Turn every gap into a prioritised next step, so operational teams know what to address first and how to move forward.
Follow a structured process
The checks and sequence are already defined. Your team can focus on execution instead of designing the audit as they go.
Ensure compliance with every obligation
Review the GDPR requirements condition by condition, reducing the risk that an important obligation is overlooked.
Demonstrate accountability
Keep evidence with each conclusion to help demonstrate compliance under Articles 5(2) and 24.
GDPR audit · standard · loyalty programme · retention
Art. 5(1)(e) — how long the data is kept, and why
CompliantNon-compliantIn progressN/A
The condition
Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
Art. 5(1)(e) GDPR · fixed wording, the same on every audit
What it means
Name a period for every category of data, tie it to the reason you hold it, and actually delete when it runs out. “As long as necessary” is not a period.
Checkpoints3 / 3
A retention period is set for each category of data
Deletion or anonymisation actually runs when it expires
The period appears in the information notice — Art. 13(2)(a)
Evidence in scope2 items · this check
PDF
Retention policy v4 — loyalty.pdfThree years from the last purchase. Approved 12 Feb 2026.
820 KBReady
CSV
Deletion log — July 2026.csv4,182 records purged at 36 months. Runs monthly.
96 KBReady
Review trail · 2 entries · confirmed by M. Laurent, 14 Aug 2026Illustrative
Most companies are not unwilling to comply — they simply do not know what to do. The audit answers both questions at once: a proven status on every legal condition, so you know exactly how compliant you are, and the gap turned into a concrete list of things to do. Legiscope does the first pass — every answer proposed with its reason, every conclusion signed by a person.
Day one
Hours debating consent. Still no audit.
Teams spend hours searching forums and debating consent, even though it is often not the first issue to address. Retention, deletion, transparency and other obligations remain unchecked because there is no structured process.
With LegiscopeWork through every applicable obligation in a defined order. Add the evidence, identify the gaps and know what to address first.
The deliverable
“Broadly compliant — 78%.”
A percentage averages away exactly what a regulator asks about: which conditions failed, on which activities, on what evidence. An impression, not a record.
With LegiscopeAn exact status on every condition, and the document that proves it attached to the check it answers — Art. 5(2).
Six months later
The audit was true in March.
A vendor was added, a retention period changed — the report heard about neither. Nobody re-audits from zero, so the snapshot quietly expires.
With LegiscopeWhen a field moves, only the conclusions it touched reopen. The rest keep their date and their reviewer.
Your next audit
Make compliance operational.
See how Legiscope turns obligations, evidence and gaps into a process your team can execute.