DIRECTIVE RESPONSE · REVISED AUGUST 22, 2026

How does a GDPR audit
work?

A GDPR audit examines a defined scope, collects evidence, identifies deviations and produces a prioritized roadmap.

In brief

A GDPR audit examines a defined scope, collects evidence, identifies deviations and produces a prioritized roadmap.

It generally takes two to four weeks for an SME, depending on the availability of the teams and the quality of the documents. The price starts around €1,200 excluding tax at RCM.

What to prepare

  • Objective and scope of the processing or mission.
  • Actors, tools, suppliers and flows concerned.
  • Documents, contracts and decisions already available.

Boundaries

This content provides general information. It does not constitute legal advice tailored to any particular situation.

Ask a DPO →
Talk to a DPO