DPO Privacy
DPO Privacy
PlatformSolutionsAI governancePlansContentAbout us
PTENES
Book a demo
Book a demo
PlatformSolutionsAI governancePlansContentAbout usBook a demo
HomePublicationsAudit and Evidence
Audit and Evidence

Privacy Audit: How to Conduct It and Document Evidence

A well-conducted privacy audit is essential to demonstrate compliance. Learn the step-by-step process to plan, carry out and document internal audits under the LGPD (Brazilian General Data Protection Law).

A
Ana Beatriz Santos
January 28, 202611 min read

Privacy audits are systematic assessment processes that verify whether an organization's data processing practices comply with the LGPD (Brazilian General Data Protection Law) and with internal policies. They are a central element of the accountability principle.

What Is a Privacy Audit

A privacy audit is a formal, documented assessment that verifies the organization's adherence to data protection rules. It can be:

  • Internal: Conducted by the compliance team itself or by the DPO
  • External: Carried out by independent auditors or specialized consulting firms
  • Regulatory: Carried out by the ANPD (Brazilian Data Protection Authority) in inspection proceedings

Phase 1: Planning

Planning defines the scope, criteria and schedule of the audit:

  1. Define the scope: Select the processes or areas to be audited
  2. Create a checklist: Base it on the articles of the LGPD and on ANPD resolutions
  3. Schedule interviews: Identify the owners of each process
  4. Prepare documentation: Gather the RoPA and current policies and procedures

Phase 2: Execution

During execution, the auditor collects evidence and verifies compliance:

Evidence Collection

Evidence can be collected from various sources:

  • Formalized documents and policies
  • Records of training delivered
  • Consent and opt-in/opt-out logs
  • Records of data subject request handling
  • Security incident reports
  • Contracts with processors and third parties
  • Security settings and access controls
Audit trail: A good governance platform should keep an automatic audit trail of all actions performed, which significantly facilitates the evidence-gathering process.

Phase 3: Documentation and Report

The audit report should present findings clearly and objectively:

Report Section Content
Scope Processes and areas audited
Methodology Criteria and collection techniques used
Findings Conformities and non-conformities identified
Risk Classification Criticality level of each finding
Recommendations Suggested corrective and preventive actions
Action Plan Schedule and owners of the corrections

Phase 4: Follow-up

The audit does not end with the report. It is essential to monitor the implementation of corrective actions:

  • Set clear deadlines for each corrective action
  • Assign specific owners
  • Carry out periodic follow-ups
  • Document the resolution of each finding
Continuous cycle: DPO Privacy makes it possible to create action plans directly from audit findings, track deadlines, assign owners and generate progress reports, all with complete traceability and an automatic audit trail.

Structure your governance with DPO Privacy

Centralize process mapping, risk calculation, RoPA, DPIA, the Data Subject Portal and AI governance in a single platform.

Schedule a demonstration
AuditEvidenceComplianceLGPDDocumentation
Share
A
Ana Beatriz Santos
Information Security Consultant
  1. What Is a Privacy Audit
  2. Phase 1: Planning
  3. Phase 2: Execution
  4. Evidence Collection
  5. Phase 3: Documentation and Report
  6. Phase 4: Follow-up

Discover the platform

Centralize all data and privacy governance in one place.

Schedule a demo

Structure your governance with DPO Privacy

Centralize process mapping, risk calculation, RoPA, DPIA, the Data Subject Portal and AI governance in a single platform.

Schedule a demonstrationExplore features
Back to publications
DPO Privacy

Privacy and personal data protection governance platform for managing compliance with the LGPD (Brazilian General Data Protection Law) and the GDPR.

Platform

  • Modules
  • AI governance
  • Data and Technology
  • Enterprise
  • Plans
  • Security

Company

  • About us
  • Contact

Resources

  • Content
  • Help Center
  • Frequently asked questions

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy

© 2026 DPO Privacy · All rights reserved · Made in Brazil

Developed bysyntez