Ailance Alt TM Logo
Ailance Alt TM Logo

Auditor's right of inspection and data protection

Right of inspection of the auditor

Data protection regulations must be observed

When preparing the annual financial statements, auditors review a wide range of company documents. In doing so, they must also comply with data protection regulations.

In principle, the auditor has a right of inspection under Section 320(2), sentence 1, of the German Commercial Code (HGB). This provision states that the auditor may request from the legal representatives any information and supporting documentation necessary for a thorough audit. However, in nearly all company records, there are personal data Pursuant to Section 3(1) of the Federal Data Protection Act (BDSG), this applies not only to the company’s customers but also, in particular, to its employees.

Even though § 320(2), sentence 1, of the German Commercial Code (HGB) grants the auditor a very comprehensive right of inspection in accordance with commentaries on commercial law (e.g., Baumbach/Hopt, HGB, § 320), this right must nevertheless be assessed against the admissibility standards under data protection law.

Disclosure of Data to Auditors

Under data protection law, the transfer of company documents to auditors is considered Transmission to be classified as. This could be permissible Transmission be, if all employees are included in the Transmission have consented to being included on the lists. This will generally not be the case, so a legal basis for processing under data protection law must apply. Section 28(1), sentence 1, no. 2 of the BDSG may be applicable in this regard.

It is in the company’s legitimate interest to prepare accurate and legally compliant financial statements. In doing so, particular attention must be paid to the principle of necessity. There must be no less restrictive means by which the financial statements can be prepared with the same result.

For example, certain information can also be verified using anonymized statistical data. However, it must also be taken into account here that the auditor must of course be able to check the statistical data. Companies should note that Section 320 (2) sentence 1 HGB is not a special law that takes precedence over the BDSG, as it does not explicitly cover the Processing of personal data. However, this is absolutely necessary for the subsidiarity of the BDSG. Companies should consult with their data protection officer to determine which information is required for which purposes. In particular, the exact purposes of the requested data must be obtained from the auditors.

Comply with data protection principles

Under the current GDPR is the Transmission Regular disclosure of personal data to auditors pursuant to Article 6(1)(c) GDPR (Compliance with a legal obligation) or Art. 6(1)(f) GDPR (legitimate interest). At the same time, the principles of Data minimization, Earmarking and Confidentiality pursuant to Article 5 GDPR Please note: Companies should therefore determine which personal data is actually necessary for the specific audit and provide the auditor only with the information required to conduct the financial statement audit. Where possible, personal data may be provided in pseudonymized or aggregated form without compromising the auditability of the documents.

In addition, collaboration with auditors regarding the company’s data protection management should be documented. This includes, in particular, defining the respective roles under data protection law, which Documentation the legal basis for the data transfer, as well as the inclusion of audit activities in the record of processing activities. Since auditors are generally subject to a statutory duty of confidentiality, a high level of protection for the processed information already exists. Nevertheless, the company remains obligated to ensure compliance with data protection principles throughout the entire audit process.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

Auditor's right of inspection and data protection