Table of Contents

The Information Audit Form is a non-legal tool, intended as an aid when creating a record of the personal data held by your company. A comprehensive inventory of personal data held is a fundamental step towards GDPR compliance, as well as general good practice in data privacy protection.
 
This Information Audit Form is structured around reasons for collecting and processing personal data. Please consider all areas of your business when deciding whether or not a section of this form applies to your company.
 
In-depth knowledge of the GDPR is not required to fill in this audit form, but honest answers are necessary for the integrity of record-keeping. If you are not sure of the answer, don’t know, or need to check, fill in the fields accordingly. Please also take note of the location(s) of data storage to fill in the last part of the audit.
 
In each section, our helptext provides you with examples of information that might go in each field of the audit table, to give you a sense of direction when answering those questions. These examples are for reference only. It is crucial that you fill in each field with factual, accurate and specific information that applies in your situation. 
 
For each purpose for processing personal data, you must identify a legal basis for the processing. The GDPR has set out 6 possible legal bases that can be relied on when processing personal data:
 
(1) Consent: clear consent has been given for the processing of personal data for a specific purpose (consent must be specific to each purpose or opt-in and be easily withdrawn by the data subject, with evidence of this consent).
(2) Contract: processing is necessary for the performance of a contract you have entered into with an individual, or is necessary to carry out specific steps leading up to entering into a contract.
(3) Legal obligation: processing is necessary for complying with the law.
(4) Vital interests: processing is necessary to protect the vital interests of the data subject or another natural person.
(5) Public function: processing is necessary for a public body to perform a task in the public interest, or an official function.
(6) Legitimate interests: processing is necessary for your legitimate interests or the legitimate interests of a third party (applies unless these legitimate interests are overridden by a good reason to protect the individual’s personal data. A separate Legitimate Interests Assessment (LIA) is recommended).
 
Important Note: The GDPR is a complex principle-based law subject to further interpretation by the supervisory authorities of each EU country. If you are not sure whether your data handling practices are compliant with the GDPR, please seek professional legal advice.
 

What are the types of information security audits?

There are 4 main types of information security audit which are as follows:

  1. Risk assessment: this helps identify various threats to your business. 
  2. Vulnerability assessment: Will look for weak spots, which could be used to exploit or harm your business. 
  3. Penetration testing: This is a controlled and permitted attempt at hacking your system, to look for cracks and bypasses which need upgrading.
  4. Compliance audit: This is quite crucial for a business as it ensures that a business is legally in line with the governing laws. 
 

About Author

Daniel Walker

Daniel Walker

Daniel Walker is the Founder and Chief Executive Officer of Zegal, the trusted legaltech firm. Prior to founding Zegal, Daniel practised at DLA Piper, Stephenson Harwood and Clyde & Co, in Hong Kong, Singapore, and the UK.

Stay compliant with the Zegal template library

Zegal legal template are meticulously crafted with the precision of AI and the expertise of seasoned human lawyers, providing a unique blend of speed and reliability.

You can trust that Zegal agreements are legally sound and fully compliant with current regulations.

Whether you're a startupSME, or a larger enterprise, Zegal contract management will automate and speed up your legal processes.

Using Zegal will reduce risk, save money, and improve efficiency. Let us take care of the paperwork so you can focus on running your business.

Don’t compromise on speed or compliance. Stay secure, compliant, and efficient with Zegal.

“Love the new flow/design, very quick and easy to use now. I have done 2 or 3 customer contracts in a flash over the past 2 days.”

Get Started

Related Documents

If you're creating an Information Audit Form, you may also be interested in the following documents: