Understanding data protection law is one thing; continuously monitoring and controlling it is another. It's difficult to keep track of every detail if not every data processing activity and data protection requirement is organized in a system. A data protection management system – DMS – not only brings order but also fulfills the GDPR's accountability and documentation obligations.
What is it exactly about?
The topic of data protection, which is important to all of us, should by now be a firmly established part of the corporate structure. Only those who constantly keep data protection in mind can ensure a long-term data-compliant way of working. For this purpose, in cooperation with all business units of your company, we develop a coordinated procedure that enables a review of data protection requirements at continuous intervals.
Companies and their ways of working are subject to constant change. Therefore, it should and must be reflected cyclically whether and to what extent processes are designed in compliance with data protection.
Part of this procedure includes, in particular, data protection principles such as: lawfulness, transparency, purpose limitation, and data minimization. For what purpose and on what legal basis is the data processed? Is it also necessary for this reason? How can the data subject be clearly informed about which data is being processed and why? These and other answers should be found in the DMS.
The preventive goals of the DMS are, on the one hand, to comply with the data subject access rights imposed by the GDPR and, on the other hand, to prevent violations. In the worst-case scenario, the DMS particularly helps to identify the problem at a crucial point and to adapt processes quickly.
Process for Creating a Data Protection Management System
To establish a sustainable improvement process within your company, we follow the PDCA cycle (also known as the Deming Cycle). This describes the implementation of the management system: Plan – Do – Check – Act.
The first step of planning involves documenting all of the company's data processing activities. What is the current state, and which data protection requirements must be implemented to achieve the goal of a data protection-compliant company infrastructure?.
The tasks that have been identified must now be implemented correctly to avoid data protection incidents.
The third step involves the previously mentioned review and analysis after a certain period of time:
Should processes be corrected? Should other preventive measures be established? Or have the targets changed and need to be realigned? If so, this is the final step in the cycle, by evaluating and improving the system if necessary.