Overview Next training
Our teachers for the training: Data Protection Auditor Training
Data Protection Auditor Training
This three-day training course offers Data Protection Officers and privacy professionals a practical approach to efficiently auditing and systematically monitoring their organization’s GDPR compliance, as expected of a DPO under Article 39(1)(b) of the GDPR.
The training combines international audit standards, governance principles, and concrete audit techniques with realistic case studies from the instructor/auditor’s professional practice. Participants learn not only how to prepare and conduct an audit, but also how to correctly formulate findings, identify risks, and communicate audit results in a clear and convincing manner to the governing bodies that bear ultimate responsibility.
This training begins with the question: “How can we objectively determine whether an organization is truly GDPR compliant?” It focuses on governance structures, audit methodologies, and certification and accreditation systems, while also referencing ISO standards such as ISO 27701 and actively applying audit standards such as ISO 19011. Throughout the training, participants work with real-world examples, interactive exercises, and simulations that prepare them for actual audit situations and the accurate preparation of DPO reports with clear action plans and realistic priorities.
Training features
DPO’s role in GDPR compliance
DPOs must independently oversee data protection compliance, using audit skills to assess risks and provide clear recommendations to management.
Enhanced DPO skills
Practice-oriented training, designed for DPOs who wish to strengthen their role as independent and critical overseers of data protection.
From audit to GDPR accountability
Assess data protection compliance in a systematic, audit-driven manner. This training adapts internal audit methods to data protection and GDPR accountability.
From objectives to audit plan
The training focuses on aligning data protection goals with a risk-based annual plan, covering both organisation-wide and thematic audits.
Plan – Conduct – Report
Using a case study, participants learn to plan, conduct, and report a GDPR audit, with focus on the DPO’s role, turning findings into improvements.
Train management reporting skills
The training builds practical management reporting skills to structure insights, present key performance indicators clearly, and deliver concise reports.
Course highlights
- Practical GDPR audit training specifically designed for DPOs and privacy professionals
- Insight into audit objectives, governance, and compliance monitoring
- Implementing the obligation set forth in Article 39(1)(b) of the GDPR regarding the DPO’s supervisory role
- Overview of certification, accreditation, and ISO systems
- In-depth introduction to ISO 19011 and the six audit phases linked to the PDCA cycle
- Techniques for interviews, evidence gathering, and formulating findings
- Focus on facts versus assumptions in audit reporting
- Practical examples and real-life cases from experienced auditors
- Introduction to AI tools and prompting in an audit context
- Interactive group assignments and boardroom simulation
- Practice in presenting a major finding to an executive committee
Target group
Are you a DPO, an internal or external auditor or do you want to further improve your advice for customers? Do you need guidance for a GDPR audit? Do you want to assess processors on GDPR or do you want to carry out external audits? Then this training is for you. GDPR knowledge is required for this training.
Learning goals

Educational approach of this course
This module is taught in English and takes place in a training room in a hotel.
The training is provided by teachers who are top experts in their field. The teachers present the subject matter by means of a presentation.
There is interaction with the group during the explanation. Typically, the group for this course is about 20 students (minimum 8, maximum 24 students).
Each student receives a printed version of the training material with space for taking notes. In addition, the information is made available in a digital learning environment. For all knowledge items, the teacher refers to practical examples.
How to prepare yourself
DPO certification or an introductory course GDPR.
You do not have to prepare anything prior to this training, except for a refresher on the main principles of the GDPR.
Day 1
Fundamentals of Auditing and Compliance
The first day begins with an overview of the different types of audits and the essential characteristics of an effective audit. We will also explore the relationship between auditing, governance, and organizational structure. On the first day, we will focus on conducting an ISO 19011 audit, including formulating audit objectives, developing an audit plan, and designing audit activities step by step.
The central question here is: how do we verify whether an organization is GDPR compliant, and what objectives does a client or organization aim to achieve through this? Participants will receive an overview of different types of audits and the essential characteristics of an effective audit.
Day 2
Audit Methodology and Practical Application
The second day focuses on the practical execution of audits. The six audit phases are discussed in detail and linked to the PDCA cycle. Additionally, attention is given to social styles and communication skills, so that auditors can more effectively deal with different types of auditees.
Furthermore, the instructor covers techniques for obtaining relevant findings, distinguishing between facts and assumptions, and drafting clear and actionable audit reports. All topics are supported by practical examples and experiences from real-world audit situations. We also explore the use of Artificial Intelligence in auditing: where can you apply AI, and what factors should you consider?
At the end of the day, participants work in pairs on a practical exercise that involves identifying and reporting one or more non-conformities. The results are discussed in a group.
Day 3
Exercises, Simulation, and Reporting to the Board
The third day begins with a discussion of the individual exercise and the key takeaways. Participants then work in pairs on a second practical exercise in which they analyze and prepare one or more audit findings.
The highlight of the training is a boardroom simulation in which participants present a significant finding to a fictional board of directors, played by members of DPI. In doing so, they practice not only their audit knowledge but also their presentation, communication, and persuasion skills in a realistic management context.
Price
€2.195
VAT exclusive
Lunch, coffee, refreshments, course material and exam included.
Price Government Institutions: €1.750
SME portfolio Flanders - higher subsidy for theme CYBERSECURITY: 45% for small and 35% for medium-sized enterprises.
Book a Call
Planning 2026 - 2027
Name
Date
Location
Language
Register
Data Protection Auditor Training
22 June until 24 June 2026
Data Protection Auditor Training
21 June until 23 June 2027