Description

Personal Data Protection Audit: Scoping, Testing and Reporting Gaps

Audit a personal data processing activity with tests that go well beyond reading the records register

  • 0.43 days — 3 h
  • In-person or virtual
  • Expert
  • Up to 6 participants

Auditing data protection is not a matter of confirming that a processing register and privacy notices exist. The real gaps sit elsewhere: retention periods never applied in live databases, access rights left open to profiles that no longer need them, processors engaged without up-to-date clauses, and data exports to tools selected by business teams without any prior assessment.

These three hours are designed for experienced auditors and data protection practitioners. They build a method specific to this field: defining the audit scope, selecting the processing activities to examine, running technical and organisational tests, then reporting the gaps.

Learning objectives

  • Define the scope of a personal data protection audit
  • Select the processing activities to examine according to the risk to individuals
  • Build tests covering retention periods and access rights
  • Examine the processor chain and cross-border data transfers
  • Report gaps and set out prioritised corrective actions

What makes this programme different

Tests look for gaps in live databases and access rights rather than in documentation
The processor chain is audited through to the tools adopted by business teams
Reporting separates documentary gaps from gaps that genuinely affect individuals

Programme

1Framing the assignment

Choosing the processing activities that warrant examination

  • Defining scope across entities, processes and processing activities
  • Using the processing register as a starting point rather than as evidence
  • Selection criteria based on the risk to the individuals concerned
  • Alignment with information security workstreams
  • Documenting the audit approach adopted

2Running the tests

Looking for the gap where it actually sits

  • Verifying that retention periods are effectively applied
  • Reviewing authorisations and access to data
  • Examining processor contracts and the tools used by business teams
  • Traceability of data subject requests and response times
  • Checking transfers and outbound data flows

3Reporting and driving remediation

Gaps ranked by their effect on individuals

  • Qualifying gaps and distinguishing form from actual effect
  • Prioritising corrective actions
  • Engaging with business teams and with the data protection officer
  • Tracking remediation and setting watch points for the next audit

Who is it for

Experienced internal auditors and data protection officers, together with compliance managers and information security focal points.

Prerequisites

Sound knowledge of applicable personal data protection requirements and practical audit experience

Dates & locations

12 scheduled dates between November 2026 and December 2027. Seats are confirmed in the order enquiries are received.

November 2026

December 2026

January 2027

February 2027

March 2027

April 2027

May 2027

June 2027

September 2027

October 2027

November 2027

December 2027

None of these dates suit you? We open additional sessions on request, and any programme can be run privately for your team.

Practical details

Before the programme
Online positioning questionnaire. Your development objectives are shared with the trainer, who tailors the practical case studies to your context.
Teaching methods
Theoretical input, workshops and practical case studies. Digital course materials and method sheets provided.
Assessment
Multiple-choice tests and role-play exercises. Assessment of learning at the start and end of the programme, with immediate and 60-day follow-up evaluations.
After the programme
One year of access to the e-learning platform. Self-assessment of the skills acquired and a 30-day follow-up session with your trainer.
How to register
Registration online or on the basis of a quotation.
Lead time
11 working days after confirmation of registration.
Accessibility
Accessible to people of determination. Contact our accessibility coordinator to design a suitable solution: contact@mpf-academy.ae
Start dates
Rolling intake: in addition to the scheduled sessions, this programme can start on request.