Audnexa
SecurityModulesPricingFAQ
plPolski enEnglish daDansk
Book a security walkthrough
SecurityModulesPricingFAQ For audit firms +48 12 200 27 10 Book a security walkthrough

← All articles

GDPR audit — security of processing (Art. 32), DPIA, RoPA and the 72-hour breach

Author: Adam Wojak · Managing Director, Virtline (ISO/IEC 27001) · Updated: 2026-06-25

In short: A GDPR audit (Regulation (EU) 2016/679) covers security of processing (Art. 32), data protection impact assessments (DPIA, Art. 35), records of processing activities (RoPA, Art. 30) and breach-notification procedures within 72 hours (Art. 33). Penalties reach up to €20M or 4% of annual turnover.

What a GDPR audit is

A GDPR compliance audit assesses whether an organization meets Regulation (EU) 2016/679 requirements for personal-data protection — from lawful bases through security to data-subject rights and breach handling.

Key areas and articles

  • security of processing — Art. 32 (technical and organizational measures),
  • data protection impact assessment (DPIA) — Art. 35,
  • records of processing activities (RoPA) — Art. 30,
  • breach notification: to the authority within 72 hours (Art. 33), to individuals where high risk (Art. 34),
  • data-subject rights and processor agreements (DPA).

Penalties

The most serious GDPR infringements carry fines up to €20M or 4% of total worldwide annual turnover (whichever is higher); other infringements up to €10M or 2%.

How to prepare for a GDPR audit

  • gather policies, procedures and evidence for Art. 32,
  • prepare/update the RoPA and DPIAs where required,
  • document the breach-handling procedure (including the 72-hour deadline),
  • review processor agreements (DPAs) and the subprocessor register,
  • prepare an auditable report with references to evidence.

How Audnexa supports GDPR audits

Audnexa supports reviewing security of processing (Art. 32), preparing DPIAs, maintaining records of processing and documenting breach-handling procedures (including the 72-hour requirement under Art. 33) — in offline mode, without moving data to the cloud. A human approves every report.

A mature tool proven in Virtline’s audit practice (ISO/IEC 27001). It does not replace a legal or auditor’s opinion.

Frequently asked questions

What is a RoPA?

The record of processing activities (Art. 30 GDPR) — a document describing what data, for what purpose and on what basis the organization processes. A core GDPR-audit artifact.

When must a data breach be reported?

To the supervisory authority generally within 72 hours of becoming aware (Art. 33); to affected individuals where there is high risk (Art. 34).

Can a GDPR audit be done offline?

Yes. Audnexa runs in offline mode — personal data does not leave the customer’s infrastructure.

Sources

  • EUR-Lex — GDPR (EU) 2016/679
  • EDPB — European Data Protection Board

Book a security walkthrough

Related articles

  • NIS2 audit — who is covered, what the obligations are, and how to prepare
  • Which tools support NIS2, DORA and banking compliance audits? Selection criteria
  • DORA audit — ICT requirements, third-party risk and how to prepare

This content is informational and does not constitute a legal opinion, an auditor’s opinion or a formal compliance decision.

← All articles

Audnexa

Auditable AI workspace for IT security and compliance reporting at regulated institutions.

Audnexa is a product of Virtline Sp. z o.o.

Product

Security Deployment Modules Pricing Trust Center

Company

Knowledge For audit firms Contact LinkedIn +48 12 200 27 10 biuro@virtline.com

Legal

Privacy policy DPA Terms security@virtline.com

Audnexa supports the work of auditors and compliance teams. It does not constitute a legal opinion, an auditor’s opinion, or a formal compliance decision.

© 2026 Virtline Sp. z o.o. All rights reserved. ul. Wadowicka 8A, 30-415 Kraków · NIP 6751499701

We use cookies for traffic analytics (GA4). Statistics load only after your consent. Privacy policy