{"id":43430,"date":"2026-03-05T08:30:44","date_gmt":"2026-03-05T06:30:44","guid":{"rendered":"https:\/\/2b-advice.com\/?p=43430"},"modified":"2026-06-22T16:08:44","modified_gmt":"2026-06-22T14:08:44","slug":"audit-preparation-in-data-protection","status":"publish","type":"post","link":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/","title":{"rendered":"Audit preparation in data protection"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"43430\" class=\"elementor elementor-43430\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6708f3e e-flex e-con-boxed e-con e-parent\" data-id=\"6708f3e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9a55182 elementor-author-box--align-left elementor-widget elementor-widget-author-box\" data-id=\"9a55182\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<a href=\"http:\/\/2b-advice.com\/en\/marcus-belke\/\" class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/2b-advice.com\/wp-content\/uploads\/2024\/04\/Marcus_B-300x300.png\" alt=\"Picture of Marcus Belke\" loading=\"lazy\">\n\t\t\t\t<\/a>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<a href=\"http:\/\/2b-advice.com\/en\/marcus-belke\/\">\n\t\t\t\t\t\t<h4 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\tMarcus Belke\t\t\t\t\t\t<\/h4>\n\t\t\t\t\t<\/a>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>CEO of 2B Advice GmbH, driving innovation in privacy compliance and risk management and leading the development of Ailance, the next-generation compliance platform.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-012dbf6 elementor-widget elementor-widget-text-editor\" data-id=\"012dbf6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Good audit preparation means more than just providing complete documentation. It requires clear responsibilities, structured evidence and transparent processes. Companies that establish these structures at an early stage avoid stress during the audit and strengthen their governance at the same time. In this article, you will learn how auditors think, what weaknesses often occur in data protection audits and how you can prepare for an audit in a structured way.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-95432c0 elementor-widget elementor-widget-heading\" data-id=\"95432c0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What auditors typically expect<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6f15672 elementor-widget elementor-widget-text-editor\" data-id=\"6f15672\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The auditing bodies (supervisory authority, internal audit, external auditor, client\/partner) may differ in tone, but rarely in the core statements. Auditors are looking for reliable answers to three key questions:<\/p><ol><li>Does the organization know its processing?<br \/>\u201eWhat do we process, why, for how long, with whom, where?\u201c (<a href=\"https:\/\/2b-advice.com\/en\/2025\/09\/30\/ropa-neu-gedacht-vom-pflicht-vvt-zum-maechtigen-management-tool\/\">VVT<\/a> as core evidence).<br \/><br \/><\/li><li>Are the protective measures selected in line with the risk and are they effective?<br \/>The TOMs are not just \u201eon paper\u201c, but have been implemented and checked in a comprehensible manner.<br \/><br \/><\/li><li>Are data subjects' rights and obligations operationalized? <br \/>Information\/deletion, incident management, information obligations, withdrawal of consent must be defined as real processes with deadlines and responsibilities.<br \/><br \/><\/li><\/ol><p>It is also crucial for supervisory authorities that controllers and processors cooperate upon request. The cooperation behavior can also be relevant for fines (reduction\/assessment criterion).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2815f8f elementor-widget elementor-widget-heading\" data-id=\"2815f8f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Test methods that you should realistically plan for<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d328af2 elementor-widget elementor-widget-text-editor\" data-id=\"d328af2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In practice, a mixture of document reviews, structured questionnaires, interviews and spot checks are used. The fact that supervisory authorities can carry out data protection reviews and request information, among other things, is enshrined in the legal framework of powers.<\/p><p>The BayLDA questionnaire, for example, provides a very \u201eaudit-related\u201c perspective: it explicitly asks about data protection governance, the involvement of the data protection officer, VVT, privacy by design, processors\/contracts, information obligations, data subject rights, proof of consent and data protection management. This is practically a catalog of expectations.<\/p><table width=\"900\"><tbody><tr><td><p><strong>Test methodology<\/strong><\/p><\/td><td><p><strong>How inspectors recognize maturity<\/strong><\/p><\/td><td><p><strong>Typical evidence<\/strong><\/p><\/td><\/tr><tr><td><p>Document review (\u201eDesk\u00a0<a href=\"https:\/\/2b-advice.com\/en\/glossary\/audit\/\">Audit<\/a>\u201c)<\/p><\/td><td><p>Consistency: VVT \u2194 TOM \u2194 DSFA \u2194 Contracts \u2194 Deletion periods \u2194\u00a0<a href=\"https:\/\/2b-advice.com\/en\/glossary\/information-obligations\/\">Duty to inform<\/a><\/p><\/td><td><p>VVT, TOM concept\/mapping, AV contracts,\u00a0<a href=\"https:\/\/2b-advice.com\/en\/glossary\/deletion-concept\/\">Deletion concept<\/a>, DPIA\/risk analysis, proof of consent<\/p><\/td><\/tr><tr><td><p>Questionnaire (official\/partner audit)<\/p><\/td><td><p>Ability to respond without \u201ead hoc invention\u201c; clear responsibilities<\/p><\/td><td><p>Completed questionnaires, verification index per question (voucher link)<\/p><\/td><\/tr><tr><td><p>Interviews\/workshop discussions<\/p><\/td><td><p>Employees know the process, escalation, deadlines; no contradictory statements<\/p><\/td><td><p>Role matrix, training certificates, process manuals, ticket\/workflow examples<\/p><\/td><\/tr><tr><td><p>Samples\/Walk-through<\/p><\/td><td><p>\u201eShow me\u201c: Information,\u00a0<a href=\"https:\/\/2b-advice.com\/en\/glossary\/deletion\/\">Deletion<\/a>, Authorization, incident response actually feasible<\/p><\/td><td><p>1-3 case files per process (DSAR tickets, deletion runs, authorization review, incident runbook)<\/p><\/td><\/tr><tr><td><p>Technical evidence (demos\/logs)<\/p><\/td><td><p>Effectiveness and traceability (e.g. roles\/rights, 2FA, backup tests)<\/p><\/td><td><p>Authorization concepts, protocols, backup test protocols, MFA rollout proofs\u00a0<\/p><\/td><\/tr><\/tbody><\/table><p>Link tip:\u00a0<a href=\"https:\/\/www.lda.bayern.de\/media\/dsgvo_fragebogen.pdf\">GDPR questionnaire LDA Bavaria<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9df5d27 elementor-widget elementor-widget-heading\" data-id=\"9df5d27\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Typical test questions and assessment criteria<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ba965ca elementor-widget elementor-widget-text-editor\" data-id=\"ba965ca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The following examples are formulated in such a way that they are suitable for both authority and customer\/certification audits. They reflect typical questions from authorities (e.g. BayLDA questionnaire) and the DSK system (VVT\/DSFA\/rights of data subjects).<\/p><table style=\"border-collapse: collapse;width: 100%\" border=\"1\"><thead><tr><th><strong>Theme block<\/strong><\/th><th>Typical test question<\/th><th><strong>Assessment criterion (what \u201egood\u201c means)<\/strong><\/th><th><strong>Typical evidence<\/strong><\/th><\/tr><\/thead><tbody><tr><td style=\"text-align: left\">Governance<\/td><td style=\"text-align: left\">\u201eIs <a href=\"https:\/\/2b-advice.com\/en\/marcus-belke\/\">Data protection<\/a> A matter for the boss, are responsibilities regulated?\u201c<\/td><td style=\"text-align: left\">Responsibilities are documented and effective in everyday life<\/td><td style=\"text-align: left\">Data protection guideline, roles\/RACI, DPO integration concept<\/td><\/tr><tr><td style=\"text-align: left\">Processing transparency<\/td><td style=\"text-align: left\">\u201eIs there a VVT, is it complete and up-to-date?\u201c<\/td><td style=\"text-align: left\">VVT covers real processing operations, incl. recipients, deletion periods, TOM description<\/td><td style=\"text-align: left\">VVT + change process\/review protocol<\/td><\/tr><tr><td style=\"text-align: left\">Order processing<\/td><td style=\"text-align: left\">\u201eHave all processors been recorded and are DP contracts Art. 28 concluded?\u201c<\/td><td style=\"text-align: left\">Complete vendor list; AV contracts with minimum content; control mechanism<\/td><td style=\"text-align: left\">Vendor register, AV contracts, TOM audit Service provider\u00a0<\/td><\/tr><tr><td style=\"text-align: left\">Rights of data subjects<\/td><td style=\"text-align: left\">\u201eCan you provide information within the deadline?\u201c<\/td><td style=\"text-align: left\">Process &amp; organization ensure timely, comprehensible information<\/td><td style=\"text-align: left\">DSAR process, sample answers, ticket examples\u00a0<\/td><\/tr><tr><td style=\"text-align: left\">Deletion<\/td><td style=\"text-align: left\">\u201eHow do you ensure deletion periods for each type of data?