Legal
Procedure for Internal Audit of Data Privacy and Protection Compliance
Last updated: March 10, 2026
Introduction
iENTR recognises the importance of ensuring compliance with data privacy and protection standards and laws. This procedure outlines the steps for implementing an internal audit function to evaluate iENTR's adherence to these standards and laws. The audit function aims to oversee employee adherence to company protocols, policies and the usage of computers and/or mobile devices as well as maintaining a list of employees who have had access to Personal Data obtained on behalf of iENTR. Specific monitoring techniques and tools are detailed to detect suspicious or unusual activity. This procedure ensures full compliance with the New Zealand Privacy Act and other applicable laws.
Appointment of Internal Audit Function
- iENTR shall appoint a dedicated internal audit function responsible for assessing data privacy and protection compliance.
- The function may be led by a designated privacy officer or an independent auditor with expertise in privacy and data protection laws.
- The internal audit function should operate independently and have sufficient authority, resources and access to conduct comprehensive audits.
Audit Planning and Scope
The internal audit function shall develop an annual audit plan that identifies the areas to be audited based on risk assessment and compliance priorities. The plan should consider factors such as the sensitivity of data, the complexity of processes and changes in regulatory requirements. The scope of the audit should cover:
Adherence to Policies and Protocols
Review the implementation and effectiveness of iENTR's data privacy and protection policies and protocols including access controls, data classification, data retention, incident response and employee training.
Usage of Computers and Mobile Devices
Assess the usage of computers and mobile devices within iENTR to ensure compliance with data privacy and protection standards. This includes monitoring the security configurations, encryption practices, software updates and employee adherence to acceptable use policies.
Maintenance of Employee Access List
Verify the existence and accuracy of a comprehensive list of employees who have had access to Personal Data obtained on behalf of iENTR. This list should include relevant details such as names, roles, access levels and dates of access.
Monitoring Techniques and Tools
Evaluate the monitoring techniques and tools employed by iENTR to detect suspicious or unusual activity related to data privacy and protection. This may include intrusion detection systems, log monitoring, security incident and event management tools and data loss prevention mechanisms.
Conducting Audits
The internal audit function shall conduct audits in accordance with the annual audit plan. The audit process includes the following steps:
Pre-Audit Preparation
Notify the relevant departments and individuals about the upcoming audit outlining the objectives, scope and expected timelines. Request relevant documentation such as policies, procedures, access logs and incident reports.
Document Review
Thoroughly review the relevant documentation to assess compliance with data privacy and protection standards, laws and internal policies. This includes examining policies and procedures, training materials, incident reports, access logs and relevant agreements.
Interviews and Data Sampling
Conduct interviews with employees involved in handling Personal Data and sample data to validate adherence to protocols, policies and standards. This may involve reviewing access controls, data handling processes, encryption practices and incident response procedures.
Technical Assessment
Perform technical assessments to evaluate the effectiveness of monitoring techniques and tools. This may involve analysing logs, network traffic, system configurations and access controls to detect any suspicious or unusual activity.
Reporting and Recommendations
Prepare a comprehensive audit report that documents findings including any areas of non-compliance, identified vulnerabilities and recommended remedial actions. The report should also highlight areas of good practice and commendable adherence to data privacy and protection standards.
Remediation and Follow-Up
iENTR shall develop a process for addressing the findings and recommendations identified in the audit report. The process includes developing a remediation plan to address any areas of non-compliance or vulnerabilities identified during the audit. The following steps should be taken:
Prioritisation of Findings
Assess the severity and potential impact of each finding to prioritise remediation efforts. Focus on addressing high-risk areas first to mitigate any immediate risks to data privacy and protection.
Remedial Actions
Develop and implement specific action plans to address each finding. This may include revising policies and procedures, enhancing security controls, providing additional training or implementing technical safeguards. Assign responsibilities to relevant stakeholders for the execution of remedial actions.
Monitoring and Follow-Up
Establish a mechanism to monitor the progress of remediation efforts. Regularly review the implementation of corrective measures to ensure they are effectively addressing the identified issues. Conduct follow-up audits if necessary to validate the effectiveness of the remedial actions taken.
Documentation and Reporting
Maintain detailed documentation of the remediation process including the actions taken, responsible parties, timelines and outcomes. Provide periodic progress reports to senior management and the internal audit function to demonstrate compliance improvements and ongoing commitment to data privacy and protection.
Continuous Improvement
iENTR recognises that achieving and maintaining data privacy and protection compliance is an ongoing process. The internal audit function should continuously assess and refine audit procedures based on emerging risks, regulatory changes and industry best practices. Regularly review and update policies, protocols and training programs to ensure they reflect current legal requirements and organisational needs.
Legal Compliance
Ensure that the internal audit function operates in full compliance with the New Zealand Privacy Act and any other applicable laws and regulations. Maintain confidentiality and securely handle any personal data accessed during the audit process.
Independence and Objectivity
The internal audit function should maintain independence and objectivity in conducting audits. Avoid conflicts of interest and ensure that auditors are free from undue influence or bias. If necessary, engage external auditors or experts to provide an independent assessment of data privacy and protection compliance.
Conclusion
By implementing an internal audit function and following this procedure, iENTR can proactively evaluate its adherence to data privacy and protection compliance standards and laws. Through regular audits, monitoring techniques and remediation efforts, iENTR can enhance its data privacy and protection practices, mitigate risks and demonstrate its commitment to safeguarding personal data in compliance with the New Zealand Privacy Act and other relevant laws.