Overview Next training
Our teachers for the training: Data Protection Auditor Training
Under the GDPR, the role of the Data Protection Officer goes beyond providing advice. DPOs are also expected to exercise independent and critical oversight of an organisation’s actual compliance with data protection requirements. This supervisory responsibility requires structured audit competencies, including planning assurance activities, assessing risks, conducting interviews and document reviews, and formulating clear, actionable recommendations for management.
Learn how to conduct an audit: Through a stap-by-step approach we will guide you from scratch to conduct a GDPR audit. We will learn how to set audit objectives, scope, planning, audit activities and management reporting.
Do it yourself and get feedback and guidance: We will challenge you to conduct your own audit based. We will bring participants together to evaluate and discuss your audit strategy, plan and reporting skills. You will be challenged to audit your own company or a DPI produced case.
A 3-Day Practical Format: The training spans three days to ensure a deep understanding of both theory and practice. While the first two days focus heavily on how to audit compliance, the third day is specifically designed as an online mentoring and feedback session. During this final day, you will learn how to translate your audit results into concrete improvement actions and build your own audit report. Furthermore, you will practice techniques for reporting to management and the board, directly benefiting from peer review and mentor feedback.
Training features
DPO’s role in GDPR compliance
DPOs must independently oversee data protection compliance, using audit skills to assess risks and provide clear recommendations to management.
Enhanced DPO skills
Practice-oriented training, designed for DPOs who wish to strengthen their role as independent and critical overseers of data protection.
From audit to GDPR accountability
Assess data protection compliance in a systematic, audit-driven manner. This training adapts internal audit methods to data protection and GDPR accountability.
From objectives to audit plan
The training focuses on aligning data protection goals with a risk-based annual plan, covering both organisation-wide and thematic audits.
Plan – Conduct – Report
Using a case study, participants learn to plan, conduct, and report a GDPR audit, with focus on the DPO’s role, turning findings into improvements.
Train management reporting skills
The training builds practical management reporting skills to structure insights, present key performance indicators clearly, and deliver concise reports.
Why take this course?
- This module is an ideal introduction to the world of audits
- You want to apply the GDPR in your company
- You want to check whether the GDPR has been applied correctly
Target group
Are you a DPO, an internal or external auditor or do you want to further improve your advice for customers? Do you need guidance for a GDPR audit? Do you want to assess processors on GDPR or do you want to carry out external audits? Then this training is for you. GDPR knowledge is required for this training.
Learning goals
Educational approach of this course
This module is taught in English and takes place in a training room in a hotel.
The training is provided by teachers who are top experts in their field. The teachers present the subject matter by means of a presentation.
There is interaction with the group during the explanation. Typically, the group for this course is about 20 students (minimum 8, maximum 24 students).
Each student receives a printed version of the training material with space for taking notes. In addition, the information is made available in a digital learning environment. For all knowledge items, the teacher refers to practical examples.
How to prepare yourself
DPO certification or an introductory course GDPR.
You do not have to prepare anything prior to this training, except for a refresher on the main principles of the GDPR.
Click here for more information about our teachers.
Day 1
- Audit objectives and annual planning for data protection
- Translation of organisational risks into risk-based audit plan
- Preparation and initiation of an organisation-wide audit
- Methodology for auditing governance & management systems
- Application of ISO 19011 to data protection
- Audit criteria for accountability and GDPR compliance
- Document review of policies, procedures and audit evidence
- Interview techniques and walk-throughs
- Evaluation of internal controls and management measures
- Structuring and formulating audit findings
- Risk assessment and prioritisation of observations
- Reporting findings and recommendations
Day 2
- In depth exercises on document findings, risk measurement, quality objectives and drafting audit reports.
- Translating audit results into concrete improvement actions
- Report the audit to management: practice and techniques
Day 3 - Online
- Build your own audit report
- Report to the board
- Get mentoring
- Peer review and mentor feedback
Price
€2.195
VAT exclusive
Lunch, coffee, refreshments, course material and exam included.
SME portfolio Flanders - higher subsidy for theme CYBERSECURITY: 45% for small and 35% for medium-sized enterprises.
Book a Call
Planning 2026
Name
Date
Location
Language
Register
Data Protection Auditor Training
22 June until 24 June 2026