Short Reads

Countdown 2 weeks until GDPR : Will periodic data protection audits be mandatory under the GDPR?

Stibbe - Will periodic data protection audits be mandatory under the G

Countdown 2 weeks until GDPR : Will periodic data protection audits be mandatory under the GDPR?

09.05.2018 EU law

Only 2 more weeks to go before the GDPR becomes fully effective. Preparing your company for the application of this new regulation requires a correct understanding of its principles. Each week, we highlight one particular misconception regarding the interpretation of the GDPR.

Will periodic data protection audits be mandatory under the GDPR?

Under Article 32.1.d of the GDPR, data controllers and data processors must implement appropriate technical and organizational measures to ensure a level of security that is appropriate for the risk and, among those measures, they must regularly test and evaluate the effectiveness of the measures adopted for ensuring security of files.

Having said this, the GDPR does not lay down specific procedures or a specific format for those review and evaluation tasks. Consequently, unless binding national regulations set forth otherwise, data controllers and data processors are not required to conduct a specific type of mandatory audit – as defined in national regulations adopted under Directive 95/46. On the contrary, the general rule would be that the data controller or processor has the discretion to define the procedures for review and evaluation, provided that those procedures ensure complete verification and assessment of risks connected with the security of files.

approach will differ if the data controller or processor has voluntarily adhered to a given code of conduct (which could define detailed procedures for testing and reviewing purposes) or if they are bound by national regulations that, being aligned with the GDPR anyway, impose specifically defined (and mandatory) audit procedures.

 

Stibbe, together with Chiomenti, Cuatrecasas, GIDE and Gleiss Lutz, have gathered this useful information, reflecting some common misconceptions about the implementation of the GDPR.

Team

Related news

20.05.2020 NL law
Stibbe in Amsterdam answers questions from consumers, small business foundations and NGOs about the coronavirus [updated]

Inside Stibbe - In a special Q&A (in Dutch), lawyers from our Amsterdam office share their legal expertise and strive to provide answers to questions put to us by consumers, self-employed persons, enterprises large and small, foundations and NGOs as a result of the corona crisis.

Read more

07.05.2020 NL law
E-book 'De huidige NOW en de verwachte wijzigingen in de nieuwe/verlengde NOW (NOW 2.0)'

Articles - Op 1 april 2020 werd de Tijdelijke noodmaatregel overbrugging voor behoud van werkgelegenheid gepubliceerd (“NOW”). Sinds 6 april 2020 is het UWV-loket geopend en kunnen werkgevers een aanvraag doen voor loonkostensubsidie onder de NOW. Op 30 april 2020 waren er ongeveer 114.000 aanvragen ingediend bij het UWV.

Read more

08.04.2020 NL law
Schadevergoeding bij de bestuursrechter op grond van de AVG voor feitelijk handelen van een bestuursorgaan?

Short Reads - Op 1 april 2020 heeft de Afdeling bestuursrechtspraak van de Raad van State (“Afdeling”) een viertal uitspraken gewezen waarin zij oordeelt over het verzoek tot toekenning van schadevergoeding door een bestuursorgaan op grond van de (Europese) Algemene Verordening Gegevensbescherming (AVG).

Read more

This website uses cookies. Some of these cookies are essential for the technical functioning of our website and you cannot disable these cookies if you want to read our website. We also use functional cookies to ensure the website functions properly and analytical cookies to personalise content and to analyse our traffic. You can either accept or refuse these functional and analytical cookies.

Privacy – en cookieverklaring