Data Protection Audits: The GDPR is built on the principle of Accountability. Data controllers are therefore responsible for and may be called to demonstrate its compliance with each GDPR requirement. In effect, organisations require documentary proof on how they support the principle of privacy by design and default, manage their security posture, respond to subject access rights requests and communicate data breaches to regulators and data subjects when required. DigiTorc offers the folllowing data protection auditing services to help data controllers to satisfy themselves by undertaking a:
- GDPR Gap Analysis
- GDPR Maturity Level Assessment
- Health Insurance Portability and Accountability Act (HIPAA) Assessment for US Healthcare Market
- Data controller Supply Chain Assessment
- EU Data Protection Certification Readiness Assessment (Europrivacy Mark)
AI Act Audits: AI officers working with developers, manufacturers, importers, resellers and deployers of potentially High-Risk AI systems or services, will need to commission one or more of the following audits at various points throughout their AI Model Lifecycles:
- AI Gap Analysis
- AI Maturity Level Assessment
- Third-party AI vendor Conformity Assessment
- CE Mark Preparation and Readiness Assessment
The EU AI Office may also conduct or commission third-parties to evaluate General Purpose AI (GPAI) models in the market to assess compliance with AI Act obligations, or identify systemic risk in GPAI models at Union level. The EU Commission may appoint independent experts or scientific panel (Article 68) to conduct evaluations on behalf of the EU AI Office.
Cybersecurity Audits: To help organisations prepare for a certification audit against the ISO/IEC 27001 standard, DigiTorc provides the following cybersecurity auditing services:
- ISO/IEC 27001 Preparation and Readiness Assessment
- NIST Security Risk Management Framework Preparation and Readiness Assessment
Digital Markets Act Audits: Under Article 13, each Commission-designated Gatekeeper must submit their systems annually to independent audits to inspect the techniques used to profile consumers. At any time, the EU Commission may request an independent inspection and assessment of organisations, IT systems, algorithms and data handling practices.
Digital Services Act Audits: Under Article 37, each Commission-designated Very Large Online Service Provider (VLOP) and Very Large Online Search Engine (VLOSE) must submit their systems to compliance audits annually. Assigned Digital Services Coordinators may request the assistance of independent auditors to undertake these assessments.
DigiTorc offers fixed price undertakings for Data Protection, Cybersecurity and AI Act audits that will show you exactly:
- How compliant you are with regulations and standards,
- How you compare with similar organisations,
- A prioritised Top 10 risk-reducton remedial action plan for your organisation to work on to achieve its compliance objectives.
Contact us now to book your audit.
- PECR: an Introduction
- What are Joint Controllers?
- Four key points to include in contracts between Data Controllers and Data Processors
- GDPR Data Retention: Adequate, relevant and not excessive
- GDPR: encryption, pseudonymisation and anonymisation – security as a Russian doll
- GDPR and Charities in Ireland
- 3 Free Information Security tools
- First five questions for GDPR compliance
- GDPR a primer