Skip to main content

Pro audit program · v1.0

GDPR Readiness Quick Check

A practical 30-minute self-check on the GDPR controls that fail most audits — not a full DPIA.

  • General target area
  • GDPR framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

A practical 30-minute self-check on the GDPR controls that fail most audits — not a full DPIA.

Risks addressed

  • High No basis recorded for processing categories of data
  • Critical Breach notification timeline missed (>72h)
  • High No DPA with a Tier-1 processor

Controls (7)

  1. Article-30 Record of Processing Activities maintained

    High

    Article 30 of the GDPR mandates that organizations acting as data controllers or processors maintain comprehensive, up-to-date written records of all personal data processing activities. These records document the purposes of processing, categories of data subjects and personal data, recipients,…

    How to test + evidence

    Testing procedure: RoPA exists, covers all processing activities, dated within 6 months.

    Evidence to collect: RoPA file.

  2. Lawful basis recorded per processing activity

    High

    This control requires organizations to document the lawful basis for each personal data processing activity in accordance with applicable privacy regulations such as GDPR Article 6, CCPA, or other jurisdictions. Each processing activity recorded in the Record of Processing Activities…

    How to test + evidence

    Testing procedure: Each activity has a documented basis (consent, contract, legitimate interest, …).

    Evidence to collect: RoPA — basis column.

  3. DPAs in place for all processors

    High

    This control requires that formal Data Processing Agreements (DPAs) are executed with all third-party data processors who handle personal or sensitive data on behalf of the organization. DPAs define the scope, duration, nature, and purpose of data processing, establish processor…

    How to test + evidence

    Testing procedure: Article-28 contracts on file for every Tier-1/2 processor.

    Evidence to collect: DPA inventory.

  4. Breach notification process tested

    Critical

    This control requires organizations to periodically test their data breach notification process through simulated exercises or tabletop scenarios. Testing validates that procedures for identifying, classifying, escalating, and notifying stakeholders (customers, regulators, partners) of security incidents function as documented. Regular testing…

    How to test + evidence

    Testing procedure: Workflow tested; named DPO + comms templates; <72h timeline understood.

    Evidence to collect: Tabletop AAR.

  5. Subject access (DSAR) workflow tested

    Medium

    This control validates that the organization has designed, documented, and operationally tested its Data Subject Access Request (DSAR) workflow to ensure timely, accurate, and complete responses to individual rights requests under privacy regulations such as GDPR, CCPA, or similar. Testing…

    How to test + evidence

    Testing procedure: Test request handled end-to-end within statutory window.

    Evidence to collect: DSAR test report.

  6. Privacy notice up to date

    Medium

    This control requires that privacy notices provided to data subjects are kept current with actual data processing activities, legal requirements, and organizational practices. It ensures that individuals receive accurate, complete information about how their personal data is collected, used, stored,…

    How to test + evidence

    Testing procedure: Public-facing notice reflects current processing + last reviewed within 12 months.

    Evidence to collect: Notice + review date.

  7. Cross-border transfers via SCCs / adequacy

    High

    This control ensures that personal data transferred outside the European Economic Area (EEA) or other jurisdictions with strict data protection laws is protected through legally recognized mechanisms. Organizations must rely on European Commission adequacy decisions (recognizing equivalent protection in destination…

    How to test + evidence

    Testing procedure: Transfers outside EEA covered by SCCs or adequacy decision; TIAs done.

    Evidence to collect: SCC inventory + TIAs.