Audit Is Coming: Prepare for the White Walkers (aka Customers and Regulators)

No ratings

Presented at GlobalPrivacySummit 2019 by

Many controller-to-processor data processing agreements contain strong audit clauses, and we have only started to understand how EU regulators are auditing companies. Based on practical experience in auditing and being audited, the speakers will discuss multiple audit scenarios and the preparation needed for them. The speakers will share insights from an audit by a regulator on the implementation of GDPR processes in a company, customer audits, audits by certification authorities, internal audits and vendor audits. They will look into the cost and benefits of paper audits versus on-site audits, and they will also talk about an approach towards auditing your contract partners. Lastly, they will look at the different styles of audit reports, technical audits and legal audits alike.What you’ll take away:Understand the audit clause in your controller-to-processor agreement: what is permissible, how to prepare, the features and dynamics of an audit, what regulators have audited, and how they have approached the auditLearn about killer questions and how to prepare for them