\u201c<\/td><td style=\"text-align: left\">Data deletion concept per data type; justified deadlines; documented deletion runs<\/td><td style=\"text-align: left\">Deletion concept, deletion logs, exception\/blocking rules\u00a0<\/td><\/tr><tr><td style=\"text-align: left\">Risk\/DSFA<\/td><td style=\"text-align: left\">\u201eFor which processes do you carry out a DPIA?\u201c<\/td><td style=\"text-align: left\">DPIA before start; decision per process documented; measures derived<\/td><td style=\"text-align: left\">DSFA reports, threshold value analysis, action plan<\/td><\/tr><tr><td style=\"text-align: left\">Consents<\/td><td style=\"text-align: left\">\u201eCan you prove consent and enable revocation?\u201c<\/td><td style=\"text-align: left\">Verifiability, information, revocation mechanism<\/td><td style=\"text-align: left\">Consent register, UI screenshots, logs\u00a0<\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-75376b7 elementor-widget elementor-widget-heading\" data-id=\"75376b7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Frequent weaknesses in audits<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d615ebb elementor-widget elementor-widget-text-editor\" data-id=\"d615ebb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The following weaknesses are not \u201etheoretical errors\u201c, but typical gaps between paper compliance and everyday life. The examples are deliberately based on official audit questions and good practice catalogs (e.g. TOM checklists), as auditors ask questions precisely where implementation is often incomplete.<\/p><h5>Technical defects<\/h5><p>A frequent audit finding is not \u201eno TOM\u201c, but TOM without reference to effectiveness: although there is a PDF with keywords, there is no reliable evidence that measures have been implemented, tested and selected in line with the risks. Although the benchmark \u201eregularly review\/assess\u201c is explicitly addressed, it is practically impossible to fulfill without a concrete description.<\/p><p>Concrete, often criticized technical examples:<\/p><ul><li>Weak authentication: no (or inconsistent) 2FA use in high-risk areas, lack of lockouts on failed attempts, passwords are shared\/written down, inadequate admin password standards.<\/li><li>Immature role\/rights concept: lack of role profiles, no regular checks, \u201efunction mailboxes\u201c and collective accounts without accountability.<\/li><li>Backup\/recovery as a blind spot: no written backup concept, no restore tests, no 3-2-1 strategy, backups potentially encrypted by ransomware, missing or untested contingency plan.<\/li><li>Mobile\/remote risks: lack of full device encryption, lack of MDM, insecure app sources, no clear loss chain.<\/li><\/ul><h5><br \/>Organizational deficiencies<\/h5><p>Here, organizations often fail because of responsibilities and control, not because of legal knowledge.<\/p><ul><li style=\"list-style-type: none\"><ul><li>The DPO\/data protection function is integrated too late. Projects start and systems go live while data protection is \u201edragged on\u201c. However, this clashes with the expectation that data protection issues should be taken into account right from the start or when processes are changed (privacy by design in the audit question logic).<\/li><li>There is no robust data protection management, only individual measures that are not brought together in a system that structures implementation, verification and updating. It is precisely this ability to \u201eensure and provide evidence\u201c (risk-based) that is at the heart of the accountability logic.<\/li><li>Service provider control is formal, but not in terms of content: AV contracts exist, but there is no complete service provider overview, no transparency about sub-processors and no recurring review of technical and organizational measures. Auditors ask precisely about \u201eoverview\u201c and \u201eminimum content Art. 28\u201c.<\/li><\/ul><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-20fccd5 elementor-widget elementor-widget-heading\" data-id=\"20fccd5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Audit Organization: No Stress!<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0d5496a elementor-widget elementor-widget-text-editor\" data-id=\"0d5496a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Audit stress is rarely caused by individual questions, but mostly by disorganized searches, contradictory statements and unclear allocation of roles. Avoiding stress is therefore first and foremost a question of organization.<\/p><h5>Before the audit<\/h5><p>Evidence mapping is an effective lever: each test requirement is given clear evidence in advance (\u201esingle source of truth\u201c) and a responsible role. This avoids hectic compilation during the audit.