# Data protection in IT: technical measures, contracts, deletion concept and evidence

> GDPR put into practice: technical and organisational measures, processor agreements, records, deletion concept, log data, third country transfers and handling data breaches.

URL: https://techport.ai/en/it-beratung/it-governance-und-recht/datenschutz-in-der-it

---

1.  [IT Consulting](/en/it-beratung)/
2.  [IT Governance and Compliance](/en/it-beratung/it-governance-und-recht)/
3.  Implementing data protection technically

[IT Governance and Compliance](/en/it-beratung/it-governance-und-recht)

# Implementing data protection technically

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

In many companies data protection is treated as a paper topic: there is a record, there are contracts and there is a privacy notice. The technical side lags behind, and that is exactly where it is decided whether the implementation holds. Whether permissions follow the principle of necessity, whether deletion periods actually take effect, whether log data is limited, and whether in the event of a breach you know within seventy-two hours what happened.

We do not provide legal advice. We make sure the requirements of your data protection advisers are implemented technically and can be demonstrated.

## How you notice it

*   The record of processing activities is years old and does not cover new systems.
*   There is no automatic deletion, data stays indefinitely.
*   Responding to an access request takes weeks to assemble.
*   New cloud services are used without contracts and transfer bases being checked.

## Why this happens

The documentary obligations are visible and therefore get done. Technical implementation is invisible and expensive: deletion concepts require changes to systems, access concepts require alignment with departments, and log data accumulates automatically without anyone ordering it. As long as nothing happens, the gap between paper and technology goes unnoticed. It becomes noticeable with an access request, a complaint or an incident, which is exactly when there is no time.

## How we go about it

1.  **Reconcile processing activities with systems.** We reconcile the record of processing activities with the systems and services actually in use and add what is missing. Frequently these are departmental tools and features that arrived with an update.
2.  **Implement and describe technical measures.** We implement the measures under Article 32 GDPR and describe them so they can be reviewed: access control, encryption, separation, logging, restorability and regular verification.
3.  **Make deletion possible.** We produce a deletion concept setting periods per data type, resolve the conflict with retention obligations, and implement it technically where the data volume justifies it. That includes backups, archives and log data.
4.  **Prepare for incidents.** We set up a procedure for data breaches, with detection, assessment, notification within the deadline and documentation. The most common failure is not the breach but late detection.

## What you gain

*   An implementation that can be evidenced in an audit rather than merely asserted.
*   Access and deletion requests handled in days rather than weeks.
*   Less risk from systems nobody has reviewed.

## From our projects

Log data is the most frequently overlooked area. Systems log sign-ins, access and changes, often for years, and nobody ever set a deletion period. That data is personal, it can be analysed, and in case of doubt it is subject to codetermination. We therefore review it early and set periods. The second recurring finding concerns test environments: in many companies they contain a copy of production data, with wider permissions and weaker protection. That is one of the easiest routes to a reportable incident and can be avoided with anonymised or synthetic data.

## Good to know

Four points are central. Article 30 GDPR requires the record of processing activities, which has to be kept current. Article 32 requires technical and organisational measures appropriate to the risk, explicitly including a procedure for regularly reviewing their effectiveness. Article 28 requires a processor agreement for every service provider processing personal data on your behalf. Article 35 requires a data protection impact assessment for processing likely to result in a high risk, which can apply to comprehensive monitoring systems, biometric procedures and certain AI applications. For employee data, the legal basis in Germany has to be examined carefully following the Court of Justice ruling on a state law provision equivalent to Section 26 BDSG.

## Häufige Fragen

May we use US providers?

Yes, if there is a valid basis for the transfer and the risks have been assessed. Check in each case the provider's certification under the applicable adequacy decision, the contractual commitments and the question of which data is actually transferred. That assessment belongs documented, because it will be requested in case of doubt. The legal assessment in the individual case belongs with your data protection advisers.

How do we handle a data breach?

Detect, assess, report, document. Notification to the supervisory authority has to be made without undue delay and where feasible within seventy-two hours of becoming aware, where there is a risk to the individuals concerned. What matters is that the procedure exists beforehand: who assesses, who reports, which information is needed. Clarifying those questions during an incident consumes exactly the time the deadline allows.

## Let us talk about Implementing data protection technically

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our consulting](/en/so-funktionierts)

## Further reading

[Security and ResilienceOrdering identities and accessWho may do what and why: build an access concept, use roles instead of individual rights, introduce multi-factor authentication, automate joiners and leavers and review permissions regularly.](/en/it-beratung/sicherheit-und-resilienz/identitaeten-und-zugriffe)[IT Governance and ComplianceIT obligations at a glanceWhich IT related obligations affect your company, who owns them, which evidence is needed and how a register of obligations gets you prepared for every audit.](/en/it-beratung/it-governance-und-recht/it-compliance)[Build and BuyBringing shadow IT into orderWhy departments buy their own tools, which risks arise, and how to make shadow IT visible, assess it and move it onto an orderly path without punishing the departments.](/en/it-beratung/entwickeln-und-beschaffen/schatten-it)[KnowledgeIT regulatory radarWhat applies, what is coming, what to do now.](/en/it-beratung/regulatorik-radar)[KnowledgeIT glossaryTerms from IT, software and security, briefly explained.](/en/it-beratung/glossar)

Back to the field [IT Governance and Compliance](/en/it-beratung/it-governance-und-recht)

## Sources

*   [Article 30 GDPR, records of processing activities](https://gdpr-info.eu/art-30-gdpr/)
*   [Article 32 GDPR, security of processing](https://gdpr-info.eu/art-32-gdpr/)
*   [Article 35 GDPR, data protection impact assessment](https://gdpr-info.eu/art-35-gdpr/)
*   [Regulation (EU) 2016/679 (GDPR), EUR-Lex](https://eur-lex.europa.eu/eli/reg/2016/679/oj)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
