A privacy policy can be accurate on the day of its publication and false six months later. A team adds a tool, the support exports conversations, a SDK changes its collection, a backup is kept unlimited.
The documentary record is not enough, nor is technical compliance alone.
The audit links four realities: what the organisation says, what it has decided, what its systems do and what people live. Diversions are the core of the diagnosis.
1. CNIL figures to situate the risk
In 2025, the CNIL received 20,150 complaints, 10% more than in 2024. About 1,900 complaints were directly related to data personal data breaches. The complaints concerned work, commerce, real estate, social networks and other contexts.
The CNIL conducted 323 checks and issued 259 corrective measures: 83 sanctions, 143 formal notices, 31 reminders and two warnings. The 78 fines totaled €486,839,500, an amount largely influenced by two major decisions. Therefore, an audit should not minimise the risk or calculate a "probable fine" by rule of three.
The authority received 6,167 notifications of personal data breaches in 2025. One out of two reported incidents involved hacking. personal data breaches were often massive and frequently involved providers according to its record.
Cybersecurity accounted for one third of the controls and almost 30% of the sanctions. In 2026, CNIL announced that it would devote 50% of its checks and enforcement actions to data security. Security is not an annex to the GDPR audit.
The 2025 penalties against Google and Shein, respectively EUR 325 million and EUR 150 million, included cookie-related deficiencies; their scope and context are not transferable to any company, but the facts — filing, refusal, withdrawal — are technically verifiable.
2. The letter of assurance: what the audit can conclude
The sponsor defines the objective: a global review, preparation for control, acquisition, incident, new activity or verification of a previous plan.
The mission letter specifies entities, countries, periods, processing activities, systems, subcontractors and exclusions. It describes authorised accesses, interviews, samples and tests. It identifies DPO, controllers, advisers and the receiving committee.
The audit does not issue a universal certification "GPR compliant". It provides reasonable assurance on a scope and on a date, based on the available evidence. The limits are visible.
The auditor does not alone validate procedures they designed. The DPO retains an advisory and oversight role; operational managers remain accountable for corrections.
3. Audit universe and sampling
The registry provides a basis, but the auditor is also looking for processing activities missing from the record. Sources: SaaS purchases, invoices, tag manager, applications, API, warehouses, HR, support, marketing, shared files and subcontractors.
Each processing activity receives factors such as volume, sensitivity, vulnerable people, surveillance, automated decision-making, transfer, sharing, innovation, duration, incidents and external exposure.
The sample covers:
- all high-high-risk processing activities;
- one case per large function;
- a critical supplier;
- recent processing activity;
- old processing activity;
- consent-based processing activity;
- a contract, obligation or legitimate interest;
- a rights process;
- a deletion;
- a recent personal data breach.
A comprehensive audit may be necessary for a small structure. In a group, sampling is documented. A lack of deviation in twenty files does not prove absence in twenty thousand; it supports a defined level of assurance.
4. Test 1 — Governance and accountability
The auditor verifies roles, register, policies, DPO, committee, training, privacy by design and documentation of decisions.
Evidence: flowchart, mission letters, reports, analyses, trainings, reviews, exceptions and budgets. Interviews test knowledge: "What do you do before purchasing a new tool?"
The register is compared to the systems. Each line has purpose, categories, people, recipients, transfers, duration, security and owner. Generic formulations "service improvement" are challenged.
The auditor follows a project from idea to production. Does the DPO or privacy function intervene early enough to change the architecture? Approval the day before launch is not privacy by design.
The exceptions have a date. A compensatory measure is followed. The committee receives implementation indicators, not just the number of sheets.
5. Test 2 — Purpose, lawful basis and data minimisation
For each processing activity sampled, the auditor reformulates the purpose as a specific result. The auditor checks the lawful basis and its application.
The consent must be free, specific, informed and unambiguous, with proof and withdrawal. The contract covers what is objectively necessary for its execution, not everything that interests the company. The legitimate interest requires identification of interest, necessity and balance. The legal obligation is related to the text.