<\/p><p>As a minimum standard, you should ensure the following before the appointment:<\/p><ul><li>Single Point of Contact (SPoC) for inspector communication (prevents parallel chats and divergent statements).<\/li><li>Clarification of roles: who answers \u201ePolicy\u201c, who answers \u201eIT detail\u201c, who answers \u201eHR processes\u201c, who answers \u201eLegal\/Contracts\u201c.<\/li><li>Carry out a mock audit with five to ten core questions (VVT, DSAR, deletion, AV, TOM, DSFA) as a dry run.<\/li><\/ul><p><br \/>The fact that cooperation and a structured approach are not just \u201esoft skills\u201c is demonstrated by the fact that cooperative behavior can be taken into account in supervisory measures and the assessment of fines.<\/p><h5>During the audit<\/h5><p>The tried and tested communication rule is: \u201eAnswer + evidence + context\u201c.<\/p><ul><li>The answer should be brief, factual and verifiable.<\/li><li>The document must be immediately linkable in the audit folder (not \u201esubmit to someone\u201c as the default mode).<\/li><li>Context: Delimitation if the scope does not apply (e.g. \u201eonly applies to system X, not to Y\u201c).<\/li><\/ul><p><br \/>For contacts with authorities, it is also important that controllers and processors cooperate upon request.<\/p><h5>After the audit<\/h5><p>The follow-up phase determines whether the audit will be \u201eexpensive\u201c:<\/p><ul><li>Findings triage (high\/medium\/low) according to risk for data subjects and probability of occurrence; content consistent with risk-based requirements and DPIA logic.<\/li><li>An action plan is drawn up with a responsible person, deadline and form of verification. The DSK expressly recommends a coordinated approach and informing the management as a starting point for implementation projects.<\/li><li>Closure evidence: Each measure does not end with \u201eimplemented\u201c, but with \u201edemonstrably implemented\u201c (e.g. screenshot, log, test report).<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fcec3a3 elementor-widget elementor-widget-heading\" data-id=\"fcec3a3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Audit check at a glance<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cb4f850 elementor-widget elementor-widget-text-editor\" data-id=\"cb4f850\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\u00a0<\/p><table width=\"663\"><thead><tr><td><p><strong>Checkpoints<\/strong><\/p><\/td><td><p><strong>Responsible role<\/strong><\/p><\/td><td><p><strong>Form of proof<\/strong><\/p><\/td><td><p><strong>Priority<\/strong><\/p><\/td><\/tr><\/thead><tbody><tr><td><p>Audit scope, systems, locations, period defined<\/p><\/td><td><p>Management \/ Data protection coordination<\/p><\/td><td><p>Audit readme + scope document<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>Single Point of Contact (SPoC) + communication rules defined<\/p><\/td><td><p>Data protection coordination<\/p><\/td><td><p>Role sheet + communication plan<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>Data protection roles\/RACI incl. DPO involvement clear<\/p><\/td><td><p>Management \/ DPO<\/p><\/td><td><p>RACI, organization chart, integration process<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>VVT complete, up-to-date, versioned<\/p><\/td><td><p>Process owners + DPO<\/p><\/td><td><p>Master VVT + change log<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>VVT contains deletion periods\/criteria per data category<\/p><\/td><td><p>Process owner<\/p><\/td><td><p>VVT fields + references to the deletion concept<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>VVT contains TOM references \/ general TOM description<\/p><\/td><td><p>IT security + DPO<\/p><\/td><td><p>VVT entry + TOM document link<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>TOM verification: risk\u2192measure mapping available<\/p><\/td><td><p>IT security + DPO<\/p><\/td><td><p>TOM matrix\/mapping<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>Authentication: Password policy + 2FA for high risk<\/p><\/td><td><p>IT security<\/p><\/td><td><p>Policy + system settings\/reports<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Roles\/rights concept documented and checked<\/p><\/td><td><p>IT Security \/ IT Ops<\/p><\/td><td><p>Role model + review protocol<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Written backup concept + restore tests<\/p><\/td><td><p>IT Ops \/ BCM<\/p><\/td><td><p>Backup concept + test protocols<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Emergency\/BCM plan in place and practiced<\/p><\/td><td><p>BCM \/ IT Ops<\/p><\/td><td><p>Emergency plan + exercise