Introduction
摘要
The term “audit” is used not merely descriptively, referring to specific practices, but normatively within the context of demands and aspirations for accountability and control. The history of financial auditing surpasses that of many other fields, and the work of auditing significantly influences both the practices of accountants and financial institutions. The shift from “detecting fraud” to “providing an objective opinion” reflects the modern dimension of financial auditing. Auditors realized that instead of verifying the arithmetical accuracy of every transaction, they could assess these factors on a test basis after evaluating the strength of internal control. Consequently, an expectation gap emerged between the audit’s intended function and its practical achievements. In the realm of personal data processing, the right to personal data naturally differs from the right to process data as held by processors. In other words, processors do not own the personal data of users but possess the right to process it with user consent. Audits for personal data protection have become essential tools for evaluating the adequacy of data protection measures and ensuring compliance with legal and regulatory requirements. From a technical perspective, conducting audits for increasingly complex algorithmic systems necessitates a proper accountability framework that organizes different actors within the technical sector. From a legal standpoint, this calls for various legislations and regulations implemented in diverse ways.