Back to blog
Audits & pentests

GDPR and Security Audit - What You Need to Know?

Published: 2024-11-01Updated: 2026-07-273 minKrzysztof Jaroński

GDPR and security audit obligation

The GDPR does not impose a direct obligation to conduct a service or procedure literally named “IT security audit” on a fixed cycle. It requires appropriate technical and organisational measures and — under Art. 32(1)(d) — regular testing, assessment and evaluation of effectiveness.

In practice you must ensure and, when needed, demonstrate that controls work. An IT security audit (or another form of assessment) can be a tool for that — but the word “audit” is not mandated by GDPR itself. See IT security audit – what it covers for typical scope.

Key GDPR Requirements

Art. 32 - Security of Processing

The data controller must implement measures ensuring:

  • Pseudonymization and encryption of data
  • Ongoing confidentiality, integrity, and availability of systems
  • Ability to quickly restore data after an incident
  • Regular testing and evaluation of security effectiveness

Art. 35 - Data Protection Impact Assessment (DPIA)

Required for high-risk data processing:

  • Profiling and automated decision-making
  • Large-scale processing of sensitive data
  • Systematic monitoring of public places

Assessment as a GDPR effectiveness tool

What may a RODO-focused assessment cover?

1. Data Inventory

  • What data is processed?
  • Where is it stored?
  • Who has access to it?

2. Legal Bases for Processing

  • User consents
  • Contracts
  • Legitimate interest

3. Security Measures

  • Encryption
  • Access control
  • Backups
  • Incident response procedures

4. Individual Rights

  • Right to information
  • Right to erasure
  • Right to data portability
  • Right to object

5. Processing Agreements

  • Data processor verification
  • GDPR-compliant agreements
  • Subcontractor control

Penalties for Non-Compliance

GDPR provides for severe penalties:

  • Up to €10 million or 2% of annual turnover (minor violations)
  • Up to €20 million or 4% of annual turnover (serious violations)

Examples of Penalties in Poland:

  • Lack of adequate security: 100,000 - 500,000 PLN
  • Improper data processing: 50,000 - 200,000 PLN
  • Failure to report breach: 20,000 - 100,000 PLN

How often to assess effectiveness?

GDPR does not fix a “audit every 12 months” schedule. Frequency should follow risk and processing changes. Sensible practice: full assessment when risk or scope grows; always after system changes affecting personal data; immediately after incidents; before new high-risk processing.

Assessment documentation

Effectiveness assessments should be documented:

  • Audit report
  • List of identified non-compliances
  • Corrective action plan
  • Implementation timeline

Summary

GDPR requires appropriate security measures and evaluation of their effectiveness — not necessarily a service named “IT security audit.” Independent assessment remains a strong way to demonstrate due diligence. Technical context: IT security audit scope.

Need a security assessment for GDPR? Contact me to discuss scope without confusing a service name with a legal duty.