During a data protection audit, the main aspects assessed include organizational, regulatory and IT security aspects.
On the organizational side, the audit examines how data is managed within the company, including privacy policies, data collection and storage practices, staff training on data protection and third-party risk management.
From a regulatory perspective, the audit aims to verify the company's compliance with data protection laws and regulations, such as the GDPR in Europe or the nFADP in Switzerland.
Finally, from an IT security point of view, the audit assesses the technical measures in place to protect data including access controls, data encryption, network security, endpoint security, data lifecycle management, and more.
By combining these different aspects, the audit identifies potential risks to data security and recommends corrective measures to reinforce the protection of personal data.