Contents
Introduction and basics of the data protection audit
- Sense, purpose and objectives of an audit.
- Professional and personal requirements for the:internal:n/external:n data protection officer:n/datadata protection auditor.
- Position of data protection auditors.
- Audit types and audit types.
- Determination of the scope of audits.
The internal data protection officer (DPO) as an auditor in the company
- Legal obligations of the DPO - reviewing, advising and monitoring a DMS.
- Position and role of the internal DPO as data protection auditor:in.
- DPO procedure for new appointments: inventory audit and ongoing re-monitoring audits.
Legal framework and requirements for an operational data protection management system (DSMS)
- In-depth study of the legal foundations of data protection law using case studies: General requirements and areas of application, legal bases and significance of data protection principles, rights of data subjects, data protection contract typologies.
- data privacy through technology design, data security and data breach.
- Special laws and legal peculiarities.
- Current rulings in data protection law and the views of the supervisory authorities.
- Structure and elements of a DSMS.
- Relationship to other operational management systems (e.g.: ISO 9000 ff.; ISO 27001 ff.; BS; IDW PS 980) and recognized standards in the area of data privacy (standard data protection model).
Planning and preparation of a data protection audit
- Methods and tools for the data protection audit.
- Development of an audit program - determination of the subject of the audit, including clarification of responsibilities.
- Preparation of the contacts.
- Pre-audit by the auditor, including elements of a short checklist.
- Development of a list of questions for the audit.
Implementation of a data protection audit
- Examination of the structural and process organization - structure and inspection.
- Interviews as a source of information - content and procedure.
- Documents as a source of information.
- Review and examination of data protection documents and contracts.
- Processes and design as a source of information.
- Checking the technical/organizational security measures.
- Inspection and own perception as a source of information.
Completion/termination of a data protection audit
- As-is recording and analysis; weak point and risk analysis.
- Design of the audit documentation (findings).
- Evaluation and assessment of the results: Formation of a score value/scale for the level of data protection.
- Handling of deviations and conformities.
- Development of an action plan to harmonize/raise the level of data protection - post-audit after harmonization.
- The audit report - structure, content and requirements.
- Final meeting on the audit - explanation and presentation of the report.
- Proof of effectiveness - certificates, seals & co. at the end of the audit.
Critical audit situations - behavior and possible solutions
Recommendations and guidelines for practice
Explanation of sample processes in day-to-day business operations and presentation of tools (questionnaire, test criteria for individual processing operations, sample reports).
Conclusion, discussion of open questions and exam preparation
Learning environment
Your benefit
- Expansion of technical expertise as an internal or external data protection officer
- Ability to carry out data protection audits and evaluate data protection management systems
- Provision of sample documents and checklists for direct use in day-to-day business
- After passing the final exam, a certificate is awarded that expands professional opportunities in the field of data protection audits
Methods
Lecture, presentation, guided workshops to work on specific case problems in practice, discussion, case studies and checklists.
Recommended for
Data protection officers, IT security officers, compliance officers, QM officers, auditors; project managers and auditors, data protection coordinators and people involved in data protection, as well as specialists and managers from companies who want to expand their knowledge of data protection and work as auditors.
Final examination
The final exam is a written multiple-choice test that is taken online. Access to the examination system remains active for one week after the third day of the course. You have 45 minutes to complete the test. After successful completion, the certificate will be sent to you.
Further recommendations for "Certified data protection auditor"
Seminar evaluation for "Certified data protection auditor"







30752
34957
Start dates and details
Monday, 01.09.2025
09:00 am - 5:00 pm
Tuesday, 02.09.2025
09:00 am - 5:00 pm
Wednesday, 03.09.2025
09:00 am - 5:00 pm
Thursday, 04.09.2025
09:00 am - 2:00 pm
- one joint lunch per full seminar day,
- Catering during breaks and
- extensive working documents.

Monday, 13.10.2025
09:00 am - 5:00 pm
Tuesday, 14.10.2025
09:00 am - 5:00 pm
Wednesday, 15.10.2025
09:00 am - 5:00 pm
Thursday, 16.10.2025
09:00 am - 2:00 pm

Tuesday, 03.02.2026
09:00 am - 5:00 pm
Wednesday, 04.02.2026
09:00 am - 5:00 pm
Thursday, 05.02.2026
09:00 am - 5:00 pm
Friday, 06.02.2026
09:00 am - 2:00 pm
Monday, 20.04.2026
09:00 am - 5:00 pm
Tuesday, 21.04.2026
09:00 am - 5:00 pm
Wednesday, 22.04.2026
09:00 am - 5:00 pm
Thursday, 23.04.2026
09:00 am - 2:00 pm
- one joint lunch per full seminar day,
- Catering during breaks and
- extensive working documents.

Tuesday, 28.07.2026
09:00 am - 5:00 pm
Wednesday, 29.07.2026
09:00 am - 5:00 pm
Thursday, 30.07.2026
09:00 am - 5:00 pm
Friday, 31.07.2026
09:00 am - 2:00 pm
- one joint lunch per full seminar day,
- Catering during breaks and
- extensive working documents.