The audit compares the fields collected with the decisions. A "useful later" data with no current purpose is discarded or investigated.
Inferences and enrichments are included. A probability of departure, a segment or a note are personal data when they relate to an identifiable person.
Reuse is subject to compatibility analysis or a new basis. The presence in a data lake does not create any general right.
6. Test 3 — Transparency and information
The records are compared to the actual path: form, cookies, application, contract, recruitment, video surveillance, AI and support. The information is accessible before or at the appropriate time, in understandable language.
The auditor responsible control, purposes, bases, recipients, transfers, durations, rights, withdrawal, indirect source, automated decision-making and contact as appropriate.
A multilayer notice can improve readability: summary at the point of collection, accessible detail. The link must not lead to a generic policy that omits the tool.
Vulnerable children, employees and publics need appropriate attention. Information is not only legally comprehensive; it must allow for real choice or understanding.
A short user test can reveal whether people find how to refuse, withdraw or contact. It completes the legal analysis.
7. Test 4 — Consent and trackers
The audit combines interface and network. It tests before choice, acceptance, refusal, granular choice, withdrawal and return, on several third-party devices and routes.
It lists cookies, local storage, SDK, pixels and queries. Each tracer has purpose, duration, provider, status and evidence. The declared manager tag is compared to the network, as scripts can be injected elsewhere.
The CNIL states that certain trackers strictly necessary for audience measurement may be exempted under conditions, in particular limited purpose for the publisher's sole account and no incompatible reuse. The tool is not exempted by its name; its configuration is verified.
The refusal must be as simple as acceptance according to the applicable requirements. The withdrawal modifies future processing activities. Pings without cookies and modelling are documented.
The audit keeps captures, queries, time stamping, storage status and version of CMP. A capture of the banner alone does not prove the behaviour.
8. Test 5 — Data subject rights
The auditor selects requests for access, rectification, erasure, objection, restriction and portability. They measure receipt, identity, search, response, delay, exceptions and propagation.
A "authorised fictitious person" exercise can be performed. The organisation must find CRM, support, marketing, billing, warehouse, exports and subcontractors. It does not provide data from other people.
The access response is understandable. Unreadable technical export may be insufficient. Decisions to refuse or extend are justified.
The rectification is spread to consumers. The deletion covers index, cache and tools, with specific backup management. Proof of execution and failures are followed.
Requests are a source of diagnosis. Repeated complaints about a purpose may reveal a problem of transparency or design.
9. Test 6 — Retention and deletion
The auditor selects records that exceed the retention period and checks their status. They compare policy, configuration and legal basis.
The duration has a trigger: end of relationship, last qualified interaction, closure of file. Exceptions — litigation, obligation — are separated and restricted.
Intermediate archiving reduces access. It does not become a permanent preservation. Backups have a rotation and a mechanism preventing lasting reappearance after restoration.
Automatic deletions generate logs and alerts. A script programmed but failed for six months is a major deviation.
The anonymization is tested according to the possibilities of re-identification. Remove name and e-mail often remains a pseudonymization.
10. Test 7 — Processors, contracts and transfers
The list of suppliers is reconciled with the flows and expenses. Each relationship is qualified. Instructions, confidentiality, security, subsequent subcontractors, rights, personal data breaches, deletion and audit are reviewed.
The auditor verifies the implementation, not only Article 28. Do the published subcontractors correspond? Does the support access from other countries? Do the data remain after termination?
Transfers outside the European Economic Area are mapped. Adequacy decision, standard contractual clauses, additional measures and analysis are examined according to the context. The storage region does not respond to all accesses.
A sample of supplier diligence compares questionnaire and evidence: certification, report, penetration test, incident, architecture and contract. A non-contractual commercial response is noted as such.
A provider involved in twenty processing activities increases the impact of an incident.
11. Test 8 — Security and personal data breaches
The audit is based on risk: identity, lesser privilege, MFA, secrets, encryption, patches, backups, logs, segmentation, development, testing and suppliers.
