June 4, 2018 By Kim Walsh Governance and Compliance, Industry News

It has been about ten days since GDPR went into effect, and my inbox has been a steady stream of the same basic question arriving in about forty different forms.

“Kim, does our current audit program cover GDPR?”

Short answer: probably not as completely as you think. And the gap is not usually where people expect it to be.

The General Data Protection Regulation went live on May 25, 2018, and it applies to any organization that processes the personal data of individuals in the European Union, regardless of where that organization is physically located. If you have EU customers, EU employees, or EU website visitors whose data you collect, GDPR is your problem even if your headquarters is in Ohio. That scope alone catches a lot of IT audit teams off guard, because the traditional framing of “we are not a European company” does not hold up under the regulation.

Here is what I am seeing in practice. Most IT audit programs that were built before GDPR are reasonably good at covering the technical controls side of data security. Encryption at rest, access controls, network segmentation, patch management, that sort of thing. What they tend to miss are the procedural and rights-based requirements that GDPR adds on top of the technical layer. These are not purely an IT problem, but IT audit has a clear role in assessing whether the systems and processes to support them actually exist and work.

Six GDPR Principles IT Audit Needs to Address Lawfulness Data must have a legal basis for processing Purpose Limitation Data used only for its stated purpose Data Minimisation Collect only what is necessary Accuracy Data must be kept accurate and current Storage Limitation Keep data only as long as necessary Integrity and Confidentiality Security appropriate to the risk Source: GDPR Article 5 — gdpr-info.eu

The right to erasure is one area where most audit programs have a real gap. GDPR gives individuals the right to request deletion of their personal data under certain circumstances. From an IT audit standpoint, the question is whether your organization can actually demonstrate it is capable of honoring that request across all the systems where that data might live. Databases, backups, third-party processors, archived email systems. That is a harder problem than it looks, and most organizations have not mapped it out carefully enough to audit it effectively.

Data breach notification is another area worth scrutiny. GDPR requires notification to the relevant supervisory authority within 72 hours of becoming aware of a breach that poses a risk to individuals’ rights and freedoms. That clock is aggressive. Most incident response programs were not designed with a 72-hour regulatory notification requirement in mind. Your audit program should be testing whether that capability actually exists, not just whether a policy document says it does.

Third-party data processor controls are often the weakest link. GDPR requires that organizations have appropriate contracts in place with third-party processors who handle personal data on their behalf, and it requires that those processors actually provide sufficient guarantees of compliance. Auditing the vendor management process around GDPR is work that most programs have not yet built out.

ISACA has been actively developing GDPR-specific audit guidance, and their GDPR resources are worth reviewing if you are trying to build an audit approach for this regulation. The official regulation text itself is also worth having in front of you, because some of the requirements are specific enough that paraphrased summaries do not always capture the nuance.

The honest assessment is that most IT audit teams are going to spend the next twelve to eighteen months building out GDPR coverage incrementally. That is not a failure. GDPR is a substantial and complex regulation and the organizations that are claiming full compliance right now are mostly claiming something they cannot fully demonstrate yet. The practical goal for audit is to identify the highest-risk gaps, prioritize the work, and make visible progress over time.

Start with the data map. If your organization does not have a solid understanding of where personal data lives, how it flows, who has access to it, and how long it is retained, you cannot audit GDPR compliance in any meaningful way. That foundational work is the prerequisite for everything else.

It is a lot of work. But it is exactly the kind of work that makes a well-prepared audit professional genuinely valuable to their organization right now.

Kim Walsh

Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.