IT Governance and Compliance

    Implementing data protection technically

    By Redaktion techport.ai, IT-Beratung · Last updated on

    In many companies data protection is treated as a paper topic: there is a record, there are contracts and there is a privacy notice. The technical side lags behind, and that is exactly where it is decided whether the implementation holds. Whether permissions follow the principle of necessity, whether deletion periods actually take effect, whether log data is limited, and whether in the event of a breach you know within seventy-two hours what happened.

    We do not provide legal advice. We make sure the requirements of your data protection advisers are implemented technically and can be demonstrated.

    How you notice it

    • The record of processing activities is years old and does not cover new systems.
    • There is no automatic deletion, data stays indefinitely.
    • Responding to an access request takes weeks to assemble.
    • New cloud services are used without contracts and transfer bases being checked.

    Why this happens

    The documentary obligations are visible and therefore get done. Technical implementation is invisible and expensive: deletion concepts require changes to systems, access concepts require alignment with departments, and log data accumulates automatically without anyone ordering it. As long as nothing happens, the gap between paper and technology goes unnoticed. It becomes noticeable with an access request, a complaint or an incident, which is exactly when there is no time.

    How we go about it

    1. Reconcile processing activities with systems. We reconcile the record of processing activities with the systems and services actually in use and add what is missing. Frequently these are departmental tools and features that arrived with an update.
    2. Implement and describe technical measures. We implement the measures under Article 32 GDPR and describe them so they can be reviewed: access control, encryption, separation, logging, restorability and regular verification.
    3. Make deletion possible. We produce a deletion concept setting periods per data type, resolve the conflict with retention obligations, and implement it technically where the data volume justifies it. That includes backups, archives and log data.
    4. Prepare for incidents. We set up a procedure for data breaches, with detection, assessment, notification within the deadline and documentation. The most common failure is not the breach but late detection.

    What you gain

    • An implementation that can be evidenced in an audit rather than merely asserted.
    • Access and deletion requests handled in days rather than weeks.
    • Less risk from systems nobody has reviewed.

    From our projects

    Log data is the most frequently overlooked area. Systems log sign-ins, access and changes, often for years, and nobody ever set a deletion period. That data is personal, it can be analysed, and in case of doubt it is subject to codetermination. We therefore review it early and set periods. The second recurring finding concerns test environments: in many companies they contain a copy of production data, with wider permissions and weaker protection. That is one of the easiest routes to a reportable incident and can be avoided with anonymised or synthetic data.

    Good to know

    Four points are central. Article 30 GDPR requires the record of processing activities, which has to be kept current. Article 32 requires technical and organisational measures appropriate to the risk, explicitly including a procedure for regularly reviewing their effectiveness. Article 28 requires a processor agreement for every service provider processing personal data on your behalf. Article 35 requires a data protection impact assessment for processing likely to result in a high risk, which can apply to comprehensive monitoring systems, biometric procedures and certain AI applications. For employee data, the legal basis in Germany has to be examined carefully following the Court of Justice ruling on a state law provision equivalent to Section 26 BDSG.

    Häufige Fragen

    May we use US providers?

    Yes, if there is a valid basis for the transfer and the risks have been assessed. Check in each case the provider's certification under the applicable adequacy decision, the contractual commitments and the question of which data is actually transferred. That assessment belongs documented, because it will be requested in case of doubt. The legal assessment in the individual case belongs with your data protection advisers.

    How do we handle a data breach?

    Detect, assess, report, document. Notification to the supervisory authority has to be made without undue delay and where feasible within seventy-two hours of becoming aware, where there is a risk to the individuals concerned. What matters is that the procedure exists beforehand: who assesses, who reports, which information is needed. Clarifying those questions during an incident consumes exactly the time the deadline allows.

    Let us talk about Implementing data protection technically

    In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

    Further reading

    Back to the field IT Governance and Compliance

    Sources