错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Audits as a Means of Self-Monitoring

  • Paul Voigt,
  • Axel von dem Bussche

摘要

In order to ensure a high level of data protection within the EU, the European legislator relies on a high degree of personal responsibility on the part of data processing companies. Controllers are legally accountable (see Sect.  3.1 ), meaning they must ensure compliance with the GDPR while complying with the legal obligations set out by the Regulation. Both ad hoc and planned audits by the supervisory authorities are conceivable to ensure the GDPR is upheld (see Sect.  7.1.3 ). If companies fail to provide proof of compliance, they may face heavy fines (see Sect.  7.3.3 ). Record-breaking fines show the importance of complying with the GDPR. However, a one-off adjustment of (internal) processes to meet the legal requirements is not enough. Companies must constantly maintain and adapt the data protection standards that have been created. This is all the more important as the GDPR is a “dynamic” instrument. Statements from the supervisory authorities and court judgements regularly clarify its provisions. As a result, the interpretation and prioritisation of individual obligations under the GDPR are constantly changing.