GDPR audit — security of processing (Art. 32), DPIA, RoPA and the 72-hour breach
What a GDPR audit is
A GDPR compliance audit assesses whether an organization meets Regulation (EU) 2016/679 requirements for personal-data protection — from lawful bases through security to data-subject rights and breach handling.
Key areas and articles
- security of processing — Art. 32 (technical and organizational measures),
- data protection impact assessment (DPIA) — Art. 35,
- records of processing activities (RoPA) — Art. 30,
- breach notification: to the authority within 72 hours (Art. 33), to individuals where high risk (Art. 34),
- data-subject rights and processor agreements (DPA).
Penalties
The most serious GDPR infringements carry fines up to €20M or 4% of total worldwide annual turnover (whichever is higher); other infringements up to €10M or 2%.
How to prepare for a GDPR audit
- gather policies, procedures and evidence for Art. 32,
- prepare/update the RoPA and DPIAs where required,
- document the breach-handling procedure (including the 72-hour deadline),
- review processor agreements (DPAs) and the subprocessor register,
- prepare an auditable report with references to evidence.
How Audnexa supports GDPR audits
Audnexa supports reviewing security of processing (Art. 32), preparing DPIAs, maintaining records of processing and documenting breach-handling procedures (including the 72-hour requirement under Art. 33) — in offline mode, without moving data to the cloud. A human approves every report.
A mature tool proven in Virtline’s audit practice (ISO/IEC 27001). It does not replace a legal or auditor’s opinion.
Frequently asked questions
What is a RoPA?
The record of processing activities (Art. 30 GDPR) — a document describing what data, for what purpose and on what basis the organization processes. A core GDPR-audit artifact.
When must a data breach be reported?
To the supervisory authority generally within 72 hours of becoming aware (Art. 33); to affected individuals where there is high risk (Art. 34).
Can a GDPR audit be done offline?
Yes. Audnexa runs in offline mode — personal data does not leave the customer’s infrastructure.
Sources
This content is informational and does not constitute a legal opinion, an auditor’s opinion or a formal compliance decision.