Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
Supervisory authorities (Data Protection Authorities, or DPAs) exercise investigative powers under Art. 58(1) GDPR, including the power to order controllers and processors to provide any information required for the performance of their tasks (Art. 58(1)(a)), to carry out investigations in the form of data protection audits (Art. 58(1)(b)), to carry out a review on certifications (Art. 58(1)(c)), to notify the controller or processor of an alleged infringement (Art. 58(1)(d)), to obtain access to all personal data and information necessary (Art. 58(1)(e)), and to obtain access to any premises of the controller and processor, including data processing equipment (Art. 58(1)(f)).
DPA inspections may be triggered by data subject complaints, sector-wide enforcement campaigns, data breach notifications, random selection, media reports, or whistleblower reports. The consequences of inadequate inspection performance include corrective measures under Art. 58(2), administrative fines under Art. 83, and reputational damage through enforcement action publicity.
Sentinel Compliance Group maintains a standing DPA inspection readiness program that ensures the organization can respond effectively to announced and unannounced supervisory authority contact within defined timeframes.
Types of DPA Contact
Inspection Types
Type
Description
Notice Period
GDPR Basis
Written Inquiry
DPA sends written questions requiring documented responses
14-30 days typically
Art. 58(1)(a)
Announced Audit
Formal data protection audit with advance notice
2-8 weeks
Art. 58(1)(b)
Unannounced Inspection
On-site visit without prior notice
None
Art. 58(1)(f)
Complaint Investigation
Investigation triggered by data subject complaint
Variable; often begins with written inquiry
Art. 57(1)(f), 77
Breach Investigation
Investigation following a breach notification under Art. 33
Days to weeks following notification
Art. 58(1)(a), (e)
Sector Sweep
Coordinated investigation across multiple organizations in a sector
Varies by DPA
Art. 57(1)(a), 58(1)(b)
Prior Consultation Follow-Up
DPA follow-up on an Art. 36 prior consultation
Variable
Art. 36(2)
Common DPA Investigation Triggers
Trigger
Likelihood
DPA Approach
Data subject complaint
High
Written inquiry focused on specific processing; may escalate to audit
Breach notification (Art. 33)
High
Written questions; on-site audit if breach is significant
Media coverage
Medium
Preliminary inquiry; may escalate based on findings
Sector-wide campaign
Medium
Standardized questionnaire sent to multiple organizations simultaneously
Whistleblower report
Medium
Targeted investigation, possibly unannounced
Random selection
Low-Medium
Full compliance audit; common in some DPAs (e.g., CNIL, AEPD)
Prior consultation obligation
Low
Follow-up on DPIA consultation outcomes
Document Readiness Checklist
Core Documents (Must Be Immediately Available)
#
Document
GDPR Reference
Location
Owner
Last Updated
1
Records of Processing Activities (Controller)
Art. 30(1)
OneTrust RoPA module
DPO
Quarterly
2
Records of Processing Activities (Processor)
Art. 30(2)
OneTrust RoPA module
DPO
Quarterly
3
Privacy Policy (all versions, change history)
Art. 13-14
Legal document repository
Legal
Per change
4
Data Protection Impact Assessments (all)
Art. 35
DPIA register
DPO
Per assessment
5
Data Processing Agreements (all processors)
Art. 28
Contract management system
Legal/Procurement
Per agreement
6
Legitimate Interest Assessments (all)
Art. 6(1)(f)
LIA register
Legal
Per assessment
7
International Transfer Mechanisms (SCCs, BCRs, TIAs)
Art. 44-49
Transfer register
Legal
Per transfer
8
Breach Notification Records (all incidents)
Art. 33-34
Incident management system
CISO/DPO
Per incident
9
DSAR Records (all requests and responses)
Art. 12-22
DSAR management system
Privacy Ops
Per request
10
Consent Records (collection, withdrawal, preferences)
Art. 7
CMP database
Privacy Ops
Continuous
11
DPO Appointment Documentation
Art. 37-39
HR/Legal
Legal
Annual review
12
Privacy Training Records (all employees)
Art. 39(1)(b)
LMS
HR/Privacy
Per completion
13
Data Protection Policy and Procedures Manual
Art. 24(2)
Policy repository
DPO
Annual
14
Information Security Policy
Art. 32
Policy repository
CISO
Annual
15
Vendor Risk Assessment Records
Art. 28(1)
Vendor management platform
Procurement
Per assessment
Supporting Documents (Available Within 24 Hours)
#
Document
GDPR Reference
Owner
16
Data flow diagrams and system architecture
Art. 30, 35(7)(a)
IT Architecture
17
Data classification inventory
Art. 5(1)(c), (e)
Data Governance
18
Retention schedule with legal basis for each period
Retention schedule, legal basis for retention periods
Third-Party Sharing
Who receives the data and why
Recipient list, DPAs, data flow diagrams
Interview Conduct Protocol
Before the Interview:
Legal counsel confirms scope of the investigation and the DPA's legal authority
Identify interviewees and brief them on the topics likely to be covered
Prepare evidence binders or digital folders organized by topic
Designate a note-taker to create contemporaneous records
Brief interviewees on the interview principles (factual, precise, no volunteering)
During the Interview:
Introduce participants with names and roles
Confirm the DPA's scope and legal basis for the inspection
Request that questions be provided in writing where possible
Ask for clarification if questions are ambiguous
Note-taker records all questions and answers verbatim
Do not provide original documents; provide copies or controlled access
If a question requires research, commit to a specific response deadline (typically 5-10 business days)
Do not speculate or hypothesize; stick to documented facts
After the Interview:
Debrief internally within 24 hours
Finalize and distribute interview notes
Identify follow-up commitments and assign owners
Begin preparing any committed responses or documents
Update the DPA correspondence log
Technical Demonstration Procedures
