Data Privacy Basics
Blogs Omair Arfeen, CIA, CFE, CISA, CICA Jul 30, 2026

Data privacy does not only apply to IT audits or financial sector audits — it should be part of all types of audits. As I noted during a recent risk assessment, “In a data-driven world, data privacy is one of the key pillars of being a trusted advisor.”
Internal auditors today operate in an environment where data is the new oil. Data flows faster than ever, across systems, departments, and even organizational and geographical boundaries. Once the domain of privacy experts and IT audit teams, data privacy is now a core part of governance, risk management, and maintaining stakeholder trust.
While internal audit reviews privacy controls, checks policies, and evaluates compliance, one basic question often goes unanswered: Does the organization know how personal data is collected, used, and protected throughout its life cycle? This is where internal auditors can create immense value and serve the public interest.
See Beyond Definitions
An initial point in data privacy is defining what comprises personal data. Most organizations recognize obvious types of data such as names, identification numbers, and contact information. The challenge arises when data is less direct or fragmented. For example, digital identifiers, behavioral patterns, location data, and system-generated logs can all be used to identify an individual. When combined, these seemingly harmless data points can reveal sensitive data.
Internal auditors should look beyond basic definitions of private or personal data. They must look at how data can be combined, interpreted, or misused in ways that can identify individuals. For example, during an audit, practitioners may find that data that initially appeared to be routine operational information could reveal personally identifiable information when combined with other data sets. Such findings can reshape the data owner’s understanding of privacy risk.
Follow the Data Flow
Data does not remain in one place — it flows through processes, systems, and individuals throughout its life cycle. Effective data privacy audits focus on how the organization manages the movement of data by asking:
- How is data collected?
- Where and how is data stored?
- Who has access and uses data?
- How is data shared externally?
- When and how is data deleted?
This simple data life cycle perspective enables auditors to observe the complete trail of data. In a recent audit, mapping the customer information path showed that the organization had good controls when data was first collected. However, weak processes allowed information to be exported, shared informally, or stored outside the controlled environment. The lesson: Following the data trail often finds gaps that policies and controls fail to address.
Look for Hidden Weaknesses
Most data privacy breaches aren’t caused by a highly advanced fault. Many weaknesses build up during routine operations and because of convenient decisions and become exposed over time.
Several themes keep occurring:
- Too much data collection. Organizations often accumulate large amounts of data without a clearly defined business purpose.
- Uncontrolled data sharing. Data is shared both inside and outside the organization without consistent oversight.
- Weak access discipline. Authorization is very liberal or broad and not limited to specific roles.
- Unspecified retention practices. Data is stored longer than necessary.
One of the most revealing audit findings I’ve encountered involved a secondary dataset that employees had downloaded from the organization’s primary system and stored elsewhere for convenience. Because the data existed outside the controlled environment, it bypassed established security and privacy safeguards. Similar risks can arise from printed documents, customer-filled forms, photocopies, screenshots, spreadsheets, and downloaded reports.
Evaluate Controls in Practice
Organizations usually react to privacy requirements by enforcing technical and procedural controls, including encryption, access controls, and policies. While necessary, the controls’ effectiveness depends on how employees use them in practice. Beyond design, internal auditors should assess whether controls are followed consistently.
For example, sensitive data may be well-protected within a system, but that security can disappear when employees export that data to spreadsheets or share it informally. A control that employees routinely bypass offers little protection. These situations are common and highlight how employee behavior can create privacy risk.
The objective isn’t adding more controls — it’s making sure that important controls work in practice. Effective controls:
- Are well understood by users.
- Match operational needs.
- Are consistently applied throughout the data life cycle.
- Are monitored periodically.
Engage Business Units
Internal auditors should send the message that data privacy is not primarily the IT function’s responsibility. Although IT provides the infrastructure, business units typically define how they collect, use, and exchange data. Human resources handle employees’ data. Marketing teams deal with customer information. Operations works with vendor and transaction data. There are risks in each of these functions.
A good audit strategy includes engaging with business units. Understanding their processes, challenges, and objectives can help auditors identify risks that might not be apparent from a technical review.
Some of the biggest privacy concerns stem from manual processes, rather than technology failures. In one case I observed, employees shared sensitive data without appropriate data encryption or classification. These employees sent data using personal email accounts instead of the company’s email system. The organization solved the problem by providing data awareness training to staff.
Privacy Needs Accountability
Data privacy remains a vital point of discussion in organizations around the world. To internal auditors, it is a chance to add greater assurance and advice. Although technical policies and controls play a significant role, the true power of an audit is to learn how effectively the organization manages its data.
During one audit, a simple question about where data was stored helped the client understand its data ownership responsibility. This experience helped drive a crucial point: Clear responsibilities are the basis of effective privacy management.
Internal auditors who take a practical, curious, and holistic approach to data privacy will be better positioned to help their organizations. In this way, they not only help ensure robust controls are in place but also develop trust in a data-driven world.
The views and opinions expressed in this blog are those of the author and do not necessarily reflect the official policy or position of The Institute of Internal Auditors (The IIA). The IIA does not guarantee the accuracy or originality of the content, nor should it be considered professional advice or authoritative guidance. The content is provided for informational purposes only.