Menu

Filter by
content
PONT Data&Privacy

0

Wpg audit roadmap

Autoriteit Persoonsgegevens October 29, 2025

Published

For whom
All organizations that process police data (including municipalities and employers of boas) are required by law to conduct periodic Wpg audits.

Step 1: Annual internal audit

  • Conduct an internal privacy audit every year.
  • Review processes, measures and procedures around police data.
  • Use the NOREA handbook as a guide.

Step 2: Four-year external audit

  • Have an external, independent auditor conduct an audit at least once every four years.
  • External auditor may not be the Data Protection Officer (FG).
  • Ensure that the auditor is knowledgeable and independent

Step 3: Reporting and delivery

  • Prepare a "short-form" audit report.
  • Submit the report digitally to the Autoriteit Persoonsgegevens (AP) between March 1, 2025 and March 1, 2026.
  • Remove personal names; preferably deliver the report in PDF/A format.

Step 4: Improvement plan and recheck (if necessary)

  • Does the audit reveal that your organization is not compliant? Establish an improvement plan within a year.
  • Have rechecking done by an independent party.
  • Send the re-audit report to the AP - the improvement plan itself need not be reported.

Step 5: Assurance and collaboration

  • Always keep a copy of submitted reports in your own records.
  • Take responsibility when lending/hiring boas or collaborating with other organizations.

Share article

Comments

Leave a comment

You must be logged in to post a comment.