How We Achieved a Positive Result for the First GDPR Audit. Our Project for VGP

Adapting a project to the requirements of GDPR-related regulations is a challenge faced by many IT system providers. This only makes us prouder that our product has received a positive recommendation following an audit.

Read this article to find out:

  • what the audit looked at;
  • what was the purpose of the audit;
  • what good practices we used to achieve such good results.

The audit concerned information security and was carried out on the basis of the rights of the Personal Data Controller under the GDPR by consulting company KPMG for Volkswagen Group Polska.

A one-day meeting with the auditor covered the verification of documentation, information management procedures, and the practical implementation of all key principles. The auditor was given access to all documentation and the possibility of interviews with selected staff members participating in the project.

Audit Purpose and Result

The process was designed to check if data processing complies with the GDPR and the contractual requirements imposed by VGP on all suppliers.

The auditor had no concerns about the organization of work on the project or the quality of information security management by Unity Group. We obtained recommendations to confirm the high standard of information security with the formal ISO 27001 certificate.

This means that our formal solutions meet the stringent standards that must be satisfied to apply for this certificate

How to Achieve a Positive Outcome of the GDPR Audit

Over a year and a half, as part of the project of preparing the company for the GDPR, we introduced a number of organizational and formal changes to raise the standards of information security. In cooperation with an external consulting company, we inventoried in-house processes and developed documentation and proposals for solutions in accordance with the ISO 27001 standard. We appointed a Data Protection Officer, who ensures that the quality of information security management is maintained at all times.

For our clients, this means that Unity Group can be fully trusted in matters as sensitive as personal data. We are well aware of the importance of the regulations, and we strictly follow them. We are a reliable partner not only in the IT aspect of a project but also in everything that makes up its business environment.

— Anna Gubernat, Project Manager

Read More
/ Recent News


Artificial Intelligence needs to be fed with data

Our Digital Transformation Strategist, Maciej Pondel, was interviewed on the wide range of AI technology available and how businesses can best navigate the growing – and increasingly diverse – market.


Commerce transformation in the era of rapid change: Commerce Transformation Days coming in September 2022 

Commerce Transformation Days (CTD) is an international conference fully dedicated to digital commerce transformation. On September 22 and 23, 2022, the 7th edition of this annual event, previously known as the E-commerce Directors Congress, will take place at the Concordia Design business center in Wrocław. After two years of restricted event activity, the conference organized by Unity Group returns with…


1/3 of refugees from Ukraine want to stay in Poland

The input from business has been invaluable. - It is now clear that we still have months, if not years, of this emergency ahead of us. Therefore we have to start helping in a different way. Now is the time for long-term systemic actions - emphasises Grzegorz Rudno-Rudziński, managing partner of Unity Group

We’re ready.
Are You?

Our solutions make the headlines. Get in touch and let's start the next story together.

Contact us