It selects inactive accounts, privileged access, exports, test environments and large databases. It checks reviews, alerts and revocation.
A recent personal data breach is followed: detection, confinement, qualification, decision to notify, delay, information, correction and feedback. Decisions are documented.
The exercise simulates a leak in a provider. The team must identify data, people, risk, contacts and measurements. The notification clauses are faced with the real time required.
The GDPR audit is not a penetration test. It can trigger a specialized security audit when evidence or exposures so require.
12. Test 9 — Impact assessments and high-risk processing activity
The auditor verifies the criteria for triggering an DPIA, its timing and quality. The analysis describes processing activity, necessity, proportionality, risks for rights and measures.
It is not limited to a matrix; it examines the consequences: exclusion, discrimination, surveillance, manipulation, loss of confidentiality, impossibility of exercising a right or material damage.
High residual risks are dealt with in accordance with the applicable procedure. The measures have ownership and timelines. The AIDPD is reviewed after changing model, given, population or purpose.
For the AI, the auditor distinguishes development, training, evaluation and use. The CNIL recommendations on the AI systems help to frame purpose, responsibilities, base, reuse and rights.
13. Test 10 — Automated decisions and profiling
The scores, rules and recommendations are inventoried. The auditor asks: Does the decision have a legal or significant effect? Is it fully automated? What exceptions apply?
Human control is real if the person has information, time, competence and authority. Clicking "validate" on 500 files per hour is not a substantial review.
The information, meaningful logic, consequences, recourse and possibility of intervention are checked as appropriate. Performance and bias are monitored by segment.
The model and threshold are versioned. A supplier update must not silently change an important decision.
14. Classifying gaps
Each observation shall contain criteria, evidence, cause, impact, population, frequency and recommendation. The auditee shall have the right of reply.
Logiks uses four levels.
Critique. Active personal data breach likely to cause high risk, lack of essential control or major exposure. Immediate action.
Major. Significant or systemic deviation affecting a principle, right or large population.
Moderate. Limited deviation, insufficient evidence or fragile process without immediate damage observed.
Minor. Hygiene, documentary consistency or low exposure improvement.
The potential amount of a fine is not calculated automatically. Severity follows risks for people, scope, duration, intent, control and context.
Causes are grouped: governance, architecture, supplier, competence, debt, incitement or incident. Correcting only the document leaves the cause.
15. Assurance score
The report notes the design and effectiveness separately. A procedure can be well designed but not executed.
The areas are: governance, legality, transparency, rights, retention, suppliers, security, high-risk processing and evidence. Everyone receives coverage and trust.
A cap prevents the label “controlled” when a critical gap remains uncontained. The score is not a marketing claim; it tracks remediation.
Confidence depends on the sample, access and convergence. An inaccessible configuration reduces assurance even if no anomalies were observed.
16. Practical case: declared deletion, still active data
One company responds to requests for deletion by deleting the CRM. The audit follows three closed requests. Addresses remain in the e-mail tool, warehouse and commercial export.
The cause is architectural: no common identifier or propagation workflow. The teams considered each tool as an independent copy.
The correction creates a register of consumer systems, a demand ID, removal connectors and a failure file. Backups are documented and reintroduction prevented after restoration.
The audit retests ten profiles, including merged accounts and former clients. The spread rate and the delay become indicators. The policy was correct; control becomes effective.
17. Deliverables expected
- scope, universe and sample;
- mapping of missing processes and flows;
- test and evidence dossier;
- register of qualified deviations;
- analysis of contracts, transfers, security and rights;
- design/effectiveness score with confidence;
- immediate plan, 30, 90 and 365 days;
- owners, budget and closure criteria;
- Executive summary and operational annex;
- continuous control programme.
A finding is closed only after proof and retest. The updating of a policy does not close a removal that still fails.
18. Frequently Asked Questions
18.1. Does the audit guarantee compliance?
It provides assurance on a scope, on a date and on evidence. processing activities change. Compliance remains an ongoing process and an organisation's responsibility.