Common Technical Demonstrations Requested by DPAs
Demonstration
What the DPA Wants to See
Preparation Steps
DSAR Fulfillment
End-to-end DSAR processing from intake to response
Prepare test DSAR in staging environment; walk through each step; show identity verification, data retrieval from all systems, response review, and delivery
Show CMP configuration; demonstrate consent capture; show consent database records; demonstrate withdrawal processing and downstream enforcement
Data Deletion
Technical deletion process upon retention expiry or erasure request
Show deletion job configuration; demonstrate deletion execution in staging; show verification that data is unrecoverable; address backup deletion
Access Controls
RBAC configuration for personal data access
Show IAM system; demonstrate role assignments; show access review process; demonstrate that unauthorized users cannot access PII
Encryption
Encryption at rest and in transit for personal data
Show database encryption configuration; demonstrate TLS certificate deployment; show key management procedures
Breach Detection
How breaches are detected and assessed
Show SIEM rules; demonstrate alert workflow; walk through a simulated breach scenario
Logging and Audit Trail
Access logging for personal data
Show log configuration; demonstrate log review process; show log retention and integrity controls
Demonstration Environment Preparation
Staging Environment: Maintain a staging environment with anonymized data that mirrors production for demonstrations
Test Accounts: Pre-configure test accounts with appropriate roles for demonstration
Walk-Through Scripts: Prepare step-by-step demonstration scripts for each system
Screen Recording: Be prepared to provide screen recordings if the DPA requests
Technical Support: Ensure system administrators and developers are available during demonstrations
Response Protocols
Unannounced Inspection Protocol
DPA Arrives On-Site
↓
Reception notifies DPO/Legal (immediate phone call)
↓
DPO/Legal arrives at reception within 15 minutes
↓
Verify inspector credentials (official ID, authorization letter)
↓
Confirm scope of inspection (which processing activities, which legal basis)
↓
Escort inspectors at all times (never leave unaccompanied)
↓
Provide requested documents (copies, not originals)
↓
Designate meeting room for interviews
↓
Note-taker present at all interactions
↓
Do not obstruct (Art. 83(5)(e): failure to cooperate is fineable)
↓
At conclusion: obtain list of follow-up requests and deadlines
↓
Internal debrief within 2 hours of departure
Written Inquiry Response Protocol
Written Inquiry Received (email, letter, secure portal)
↓
DPO acknowledges receipt within 2 business days
↓
Legal reviews the inquiry for scope and legal basis
↓
DPO assigns response owner(s) for each question
↓
Response drafting (owner gathers evidence, drafts responses)
↓
DPO reviews draft responses for accuracy and completeness
↓
Legal reviews for legal privilege, scope compliance, and strategic considerations
↓
Senior management approves (if required by response materiality)
↓
Response submitted via the DPA's specified channel
↓
Response logged in DPA correspondence register
↓
Deadline: per DPA instruction (typically 14-30 days; request extension if needed)
Complete and distribute comprehensive inspection notes
Create an action register of all commitments and deadlines
Assign owners for each follow-up item
Begin preparing committed documents and responses
Identify potential findings based on DPA questions and areas of focus
Engage external counsel if enforcement action is likely
Response to DPA Findings
When the DPA issues findings or recommendations:
DPA Action
Required Response
Timeline
Informal recommendation
Voluntary implementation; document decision
30-60 days
Formal warning (Art. 58(2)(a))
Acknowledge; implement corrective measures; report back
Per DPA instruction
Order to comply (Art. 58(2)(c)-(j))
Implement required changes; report compliance
Per DPA instruction (typically 30-90 days)
Administrative fine (Art. 83)
Pay fine OR appeal; implement corrective measures regardless
Payment per DPA instruction; appeal within national deadline
Processing ban (Art. 58(2)(f))
Immediately cease processing; implement required measures; request lifting of ban
Immediate; restoration upon compliance demonstration
Lessons Learned Process
After every DPA interaction:
Document the complete interaction timeline
Assess the effectiveness of the readiness program
Identify documentation or process gaps exposed by the inspection
Update document readiness checklists based on DPA requests
Update interview preparation materials based on questions asked
Conduct refresher training for key personnel
Update the inspection readiness program
Share anonymized lessons learned with the privacy team
Sentinel Compliance Group DPA Inspection Readiness
Document Readiness Score: 94% Green (28 of 30 documents Green; 2 Yellow: sub-processor lists for two vendors pending update)
Interview Readiness: DPO, CISO, and 5 business process owners complete annual interview preparation refresher; last refresher December 2024
Technical Demonstration: Staging environment maintained with weekly sync from production (anonymized); demonstration scripts current for all 7 common scenarios
Response Protocol Testing: Annual tabletop exercise simulating unannounced inspection; last exercise November 2024; 3 improvement items identified and remediated
DPA Interaction History: 4 interactions in 2024 (2 complaint investigations, 1 sector sweep questionnaire, 1 breach follow-up inquiry); all resolved satisfactorily with no formal enforcement action
Response Time Performance: Average time from DPA inquiry to submitted response: 11 business days (target: within DPA-specified deadline, typically 14-30 days)
Unannounced Inspection Readiness: Reception staff trained on initial response protocol; DPO reachable within 15 minutes during business hours; after-hours DPO on-call rotation established