protocols<\/p><\/td><td><p>Medium\u00a0<\/p><\/td><\/tr><tr><td><p>Vendor register complete (all processors)<\/p><\/td><td><p>Purchasing\/Vendor Mgmt + DSB<\/p><\/td><td><p>Service provider list<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>AV contracts with minimum content (Art. 28) for all AVs<\/p><\/td><td><p>Legal + DPO<\/p><\/td><td><p>AV contracts + annex<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Subprocessor transparency + release process<\/p><\/td><td><p>Vendor Mgmt + Legal<\/p><\/td><td><p>Subprocessor list + releases<\/p><\/td><td><p>Medium<\/p><\/td><\/tr><tr><td><p>Mandatory information texts (Art. 13\/14) per core process<\/p><\/td><td><p>Legal\/Marketing + DPO<\/p><\/td><td><p>Data protection information + versioning<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>DSAR process (Intake, Ident, Data search, Response)<\/p><\/td><td><p>Customer Service \/ DPO<\/p><\/td><td><p>Process description + ticket examples<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Information deadlines\/monitoring of deadlines operationalized<\/p><\/td><td><p>DPO \/ Departments<\/p><\/td><td><p>Deadline SLA + workflow<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Deletion concept for each type of data (purpose, duration, requirements)<\/p><\/td><td><p>Records Mgmt \/ DSB<\/p><\/td><td><p>Extinguishing concept<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Deletion runs verifiable (logs\/reports)<\/p><\/td><td><p>IT Ops \/ specialist departments<\/p><\/td><td><p>Deletion logs<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>Procedure for deletion requests in accordance with Art. 17<\/p><\/td><td><p>DPO \/ Service<\/p><\/td><td><p>Process + case file<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Threshold analysis: DSFA yes\/no per high-risk process<\/p><\/td><td><p>DPO + process owner<\/p><\/td><td><p>Threshold analysis document<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>DSFA carried out before commissioning (where required)<\/p><\/td><td><p>DPO + project management<\/p><\/td><td><p>DSFA report + action plan<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Proof of consent + revocation mechanism<\/p><\/td><td><p>Marketing\/Product + DPO<\/p><\/td><td><p>Consent register + logs\/UI proofs<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><tr><td><p>Training\/sensitization (phishing, data transfer)<\/p><\/td><td><p>HR + IT security<\/p><\/td><td><p>Training plan + attendance records<\/p><\/td><td><p>Medium\u00a0<\/p><\/td><\/tr><tr><td><p>Request log for the audit (questions, answers, documents, deadlines)<\/p><\/td><td><p>Audit SPoC<\/p><\/td><td><p>Audit log (e.g. table\/ticket)<\/p><\/td><td><p>High<\/p><\/td><\/tr><tr><td><p>Action plan after audit (owner, deadline, document)<\/p><\/td><td><p>Management \/ DPO<\/p><\/td><td><p>Action plan + proof of closure<\/p><\/td><td><p>High\u00a0<\/p><\/td><\/tr><\/tbody><\/table><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f54ad5d elementor-widget elementor-widget-heading\" data-id=\"f54ad5d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Audit-ready with 2B Advice and Ailance<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-de2965e elementor-widget elementor-widget-text-editor\" data-id=\"de2965e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Audit capability does not only arise when an audit is announced. It is the result of clear structures, transparent processes and comprehensible evidence in data protection.<\/p><p>Companies that organize data protection strategically benefit twice over: they pass audits more confidently and at the same time strengthen their governance and the trust of customers and partners.<\/p><p>If you want to know how well your company is prepared for a data protection audit, it is worth taking a structured look at your own processes.<\/p><p>Find out more about our solutions for data protection and compliance management with Ailance and get in touch with our experts.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-dacd2ef e-con-full e-flex e-con e-child\" data-id=\"dacd2ef\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-c681a67 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"c681a67\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f30abe0 elementor-widget elementor-widget-text-editor\" data-id=\"f30abe0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><i>Marcus Belke is CEO of 2B Advice as well as a lawyer and IT expert for data protection and digital compliance. He regularly writes about AI governance, GDPR compliance and risk management. You can find out more about him on his <\/i><a id=\"menur29hm\" class=\"fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn\" title=\"https:\/\/2b-advice.com\/en\/marcus-belke\/\" href=\"https:\/\/2b-advice.com\/en\/marcus-belke\/\" rel=\"noreferrer noopener\" aria-label=\"Link author profile page\"><i><strong>Author profile page<\/strong><\/i><\/a><i>.