18.2. Can the DPO audit?
Yes depending on the organisation, preserving independence, means and absence of conflict. An external review can complement sensitive topics or procedures designed internally.
18.3. How long does it take?
Four to twelve weeks depending on size, quality of registry and technical depth. Incident preparation can quickly target critical processing activities.
18.4. Should we test all subcontractors?
All are inventoried and contractually arranged; the depth of diligence follows the risk. Critical and sensitive suppliers are tested as a matter of priority.
18.5. How often?
An annual risk-based programme, with post-incident review, new major processing, acquisition or regulatory change. Durations, rights and access are continuously monitored.
19. What the auditor must obtain before closing a finding
An updated policy does not close an operational non-compliance. The responsible person provides proof of deployment, a sample of execution and, where relevant, logs showing that the rule is affecting the systems concerned.
For a retention period, the acceptance test selects data close to and beyond the deadline. It checks production, replication, exports and backups according to the defined regime. Exceptions have a justification, duration and limited access.
With respect to fees, several requests are replayed from receipt to response. The team measures identification, search, propagation, delay, information and exceptions. An exact mail model does not compensate for a copy not found.
For a processor, the closure combines contract, instructions, measures, subprocessing chain, place, transfer, incident handling and data return; when the supplier declares a correction, the organisation checks the configuration of its own tenant, because an available but not activated capacity does not reduce the risk of the actual processing.
Security evidence include access control, reviews, appropriate encryption, backups, alerts and incident drills. Third-party certification supports insurance on its scope; it does not automatically respond to the customer's particular configuration.
The report retains three states: corrected and counter-tested, risk accepted by the competent authority, or open. An exceeded deadline never becomes green by changing comment.
The follow-up includes age of deviations, recurrences, requests, personal data breaches, subcontractors and changed processing activities. Long values remain legible: a serious incident is presented separately instead of being diluted in an average rate.
A quarterly management review selects the highest-high-risk processing activities, examines changes in purpose, new data, recipients, incidents and late deviations, and then checks that decisions have been applied in the systems concerned rather than only added to the registry or action plan.
For fee applications, the table shows median, extreme cases, exceptions and causes of overrun, so that a good average does not mask complex files or sources unable to respond.
For personal data breaches, feedback links chronology, detection, qualification, notification, information, correction and prevention; it distinguishes established facts from assumptions and retains the elements necessary for a possible future demonstration.
For critical providers, the review controls changes of subprocessors, regions, terms, assurances, incidents and re-evaluation dates, and then triggers an analysis when the actual service deviates from the original file.
Finally, the annual balance sheet brings together product changes, new acquisitions, migrations, AI usages, decisions of the authorities and lessons learned from internal controls, and then re-evaluates the sample and priorities according to the current risk; this deliberately longer sentence reflects a simple reality: compliance does not progress by accumulation of documents, but when the organisation knows how to detect that a processing has changed, reopen its analysis, modify systems and demonstrate execution.
20. What Logiks recommends
Confront each registry with a system and each policy with a sample. Prioritise rights, large databases, providers, trackers and high-impact processing activities. Separate design and effectiveness, then close a gap only after retest. Demonstrable compliance lives in evidence of implementation.
21. Main sources
- CNIL, Annual Report 2025 : https://cnil.fr/fr/rapport-annuel-2025
- CNIL, Penalties and corrective measures: 2025 balance sheet : https://cnil.fr/fr/bilan-sanctions-2025
- CNIL, Personal Data Security Guide: https://www.cnil.fr/fr/securite-des-donnees
- CNIL, Audience measurement tools and Exemption Conditions: https://www.cnil.fr/fr/cookies-et-autres-traceurs/regles/cookies-solutions-pour-les-outils-de-mesure-daudience
- CNIL, recommendations for the development of the systems of AI: https://www.cnil.fr/fr/developpement-des-systemes-dia-les-recommandations-de-la-cnil-pour-respecter-le-rgpd
- EUR-Lex, Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj
