| name | gdpr-compliance-audit |
| title | Conducting Data Protection Audit |
| description | Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37. Includes 50+ control points covering principles, accountability, security, and governance. Activate when performing compliance audits, preparing for supervisory authority inspections, or assessing organisational GDPR maturity. Keywords: data protection audit, compliance audit, GDPR audit, control points, accountability. |
| author | onfire7777 |
| author_url | https://github.com/onfire7777/universal-ai-skills-library/tree/main/skills/gdpr-compliance-audit |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Conducting Data Protection Audit
Overview
A data protection audit systematically evaluates an organisation's compliance with GDPR requirements across governance, processing activities, data subject rights, security measures, and third-party arrangements. This skill provides a structured audit framework with 50+ control points mapped to specific GDPR articles, enabling auditors to produce a comprehensive compliance assessment with prioritised remediation recommendations.
Audit Framework Structure
The audit is organised into eight domains aligned to core GDPR chapters and articles:
- Data Protection Principles (Art. 5)
- Accountability and Governance (Art. 24, 5(2))
- Privacy by Design and Default (Art. 25)
- Processor Management (Art. 28)
- Records of Processing (Art. 30)
- Security of Processing (Art. 32)
- Data Protection Impact Assessments (Art. 35)
- Data Protection Officer (Art. 37-39)
Domain 1: Data Protection Principles (Art. 5)
| # | Control Point | GDPR Ref | Evidence Required |
|---|
| 1.1 | Processing purposes are specified, explicit, and documented for each activity | Art. 5(1)(a)-(b) | RoPA with specific purpose statements |
| 1.2 | A valid lawful basis is identified and documented for each processing activity | Art. 5(1)(a), 6 | Lawful basis register/assessment records |
| 1.3 | Personal data collected is adequate, relevant, and limited to what is necessary | Art. 5(1)(c) | Data minimisation reviews, field-level justification |
| 1.4 | Personal data is accurate and kept up to date with rectification procedures | Art. 5(1)(d) | Data quality processes, rectification logs |
| 1.5 | Retention periods are defined for all data categories with deletion/anonymisation procedures | Art. 5(1)(e) | Retention schedule, deletion logs |
| 1.6 | Appropriate security measures protect personal data against unauthorised access, loss, or destruction | Art. 5(1)(f) | Security controls documentation, pen test reports |
| 1.7 | The controller can demonstrate compliance with all principles (accountability) | Art. 5(2) | Compiled evidence portfolio |
Domain 2: Accountability and Governance (Art. 24)