<\/i><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Good audit preparation requires clear responsibilities, structured evidence and transparent processes. Find out how auditors think, which weaknesses frequently occur in data protection audits and how you can prepare for an audit in a structured way.<\/p>","protected":false},"author":2,"featured_media":43439,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[440,13],"tags":[487,356,45,48,109,167],"class_list":["post-43430","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-marcus-belke","category-datenschutz-unternehmen","tag-audit-check","tag-datenminimierung-dsgvo","tag-datenschutz-unternehmen","tag-datenschutz-grundverordnung-dsgvo","tag-dsgvo-bussgelder","tag-dsgvo-verstoss"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Audit-Vorbereitung im Datenschutz - Ailance<\/title>\n<meta name=\"description\" content=\"Eine Audit im Datenschutz erfordert klare Verantwortlichkeiten, strukturierte Nachweise und transparente Prozesse.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-preparation-in-data-protection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Audit-Vorbereitung im Datenschutz - Ailance\" \/>\n<meta property=\"og:description\" content=\"Eine Audit im Datenschutz erfordert klare Verantwortlichkeiten, strukturierte Nachweise und transparente Prozesse.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-preparation-in-data-protection\/\" \/>\n<meta property=\"og:site_name\" content=\"Ailance\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-05T06:30:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-22T14:08:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/03\/Audit-im-Datenschutz.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Aristotelis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Aristotelis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/\"},\"author\":{\"name\":\"Aristotelis\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#\\\/schema\\\/person\\\/dec1524f23a48487067598ae938bc8eb\"},\"headline\":\"Audit-Vorbereitung im Datenschutz\",\"datePublished\":\"2026-03-05T06:30:44+00:00\",\"dateModified\":\"2026-06-22T14:08:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/\"},\"wordCount\":1733,\"publisher\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/Audit-im-Datenschutz.jpg\",\"keywords\":[\"Audit-Check\",\"Datenminimierung\",\"Datenschutz\",\"Datenschutz-Grundverordnung DSGVO\",\"DSGVO-Bu\u00dfgelder\",\"DSGVO-Versto\u00df\"],\"articleSection\":[\"Artikel von Marcus Belke\",\"Datenschutz\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/\",\"name\":\"Audit-Vorbereitung im Datenschutz - Ailance\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/Audit-im-Datenschutz.jpg\",\"datePublished\":\"2026-03-05T06:30:44+00:00\",\"dateModified\":\"2026-06-22T14:08:44+00:00\",\"description\":\"Eine Audit im Datenschutz erfordert klare Verantwortlichkeiten, strukturierte Nachweise und transparente Prozesse.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/#primaryimage\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/Audit-im-Datenschutz.jpg\",\"contentUrl\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/Audit-im-Datenschutz.jpg\",\"width\":1536,\"height\":1024,\"caption\":\"Audit im Datenschutz\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/2026\\\/03\\\/05\\\/audit-vorbereitung-im-datenschutz\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/2b-advice.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Audit-Vorbereitung im Datenschutz\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/\",\"name\":\"2B Advice\",\"description\":\"By 2B Advice\",\"publisher\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#organization\",\"name\":\"2B Advice GmbH\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/Ailance_Logo_Yellow_White_large_RGB.png\",\"contentUrl\":\"https:\\\/\\\/2b-advice.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/Ailance_Logo_Yellow_White_large_RGB.png\",\"width\":287,\"height\":401,\"caption\":\"2B Advice GmbH\"},\"image\":{\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/2b-advice-group\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/2b-advice.com\\\/en\\\/#\\\/schema\\\/person\\\/dec1524f23a48487067598ae938bc8eb\",\"name\":\"Aristotelis\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Audit preparation in data protection - Ailance","description":"A data protection audit requires clear responsibilities, structured evidence and transparent processes.