Data Protection Audit
DataHub Consulting, Experts in Analytics, Business Intelligence, and ComplianceRead it in 10 minutes
1200
627
Read it in 10 minutes
As part of our Risk & Compliance Services, Datahub Consulting deliver data protection projects to customers all over the world. Currently we are working with airlines and airports in the Middle East, manufacturing & retail companies in UK and Europe, Visa companies in Canada, and an hotel in Asia.
Our team comprises of legal experts and risk analysis professionals all with a background in data protection. Then data engineers that understand the technical aspect of IT security that can work closely with customer IT teams to bridge the gap between data protection and IT security.
We commonly get asked by customers about the audit process, what’s involved, how long it will take. This article answers a lot of questions that we get asked about and explain the process from start to finish. For any customer the audit is nothing to be afraid of, we guide customers through the process and provide an informative audit report at the end.
As part of Datahub’s data protection services we have a comprehensive audit framework that we can use to audit against any data protection law with customers in any industry. We have a full audit that deep dives into a customers data protection framework. We also have a lite audit where we will look at specific areas of focus. Usually, we only conduct a lite audit with customers that have already had a full audit and scored higher than average. With the lite audit we also like to go in unannounced so only a small number of the senior leadership team know about it. This enables us to see the business when they are not prepared for us.
What does the customer receive? After the audit the customer will receive a detailed audit report in non-technical language so the leadership team can fully understand their strengths and areas for improvement.

The audit process will allow Datahub to deep dive into a customer’s data protection framework and to fully assess if there are any risk to the organisation, to the data subjects, to any partners that you work with.
So that we can achieve this, the audit is made up of three sections.
The pre-assessment, review & audit report will be conducted from the Datahub offices. Whereas the audit will be conducted at the customers offices. For the audit we always do this at the customers offices as we will be looking at the security measures of the building like access control, the knowledge and awareness of staff, and also how data protection is embedded in the operations of the business. We also look at the general IT security awareness of staff, for example do they lock the machines when they leave their workstation, how frequent are passwords changed, are staff aware of what to do in the event of a data breach etc.
Early in the audit process the customer will be allocated a lead auditor. This will be the person that visits the organisation and conducts the audit. There will also be a secondary auditor. This person will review the audit in the review & report stage to ensure that the lead auditor has gathered all the necessary information, been fair and accurate with the audit, make recommendations, and to support with the action plan.


The pre-assessment usually will take up approx. 16 hours (2 days of work). But we understand that information will be fed to us over time. So, for this reason the 16 hours could be spread over 2 week period.
The audit, depending on the size of the organisation and the number of processes that involve personal information will take between 3-5 days. From our experience for an airline with many departments and lots of data containing personal information this will take 5 days. This will be based on the audit of the airline headquarters and excludes any country offices or airport offices etc. Then finally the review and audit report will take 3 days to complete.

We recommend an audit when an organisation starts working with Datahub Consulting. This could be for implementation of a data protection framework or DPO as a Service. We do this so that we have a full understanding of your business, the current data protection framework in place, how the business has adopted data protection, and an understanding of the areas where we can support.
We also recommend an audit periodically. This will very from 12 to 24 months based on your previous audit scores and any remedial actions recommended. This periodic audit could be either a full or lite audit. Data protection is a continual improvement process and constantly needs to be assessed. We would look at if there was any changes in a customer’s business processes, staff changes, changes that could affect risks to the personal information of the data subjects. Having periodic audits ensures continuity and compliance.

We start the audit with the pre-assessment to understand your business, how you use personal information, and the security measures in place. We will do this by asking for any documents and information to be sent though to us.
Information that we would request and review:

The audit consists of 266 controls covering the 12 sections listed below. The controls measure the full scope of a business’s data protection capabilities. Creating our detailed audit was the collaboration of the Datahub Team from legal, risk, and IT security experts. Each having their input to provide a full and concise audit benchmark.
Sections covered in the audit:

After the audit visit we may be given further information or documents by the customer to validate information provided. The review will conclude all the audit notes, review the last of the documents, and to provide a Datahub internal peer review with the secondary auditor
We feel that we have a duty of care to the customer to provide an accurate, complete, and unbiased audit. The customer has placed their trust in Datahub to assess if their current compliance is sufficient to minimise any risks, and the processes in place are good enough to be considered compliant. This is why we have a secondary auditor to validate the audit.
For customers that partner with us we feel that we have a duty of care to provide an accurate, complete, and unbiased audit. The customer has placed their trust in Datahub to assess whether their current compliance is sufficient to minimise any risks, and whether the processes in place are robust enough to be considered compliant. This is why we assign a secondary auditor to independently validate the findings, ensuring consistency, impartiality, and the highest standards of quality in every audit we deliver.

The audit report is what the customer receives after the audit. The audit will be approx. 15-20 pages in length and will include scores generated using an algorithm based on the information collated during the audit. Of the 266 controls, they are not all equally weighted, so some have more importance than others.
For this reason, we use our unique algorithm to provide an accurate scoring process based on a weighting factor. Also, the algorithm takes into consideration any applicable data protection laws. For example, EU GDPR article 37 (Designation of a DPO) designates when a DPO is required. But there are data protection laws that don’t mandate the requirement for a DPO. Where these laws are being audited, even though Datahub will always recommend a DPO, the algorithm would ensure the audit score would not be affected.
What the report will consist of:

At Datahub Consulting, we don’t just assess compliance, we uncover opportunities to strengthen your data governance, reduce risk, and build trust with stakeholders.
Our audits are designed to fit your industry, regulatory requirements, and business operations. Combining global data protection expertise with a practical approach, we deliver guidance that is actionable and aligned with your business priorities.
Discover how our audits empower you to not only meet standards, but exceed them.
“Datahub Consulting guided us seamlessly through our first data protection audit. As we hadn’t undergone one before, we were unsure what to expect or where our compliance gaps might be. Their team made the entire process smooth and straightforward, with clear communication and expert support at every step.“
Managing Director
(Financial company In Dubai)
Datahub are experts in global data protection laws and support businesses large and small all over the world. We work with global airlines, airports, retailers, financial services, healthcare organisations, and energy providers.
Contact Our Team
If you are interested in knowing more about our data protection or cybersecurity services what’s the next step!
It wouldn’t cost you anything to start a conversation with our CEO who is a data protection practitioner and subject matter expert in global data protection laws. Our CEO is an expert in data engineering with 22 years of data experience, 15 years of these are consulting with customers all over the world. He has advised global brands all over the world on data compliance and privacy best practices.
Contact Us: Contact us | DataHub Consulting
Datahub Risk & Compliance Services: Risk and Compliance | DataHub Consulting
We do not employ salespeople; our team are all experienced technical specialists that can talk you through any of our services.
Contact us