Data Protection Audit: How to Assess Where Your Business Really Stands
Quick answer: A data protection audit is a structured review of what personal data your business collects, why, where it lives, who can access it, and whether your policies and practices actually match what UK GDPR requires. It typically covers your data inventory, lawful bases, consent mechanisms, third-party contracts, and incident readiness. Most scale-ups should run one at least annually, or whenever the business changes shape (new product, new market, new funding round), and the findings should feed straight into a prioritised action plan, not just a filing cabinet.
Why Most Scale-Ups Discover Gaps They Didn't Know Existed
Here's the thing nobody tells you when you're 30 people and moving fast: your data protection setup was probably built by whoever had five minutes to spare, not by anyone thinking about what the business would look like a year later. That's not a criticism. It's just how scale-ups work.
Then you grow. New tools get added. New data gets collected because someone in product thought it'd be useful. New people join and nobody's quite sure who owns the privacy policy anymore. By the time you're 100+ people, there's usually a real gap between what your documentation says you do and what's actually happening day to day.
Cyber security and data incidents aren't rare either. Government research puts the figure at 43% of UK businesses reporting a breach or attack in the past 12 months, according to the Cyber Security Breaches Survey 2025/2026. An audit is how you find your gaps before an investor, a customer's procurement team, or the ICO finds them for you.
What a Data Protection Audit Actually Covers
A proper audit isn't a box-ticking questionnaire. It's a proportionate, evidence-based look at how personal data moves through your business. At Trust Keith, the scope usually spans five areas:
- Data inventory: what personal data you hold, where it's stored, and who processes it, mapped against the records-of-processing requirement in UK GDPR's Article 30.
- Lawful bases: whether each processing activity has a valid legal basis, and whether that basis is documented anywhere a regulator could actually find it.
- Policies and notices: privacy notices, internal policies, retention schedules, and whether they match what's genuinely happening in the business.
- Consent and rights mechanisms: cookie consent, marketing opt-ins, and how you'd actually handle a subject access request if one landed tomorrow.
- Third-party and supplier risk: who you share data with, whether contracts are in place, and whether those suppliers are handling data the way you think they are.
Some audits also assess whether particular processing activities need a formal Data Protection Impact Assessment, especially anything involving large-scale monitoring, special category data, or automated decision-making.
The Step-By-Step Audit Process
A good audit follows a fairly predictable order, even though the detail changes depending on how complex your data processing is.
1. Build (or refresh) the data inventory
You can't audit what you can't see. Start by mapping every system, tool, and process that touches personal data, including the shadow IT nobody officially signed off on. This becomes the backbone of your records of processing.
2. Check the lawful basis for each activity
For every processing activity in your inventory, confirm which lawful basis applies under UK GDPR, and whether it's actually documented anywhere, not just assumed. This is one of the most common gaps auditors find. Businesses often rely on "legitimate interests" by default without ever writing down the balancing test.
3. Review policies against reality
Pull up your privacy notice, retention policy, and internal data handling guidance. Then check them against what's actually happening. It's surprisingly common to find a retention policy that says "12 months" next to a database that's never deleted anything since 2021.
4. Test consent and rights processes
Walk through what would happen if a customer submitted a subject access request today. Would you know where to look? Could you respond within the statutory timeframe? Do this for cookie consent too.
5. Assess your third-party and supplier chain
Check that data processing agreements exist with every supplier who touches personal data on your behalf, and that they meet the requirements set out for processors under UK GDPR. If you can't find the contract, that's a finding in itself.
6. Stress-test incident readiness
Does anyone know what to do in the first hour after a suspected breach? Is there a documented process, or does it live entirely in one person's head? This is worth testing before you need it, not during.
Data Protection Audit vs Gap Analysis: What's the Difference
People use these terms almost interchangeably, but they're slightly different exercises. An audit is a full, structured review of your current state across all the areas above. A gap analysis is usually narrower and more targeted. It compares your current practices against a specific standard, framework, or upcoming requirement, like preparing for a specific customer's due diligence questionnaire or a particular certification.
Both are genuinely one-off, fixed-scope projects. That's different from ongoing compliance support or an outsourced DPO service, which is continuous, ongoing work rather than a single engagement. Trust Keith runs both audits and gap analyses as standalone projects, and also provides the ongoing support that keeps you compliant in between them.
