Publication

6 December 2018

GDPR: implications for auditors

Statutory auditors regularly process personal data obtained from their clients. They are therefore directly impacted by the General Data Protection Regulation (GDPR) that entered into force in May 2018.  

This publication aims to clarify what role auditors play under GDPR, i.e. whether they act as data controllers or as data processors. This distinction matters as the responsibilities allocated to each role are different. 

We conclude that in principle, statutory auditors qualify as data controllers. For non-statutory audit services, we encourage practitioners to analyse the processing of personal data on a case-by-case basis to determine whether they will be considered data controllers or data processors. Respective role and responsibilities should be stated in the engagement letter.

 

 

 

Related content

BlogGDPR one year on: its impact on auditors and accountants?

13 May 2019

Stories from PracticeWorried about the GDPR? Call your accountant!

3 December 2018

UpdateTechnology: GDPR extra

23 March 2018

BlogGetting your SME practice GDPR proof

25 January 2018

EventThe path to high-quality non-financial information assurance

26 November 2020

EventSmall in size, big in impact: Can NFI work for SMEs?

19 November 2020

BlogReliable non-financial information to progress sustainable finance

21 October 2020

Podcast SMEs: What’s next?

16 October 2020

Consultation responseEC’s consultation on the establishment of an EU Green Bond Standard. 

5 October 2020

UpdateSME Update

24 September 2020

NewsEUIPO and Accountancy Europe join to support SMEs

24 September 2020

Consultation responseEC’s roadmap on obligation for companies to publish non-financial information

18 September 2020

Consultation responseEC’s consultation on the VAT scheme for travel agents

2 September 2020

Blog4 steps to a sustainable recovery from COVID-19

6 August 2020

Consultation responseEC’s consultation on the renewed sustainable finance strategy

15 July 2020

PublicationSME risk management: sustainability

15 July 2020

UpdateSME Update

3 July 2020

NewsEquity: the key to unlocking a sustainable economic recovery

2 July 2020

NewsJoint statement on the revision of the non-financial reporting directive in the context of Covid-19

23 June 2020

NewsAccountancy Europe leads the non-financial reporting debate

17 June 2020

Consultation responseEC’s consultation on the Non-Financial Reporting Directive revision

15 June 2020

PublicationSetting up for high-quality non-financial information assurance in Europe

12 June 2020

Consultation responsePublic letter to the IAASB: progress on draft standard for auditing less-complex entities

11 June 2020

Stories from PracticeSME auditor brings good governance to charities

9 June 2020

Sign up for our newsletter

* indicates required
Would you like to subscribe to our newsletter?
On which topics would you like to receive news?