A privacy audit is simply a structured health-check of how your business handles personal data. For small and medium businesses in England and Wales, it is the most practical way to find and fix UK GDPR gaps before they become complaints or ICO fines. Here is a step-by-step guide you can follow.
Step 1: Map your data (the data inventory)
Start by working out what personal data you hold, where it came from, where it is stored, who has access, who you share it with, and how long you keep it. Cover customers, staff, suppliers and website visitors. This "data map" is the foundation, you cannot protect what you do not know you have.
Step 2: Check your lawful bases and purposes
For each use of data, confirm you have a valid lawful basis (such as consent, contract or legitimate interests) and that you only use the data for the purpose you collected it for. Flag anything you are doing "just in case" without a clear basis.
Step 3: Review transparency (privacy notices)
Check that your privacy notice is accurate, clear and easy to find, and that it covers what the UK GDPR requires, who you are, what data you collect, why, your lawful basis, who you share it with, how long you keep it, and people's rights.
Step 4: Test your processes for individuals' rights
Make sure you can actually honour requests (access, correction, erasure, objection) within the one-month deadline. Who handles a subject access request? Is there a process? Test it.
Step 5: Assess security
Review your technical and organisational measures: access controls, encryption, backups, device security, and staff training. Most breaches come from human error, so training and access control matter as much as technology.
Step 6: Check retention and deletion
Confirm you have retention periods and actually delete or anonymise data when it is no longer needed. Holding data forever is a common and avoidable risk.
Step 7: Review suppliers and transfers
List the processors (suppliers who handle data for you) and check you have data processing agreements in place. Identify any international transfers and confirm they are covered (adequacy, IDTA, etc.).
Step 8: Marketing and cookies
Check your marketing consents and cookie banner comply with PECR. Non-essential cookies generally require prior consent. For electronic marketing, the rules are channel- and recipient-specific: most emails and texts to individual subscribers require prior consent unless the soft opt-in applies; marketing to corporate subscribers (such as limited companies) is subject to different rules and generally requires a clear opt-out rather than prior consent. Always include an easy opt-out and honour objections.
Step 9: Breach readiness
Make sure you have a breach response plan so you can notify the ICO within 72 hours where required, and individuals where the risk is high.
Step 10: Record findings and act
Document what you found, prioritise the gaps, assign owners and deadlines, and review regularly. Keeping records also demonstrates accountability, a core UK GDPR requirement.
Key takeaways
- A privacy audit means mapping your data and checking your practices against the UK GDPR.
- Cover lawful bases, transparency, rights, security, retention, suppliers, transfers, marketing and breach readiness.
- Test that you can actually honour rights requests within a month and respond to a breach within 72 hours.
- Document and act on the findings, this evidences accountability.
Sources
- UK GDPR and Data Protection Act 2018 (principles, rights, accountability, security)
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (marketing and cookies)
- ICO guidance and self-assessment tools for SMEs
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.