You will be redirected to the website of our parent company, Schönherr Rechtsanwälte GmbH: www.schoenherr.eu
Within the framework of the "Coordinated Enforcement Framework", the data protection authorities of the EU Member States, together with the European Data Protection Board (EDPB), set the authorities' annual audit priorities. In recent years, audits have focused on the use of cloud services by public bodies, the implementation of the right of access, and, last year, the right to erasure at hundreds of companies.[1] These audits have directly led to numerous administrative penalty proceedings were initiated ex officio, often resulting in fines. Both SMEs and large companies have been audited.
The enforcement audits for 2026 will focus on controllers' compliance with the transparency and information obligations under Articles 12, 13 and 14 GDPR. The Austrian Data Protection Authority has announced that it will additionally audit the security of processing requirements under Article 32 GDPR, including the associated documentation obligations under Article 30 and, where applicable, the risk assessment under Article 35 GDPR. This means that compliance with the fundamental requirements of the GDPR will be the focus of this years' review:
To be prepared for any (unannounced) audit by the data protection authority, the company's entire data protection documentation must be critically reviewed. It can be assumed that the authority will examine more closely any inconsistencies discovered, for example, during its review of the record of processing activities. Furthermore, data protection practices must reflect the requirements arising from the extensive data protection case law of recent years, including: (i) the tiered obligation to communicate specific recipient identities (CJEU 12 January 2023, C-154/21, Österreichische Post); (ii) stricter obligations regarding data transfers to third countries (CJEU 16 July 2020, C-311/18, Schrems II) and for the selection and documentation of legal bases (CJEU 4 July 2023, C-252/21, Meta Platforms); and (iii) stricter requirements regarding the position of the Data Protection Officer (Austrian DPA 16 October 2024, DSB-D550.769). In addition, all documents must be brought up to date and the actual processing activities must be accurately and completely reflected.
We would be pleased to assist you in implementing a legally compliant and comprehensive update of your data protection compliance and the related documentation.
author: Florian Terharen
Florian
Terharen
Attorney at Law
austria vienna