Adapting a project to the requirements of GDPR-related regulations is a challenge faced by many IT system providers. This only makes us prouder that our product has received a positive recommendation following an audit.
Read this article to find out:
- what the audit looked at;
- what was the purpose of the audit;
- what good practices we used to achieve such good results.
The audit concerned information security and was carried out on the basis of the rights of the Personal Data Controller under the GDPR by consulting company KPMG for Volkswagen Group Polska.
A one-day meeting with the auditor covered the verification of documentation, information management procedures, and the practical implementation of all key principles. The auditor was given access to all documentation and the possibility of interviews with selected staff members participating in the project.
Audit Purpose and Result
The process was designed to check if data processing complies with the GDPR and the contractual requirements imposed by VGP on all suppliers.
The auditor had no concerns about the organization of work on the project or the quality of information security management by Unity Group. We obtained recommendations to confirm the high standard of information security with the formal ISO 27001 certificate.
This means that our formal solutions meet the stringent standards that must be satisfied to apply for this certificate
How to Achieve a Positive Outcome of the GDPR Audit
Over a year and a half, as part of the project of preparing the company for the GDPR, we introduced a number of organizational and formal changes to raise the standards of information security. In cooperation with an external consulting company, we inventoried in-house processes and developed documentation and proposals for solutions in accordance with the ISO 27001 standard. We appointed a Data Protection Officer, who ensures that the quality of information security management is maintained at all times.
For our clients, this means that Unity Group can be fully trusted in matters as sensitive as personal data. We are well aware of the importance of the regulations, and we strictly follow them. We are a reliable partner not only in the IT aspect of a project but also in everything that makes up its business environment.
— Anna Gubernat, Project Manager