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-preparation-in-data-protection\/","og_locale":"en_US","og_type":"article","og_title":"Audit-Vorbereitung im Datenschutz - Ailance","og_description":"Eine Audit im Datenschutz erfordert klare Verantwortlichkeiten, strukturierte Nachweise und transparente Prozesse.","og_url":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-preparation-in-data-protection\/","og_site_name":"Ailance","article_published_time":"2026-03-05T06:30:44+00:00","article_modified_time":"2026-06-22T14:08:44+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/03\/Audit-im-Datenschutz.jpg","type":"image\/jpeg"}],"author":"Aristotelis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Aristotelis","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/#article","isPartOf":{"@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/"},"author":{"name":"Aristotelis","@id":"https:\/\/2b-advice.com\/en\/#\/schema\/person\/dec1524f23a48487067598ae938bc8eb"},"headline":"Audit-Vorbereitung im Datenschutz","datePublished":"2026-03-05T06:30:44+00:00","dateModified":"2026-06-22T14:08:44+00:00","mainEntityOfPage":{"@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/"},"wordCount":1733,"publisher":{"@id":"https:\/\/2b-advice.com\/en\/#organization"},"image":{"@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/#primaryimage"},"thumbnailUrl":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/03\/Audit-im-Datenschutz.jpg","keywords":["Audit-Check","Datenminimierung","Datenschutz","Datenschutz-Grundverordnung DSGVO","DSGVO-Bu\u00dfgelder","DSGVO-Versto\u00df"],"articleSection":["Artikel von Marcus Belke","Datenschutz"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/","url":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/","name":"Audit preparation in data protection - Ailance","isPartOf":{"@id":"https:\/\/2b-advice.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/#primaryimage"},"image":{"@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/#primaryimage"},"thumbnailUrl":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/03\/Audit-im-Datenschutz.jpg","datePublished":"2026-03-05T06:30:44+00:00","dateModified":"2026-06-22T14:08:44+00:00","description":"A data protection audit requires clear responsibilities, structured evidence and transparent processes.","breadcrumb":{"@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/#primaryimage","url":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/03\/Audit-im-Datenschutz.jpg","contentUrl":"https:\/\/2b-advice.com\/wp-content\/uploads\/2026\/03\/Audit-im-Datenschutz.jpg","width":1536,"height":1024,"caption":"Audit im Datenschutz"},{"@type":"BreadcrumbList","@id":"https:\/\/2b-advice.com\/en\/2026\/03\/05\/audit-vorbereitung-im-datenschutz\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/2b-advice.com\/de\/"},{"@type":"ListItem","position":2,"name":"Audit-Vorbereitung im Datenschutz"}]},{"@type":"WebSite","@id":"https:\/\/2b-advice.com\/en\/#website","url":"https:\/\/2b-advice.com\/en\/","name":"2B Advice","description":"By 2B Advice","publisher":{"@id":"https:\/\/2b-advice.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/2b-advice.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/2b-advice.com\/en\/#organization","name":"2B Advice GmbH","url":"https:\/\/2b-advice.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/2b-advice.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/2b-advice.com\/wp-content\/uploads\/2024\/02\/Ailance_Logo_Yellow_White_large_RGB.png","contentUrl":"https:\/\/2b-advice.com\/wp-content\/uploads\/2024\/02\/Ailance_Logo_Yellow_White_large_RGB.png","width":287,"height":401,"caption":"2B Advice GmbH"},"image":{"@id":"https:\/\/2b-advice.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/2b-advice-group\/"]},{"@type":"Person","@id":"https:\/\/2b-advice.com\/en\/#\/schema\/person\/dec1524f23a48487067598ae938bc8eb","name":"Aristotle"}]}},"_links":{"self":[{"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/posts\/43430","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/comments?post=43430"}],"version-history":[{"count":26,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/posts\/43430\/revisions"}],"predecessor-version":[{"id":44979,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/posts\/43430\/revisions\/44979"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/media\/43439"}],"wp:attachment":[{"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/media?parent=43430"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/categories?post=43430"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/2b-advice.com\/en\/wp-json\/wp\/v2\/tags?post=43430"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}