DP Healthchecks & Audits

The accountability principle of the UK GDPR requires controllers to demonstrate compliance with data protection principles. Data protection audits/health checks, if done properly, are a convenient tool for controllers to demonstrate accountability.  

Besides the legal, data protection audits/health checks can help you to really understand the data protection function of your business, including potentially identifying how things ought to be changed to enhance profitability and/or productivity.  

What do audits/healthchecks involve?  

Broadly there are two types of audits/healthchecks – adequacy and compliance. An adequacy audit/healthcheck focuses on understanding how a business carries out data processing and will consider its relevant policies and procedures.

A compliance audit/healthcheck goes further and tests how a businesses data protection framework works in practice.  

Often, the two types of audit are combined and their extent will be dictated by the extent of perceived risks, and available time and budget.  Audits/healthchecks typically involved questionnaires and interviews of key staff but can stretch as far as monitoring workflows across departments, for example to ascertain what steps a business takes to process a data subject access request or to deal with a suspected or confirmed personal data breach.  

What should I think about before conducting an audit/healthcheck?  

First, a business should consider whether it has sufficient resource and expertise to conduct the audit itself, or whether it should bring in a third-party auditor. Whether or not your business has an experienced Data Protection Officer will likely factor into this.  

Second, the business will need to determine the scope of the audit/ healthcheck across the business. Typical areas of a business which are audited include HR (including payroll and benefits); IT (to determine security and contingency measures in place); customer support and sales.

Whether or not to audit/healthcheck the business as a whole or by specific function will depend on the business as well as time and budget available.  Either way, a successful audit/healthcheck will require buy in from the business and should start at the top to set the correct precedent. Whilst an in house legal/compliance function or an external auditor may lead the audit/healthcheck, it will need the co-operation of the business, its staff and potentially contractors and other third parties to obtain all information needed to complete the audit.  

What happens after an audit/healthcheck?  

After an audit, typically a written report is produced detailing key results. The aim of an audit/health check report is to help the business identify actual and potential issues in relation to data protection as well as areas for improvement. Having reviewed the report, it will then be for the business to decide and implement any appropriate, necessary corrective action.  

How can we help?  

We can advise on audits/healthchecks from a data protection perspective, including what should be audited for data protection compliance.  

Want to speak with one of our experienced data protection lawyers? Get in touch with the team.  

How to get started

Don't take our word for it

speech mark red

Real world legal advice from real people. No stuffy posh nonsense or complicated legal speak for the sake of it, just great value legal advice. Making the switch to Plume was easy and has saved us a lot of money compared to our previous subscription legal service.

Chris Lake, Ops Director. Glendining Signs
speech mark red

Rachael is a diamond and very intelligent. She has a lovely style and an efficient, commercial & more collaborative approach to advising clients. It's also reassuring to know that Rachael is a former litigator so you know you are getting all-round excellent commercially sound advice. Highly recommended!

Lesley Wan, GC
speech mark red

Having negotiated against Alice personally, we were confident of her legal skills and commercial acumen. They immediately submersed themselves into our business, acting as an extension of our legal team. They worked incredibly hard, are friendly, approachable and above all could always be counted on to retain a sense of humour.”

Jen Kitson, GC, BlueYonder
speech mark red

Rachael is commercially focussed, and her investment in taking the time to get to know our business means she takes a pragmatic, human-centric approach to negotiations. She proactively gets her head around the particular priorities and constraints on each engagement, meaning she hits the ground running adding value while being able to move at pace.

Eleanor Kearon, VP Legal, Onfido
speech mark red

“Plume is anything but your traditional law firm. We found the lawyers to not only be experts in their fields, but dedicated to understanding our business, which is so important to finding innovative solutions to the problems that we bring to them. Every single person I’ve met at Plume has been a delight to work with, and that just makes all the difference. I really do feel in very good hands working with Plume.”

Tara Haig, GC, Multiverse
speech mark red

Our favourite thing about working with Plume is it doesn’t feel like we’re working with a law firm but rather an extension of our own team. The lawyers have become so embedded in our business, so commercially focussed and so tuned to our risk appetite and way of working

Francesca Porter, General Counsel, Onfido
speech mark red

The best thing about working with the Employment team is the prompt guidance and support they have given with sensitive and complex issues. They offer professional and diligent advice as well as being incredibly genuine and encouraging. It is reassuring to know they are on hand to help at all times.

Katie Whitfield, M2A
speech mark red

Everyone internally has been incredibly impressed with your work and I'm sure we will want to continue working together long-term.

speech mark red

Plume is quite clearly the best law firm in the history of the universe. With trademark protections bestowed upon us by your godly lawyers, we'll be able to focus on what we do best.... developing awesome medical technology for the blind community.

LinkedIn follower
speech mark red

Quickly understood my requirements, carried out a thorough review of the facts and produced a user-friendly reference document tailored to my business which demonstrated a strong grasp of the commercials. Take on was pain-free and everyone was friendly and responsive. Would recommend.

Charlotte Ashton, founder director, The Implicit
speech mark red

Excellent firm. Professional and ideal for start-ups.

Joe Lines, co-founder, Nook
speech mark red

The team have supported us with day-to-day and strategic legal advice throughout the year. We're grateful to them for stepping up to support us through this important milestone in MyTutor’s development and for their commitment in getting the deal over the line.

speech mark red

We currently use Plume for our small business and have had a great experience! They are knowledgeable, professional and answer in a timely fashion. Would recommend!

Angie Allgood, CMO, SmashCo
speech mark red

Great working with the folks at Plume. The quality of their work was top notch, their communication was effective and overall happy with the services provided.

Jimi Daodu, founder and CEO, Vault Hill
speech mark red

You are without a doubt the COOLEST law firm ever, and we love working with you! <3

Katy Hamilton Jennings on LinkedIn
speech mark red

They're doing amazing stuff on social media and standing out from the crowd. This is a gold standard in disruption.

Sian Thomas (@IntegrowSales) on Twitter
speech mark red

You are continuing to shape the legal industry to be more creative, compassionate, and (most significantly) human. Keep breaking down barriers - your reach is further than you may realize 🦩

Tiffany Sanchez, Sustainable Wealth Lawyer on LinkedIn
speech mark red

The team have come on board to support MyTutor, a fast growing EdTech business which previously had no in-house legal resource. The team have made a hugely positive difference in a short space of time and we feel incredibly supported by the team, who offer a commercial, low fuss and highly responsive service

Manisha Chana, CFO, MyTutor
speech mark red

Plume are a wonderful, professional and caring law firm. The communication and attention to detail we received by them in dealing with our case was brilliant. I will definitely be using them again for future needs.

Frances Lucraft, CEO/founder, Grace and Green
speech mark red

The team provided excellent leadership and support throughout our funding process. In particular, they provided comprehensive ownership and management of the close process for AccelerComm, providing excellent, professional guidance from start to finish and enabling AccelerComm to focus on growing core business growth


Dig deeper

No insights found
No insights found