How Often Should You Audit
There's no single legal requirement dictating audit frequency, but most scale-ups benefit from a full audit at least once a year, with lighter reviews triggered by specific events:
- A funding round: investors and their lawyers will ask, and you want answers ready, not answers invented on the spot.
- A new product or market: new processing activities mean new lawful bases and potentially new risks to assess.
- A major tool or vendor change: switching CRMs or adding a new AI tool changes where personal data lives.
- Team turnover in privacy-adjacent roles: when the person who "knew where everything was" leaves, that knowledge needs to be somewhere more durable than their head.
Who Should Actually Run the Audit
This question tends to come down to the same trade-off as the "who should be our DPO" question, because the two roles overlap so much in practice.
An in-house person, whether that's someone with "DPO" in their title or just whoever's picked up privacy as part of a bigger role, knows the business inside out and can move fast. The honest weakness isn't competence, it's independence and continuity. It's hard to audit your own work objectively when you're also the person who built the processes being reviewed, and if that person's on leave or leaves the company altogether, there's often nobody else who knows the setup well enough to step in.
An external specialist brings genuine independence, because they sit outside the day-to-day operational structure and have no stake in defending decisions they didn't make. This is exactly why Trust Keith's outsourced DPO service works the way it does. It's continuous, ongoing support, not a one-off project, so the person acting as your DPO gets to know your processing the way an in-house hire would, but stays independent of it. That expert is backed by a full team of DPOs rather than working alone, so audits, reviews, and day-to-day questions don't grind to a halt just because one person's unavailable. You never lose cover and never lose momentum on staying compliant.
A standalone audit or gap analysis is a slightly different thing again, a genuinely one-off, fixed-scope project rather than ongoing oversight, and it's a sensible starting point even if you're not ready to commit to an ongoing DPO arrangement yet.
What to Do With Your Findings
An audit that ends in a PDF nobody opens again isn't worth much. The findings should turn into a prioritised, owned action plan, ideally ranked by risk rather than by how easy each fix is. Quick wins matter, but the highest-risk gaps (undocumented lawful bases, missing supplier contracts, no breach response process) deserve attention first, even if they're the harder ones to fix.
This is where a lot of scale-ups get stuck. The audit tells you what's wrong, but fixing it, tracking it, and keeping it fixed as the business keeps changing is a different job entirely. That's the gap between a one-off compliance project and ongoing privacy management, and it's worth being honest with yourself about which one your business actually needs right now.
Frequently Asked Questions
Do I need a data protection audit if I already have a DPO?
Yes, an audit and a DPO serve different purposes. A DPO provides ongoing oversight and advice, while an audit is a point-in-time assessment. In fact, a good DPO will often recommend regular audits as part of their role, and use the findings to shape what they focus on next.
What's the difference between an internal review and a formal audit?
An internal review is informal, usually done by whoever's closest to the data day to day. A formal audit is structured, independent, and evidenced, which matters a lot if you ever need to show a regulator, investor, or customer that you took it seriously.
Can a data protection audit help with investor due diligence?
Very much so. Having a recent, documented audit ready to share is one of the fastest ways to answer investor data protection questions without scrambling, and it signals that the business takes this seriously before anyone even has to ask.
What happens if an audit finds serious gaps?
That's not a failure, it's the point of running one. The ICO itself expects organisations to have processes for identifying and fixing gaps, and has a range of powers, including the ability to issue enforcement notices, set out under Article 58. Finding the gaps yourself, on your own terms, is always better than having them found for you.
Where to Go From Here
Running an audit is genuinely useful on its own, but it's most useful when it's part of a bigger picture rather than a one-off exercise you revisit next year and wonder what changed. Trust Keith offers standalone audits and gap analyses for businesses that want a full, structured view of where they stand, alongside the ongoing support to keep that picture accurate as things change.
If you'd rather start lighter first, we've also put together a free Data Privacy Risk Assessment, a quick, no-pressure look at where your risk actually sits based on your size, structure, tools, and how you handle data, with tailored advice and free resources matched to your results.


.png?width=2048&height=400&name=Blog%20Banners%20(21).png)
.png?width=3584&height=700&name=Blog%20Banners%20(12).png)
.png?width=244&height=61&name=CTAs%20(14).png)
.png?width=240&height=60&name=CTAs%20(16).png)
.png?width=3450&height=1150&name=blog%20cta%20(5).png)