as systems and business processes change.

14

The audit must produce an action plan

Prioritise findings by impact and likelihood, assign owners and deadlines, and distinguish urgent operational risks from lower-priority documentation improvements.

PRACTICE

How the issue appears in practice

Example

Hypothetical example: the policy and system disagree

A recruitment record states that unsuccessful applications are deleted after a set period, but CVs remain indefinitely in shared mailboxes. A document-only review would miss the real retention problem.

Working checklist

Matters to determine or verify before proceeding

  • Map the real data flows
  • Roles and ownership
  • Purposes and legal bases
  • Privacy information
  • Records and accountability
  • Suppliers and processing agreements
  • Access management

Key issues at a glance

IssueKey information
Map the real data flowsIdentify where personal data enters sales, marketing, recruitment, HR, finance, monitoring and user support; who uses it; where it is stored; and to whom it is disclosed.
Roles and ownershipDetermine when the business acts as controller, joint controller or processor, and assign internal responsibility for decisions, requests and incidents.
Purposes and legal basesRecord the genuine purpose and legal basis for each activity.
Privacy informationCheck that employees, candidates, customers, users and website visitors receive the right information at the right time and through the correct channel.
Records and accountabilityRecords should reflect current purposes, data categories, recipients, transfers, retention and safeguards.
LEGAL BASIS

Legal basis

  • Regulation (EU) 2016/679 (GDPR)
  • Polish Entrepreneurs' Law of 6 March 2018
  • Polish Act of 6 March 2018 on participation of foreign entrepreneurs and other foreign persons in economic activity in Poland
Explore this areaBusiness in Poland

This article provides general information and does not constitute legal advice for a specific matter. The appropriate solution depends on the facts, documents and business objective.

Summary

A useful audit compares documents with reality and ends with a prioritised remediation plan. Data flows, suppliers, access, retention and incident readiness usually deserve particular attention.