What the inspector wants to see on the table
The Office for Personal Data Protection (ÚOOÚ), the Czech data protection authority, does not merely ask that documents exist. Inspectors check that policies are current, cover every process and link to enforceable technical controls. The baseline set comprises the information security policy, access control policy, data retention and deletion policy, incident response plan and the record of processing activities (ROPA). Each document must carry a version number, approval date, owner and revision history. In practice a frequent gap appears: a password policy states one rule while Active Directory is configured with 365‑day expiry and zero history. The inspector records the contradiction as a deficiency.
Risk management as the backbone of evidence
The risk analysis methodology, whether ISO 27005 or a proprietary model, must cover all assets that hold personal data. Inspectors expect a table of threats, vulnerabilities, existing controls, residual risks and a treatment plan. For every risk the evidence must show which technical or organisational measures (TOMs) mitigate it. A typical Czech example: an e‑shop records the risk “SQL injection on the order form”, notes the existing control as a web application firewall, rates residual risk as low and plans regular penetration tests. If the evidence lacks a penetration test from the past 12 months the inspector treats the missing test as a failure to follow the plan.
Technical proof: logs, configurations, tests
Documents without technical artefacts are insufficient. The inspector asks for firewall rule exports that demonstrate network segmentation, multi‑factor authentication settings in Azure AD/Entra ID, backup policies with tested restore, disk encryption (BitLocker, LUKS) and encryption in transit (TLS 1.2 or higher). Vulnerability scanner output (for example OpenVAS, Nessus) and penetration test reports with confirmed remediation are also required. CIAD audits show that organisations often commission a penetration test but leave findings in a state other than “fixed and retested”. The inspector treats such open findings as an incomplete task.
Access evidence and incident management
The role‑based access control matrix must match reality in the HR system and Active Directory groups. The controller requests a list of privileged accounts, their usage history and the offboarding checklist that revokes access when an employee leaves. For incidents the inspector looks for a timeline: detection, classification, containment, resolution, notification to the Office for Personal Data Protection (ÚOOÚ) where a risk to data subjects’ rights exists, and measures to prevent recurrence. A common shortfall: a ticketing system exists but incidents are not tagged as security related and there is no proof of notification within 72 hours.
Training and suppliers as part of the evidence
The final dimension covers the human factor and the supply chain. Organisations need records of completed training, date, content, attendees, knowledge test results, and data processing agreements (DPAs) with processors, including a register of sub‑processors and international transfers (SCCs, TIAs). For cloud services (Microsoft 365, AWS, Google Cloud) the inspector expects exported security scores, Conditional Access configuration and evidence that data does not leave permitted regions. A missing DPA with an external accounting or HR agency is a standard finding in Czech inspections.
What this means for any GDPR‑regulated organisation
Prepare an “inspection package”, a structured directory with subfolders for policies, risks, technical outputs, access, incidents, training and suppliers. Link every artefact to the specific requirement in GDPR Article 32 and be ready to show live system configuration, not only a PDF export. The Czech experience mirrors what supervisory authorities across the EU increasingly demand: documented, current and technically verifiable proof that security measures are actually operating.
Frequently asked questions
What if we don't have a formal risk analysis, just antivirus and a firewall?
Without a documented risk analysis, you cannot prove that measures correspond to threats under Article 32(1) GDPR. The inspector will assess this as insufficient TOMs and may order remediation with a sanction. Companies should create at least a basic risk table and assign specific control mechanisms to them.
Do we need a penetration test from an external company?
GDPR does not explicitly require an external pentest, but it requires regular verification of the effectiveness of measures. In practice, the inspector also accepts internal tests if they are methodically described, independent of operations, and have a remediation protocol. The important thing is to show that findings were fixed and retested.
How old must the logs and backups we present be?
The period is determined by your internal policy and data type. For access logs, the standard is 12 months; backups must cover RPO/RTO defined in the BIA. The inspector will verify whether retention policies match the reasons for retention and whether data can be restored in time.
Are English policies sufficient for an international corporation?
If employees in the Czech Republic do not work in English daily, the inspector requires a Czech version or at least key processes translated. Proof is that the employee understood the policy (signature, test). Without a local version, there is a risk of an objection of non-transparency.
What if a cloud service provider does not provide a DPA?
Without a DPA, the contract does not meet Article 28 GDPR. You must replace the provider or achieve signing of an addendum. Temporary remediation: documented risk analysis and compensatory measures (client-side key encryption), but this is only a temporary solution.