The Privacy Audit service will validate that your data privacy practices meet your applicable regulatory requirements for either the GDPR (General Data Protection Regulation) and Data Protection Act 2018 (DPA), the PECR (Privacy and Electronic Communications Regulations), or both.
Regulatory compliance is not a one-off exercise. True compliance involves consistently identifying and managing emerging privacy and security risks. An internal audit, conducted by a privacy expert, can help you validate whether your practices are in line with the GDPR and/or PECR (as applicable).
Our experienced data privacy team will assess your organisation’s data privacy and information security practices through an on-site compliance audit, checking them against relevant regulatory requirements, ICO (Information Commissioner’s Office) guidance and IT Governance best practice.
We will:
After the audit, you’ll receive a report that records the consultant’s observations and findings, as well as a separate audit tool workbook that contains the detailed audit results.
This is not a legal service, but our sister company GRCI Law Limited can offer legal advice where potential legal issues are identified.
| GDPR Audit | PECR audit |
|---|---|
|
|
For more information, download the service description
| Gap analysis | Audit |
|---|---|
| Exclusively question-based (‘Do you do X?’). | Evidence-based: the consultant needs to be able to see X is done (so must be on site). |
| Typically conducted at an early stage in the compliance programme. | Typically conducted when the organisation believes it is already compliant. |
The price is applicable for organisations with up to 500 employees, based at a single main site.
For larger or more complex organisations, please contact us for a custom quote by emailing servicecentre@grcsolutions.io.
The fee excludes any necessary travel, accommodation and subsistence expenses. Expenses will be assessed and charged in arrears.
Discounts for multi-year audits only apply when a two- or three-year contract is agreed at the purchase of the first audit; discounts cannot be backdated.