Privacy audits are systematic assessment processes that verify whether an organization's data processing practices comply with the LGPD (Brazilian General Data Protection Law) and with internal policies. They are a central element of the accountability principle.
What Is a Privacy Audit
A privacy audit is a formal, documented assessment that verifies the organization's adherence to data protection rules. It can be:
- Internal: Conducted by the compliance team itself or by the DPO
- External: Carried out by independent auditors or specialized consulting firms
- Regulatory: Carried out by the ANPD (Brazilian Data Protection Authority) in inspection proceedings
Phase 1: Planning
Planning defines the scope, criteria and schedule of the audit:
- Define the scope: Select the processes or areas to be audited
- Create a checklist: Base it on the articles of the LGPD and on ANPD resolutions
- Schedule interviews: Identify the owners of each process
- Prepare documentation: Gather the RoPA and current policies and procedures
Phase 2: Execution
During execution, the auditor collects evidence and verifies compliance:
Evidence Collection
Evidence can be collected from various sources:
- Formalized documents and policies
- Records of training delivered
- Consent and opt-in/opt-out logs
- Records of data subject request handling
- Security incident reports
- Contracts with processors and third parties
- Security settings and access controls
Phase 3: Documentation and Report
The audit report should present findings clearly and objectively:
| Report Section | Content |
|---|---|
| Scope | Processes and areas audited |
| Methodology | Criteria and collection techniques used |
| Findings | Conformities and non-conformities identified |
| Risk Classification | Criticality level of each finding |
| Recommendations | Suggested corrective and preventive actions |
| Action Plan | Schedule and owners of the corrections |
Phase 4: Follow-up
The audit does not end with the report. It is essential to monitor the implementation of corrective actions:
- Set clear deadlines for each corrective action
- Assign specific owners
- Carry out periodic follow-ups
- Document the resolution of each finding
