Procedure
Data protection in a new IT project
Data protection belongs in a new project from the outset and not in the acceptance test. Calling it in at the end postpones no task, it forfeits the room for design that was open before. Individual points in time are also set by the law and not by the project plan, and they do not follow the go-live date.
Data protection comes last
The decision on the system has been taken, the contract sits with procurement, the go-live date is in the project plan. Whether anything is owed under data protection law has not been answered so far. The time pressure therefore starts in the wrong place, because the assessment holds up a project that never made room for it. At the same time the means of avoiding a data protection problem are largely spent once the selection has been made. After a rollout, every change costs migration and downtime on top.
The sequence that saves rework
When data protection belongs in a project is answered by the sequence itself. Five steps arise in any case, and each of them carries a decision that costs less there than later.
A project with data protection running alongside
Describe the need
Which task the system is to solve and which data it needs for that. What it does not need belongs in the description just as much.
Set the requirements
Data categories, place of processing, retention periods, deletion routines and role permissions become part of the tender. Art. 25(1) GDPR requires the measures at the time the means are determined.
Assess the supplier
Under Art. 28(1) GDPR only processors providing sufficient guarantees may be used. The assessment belongs here, because here there is still an alternative.
Conclude the contract
The contract under Art. 28(3) GDPR is concluded before the processing begins. Its draft is to be read before the commitment.
Configure and go live
The default settings under Art. 25(2) GDPR are set, the impact assessment is complete and the entry in the records under Art. 30(1) GDPR is in place.
Anyone joining only after the selection skips the first three steps. What is left open then turns out to be less than expected.
What is still open, and when
| Before the selection | Merkmal | After the selection |
|---|---|---|
| Open to choiceBetween two products there are often whole categories of data, such as location, usage logs or biometric features. | Which data arise at all | Settled |
| Open to choiceData centre, sub-processors and remote maintenance follow the product and can rarely be changed later. | Where processing takes place | Mostly settled |
| Open to choiceWhether a product knows retention periods, visibility settings and deletion routines at all is decided with the product. | Retention periods and visibility | Only where provided forArt. 25(2) GDPR requires data protection by default. What can be set, however, is only what the product provides for. A deletion routine is often missing altogether, and then deleting by hand is all that remains. |
| A selection criterionReading the draft contract before the selection allows it to be weighed against another supplier's. | Instructions and audit rights | Often laid downThe contract under Art. 28(3) GDPR has to be concluded. That does not make it negotiable. Suppliers of standard software present it as a condition. |
Under Art. 28(1) GDPR only processors providing sufficient guarantees may be used. That assessment therefore belongs in the selection and not in the acceptance test.
A supplier’s certification does not take that assessment off anyone’s hands. Art. 28(5) GDPR provides that it may be used as an element by which to demonstrate sufficient guarantees. It does not replace the assessment, and it says nothing about the configuration in your own organisation.
What a project plan does not negotiate
Which deadlines the schedule cannot move is the question whose answer is missing most often from project plans. Three points in time are set by the Regulation and not by the project. They do not depend on one another, each rests on a provision of its own.
Timely involvement
Art. 38(1) GDPR requires the data protection officer to be involved in good time in all issues relating to the protection of personal data. A submission for sign-off does not meet that.
Impact assessment in advance
Art. 35(1) GDPR requires it before the processing. Under the supervisory authorities’ guidelines it starts as early as is practicable, even where individual operations are still open.
Up to 14 weeks for the consultation
Where a high risk remains, the supervisory authority has to be consulted before the processing under Art. 36(1) GDPR. It has eight weeks, extendable by six. That duration does not lie with your own organisation.
The most common objection to an early assessment is that not enough is settled yet. The supervisory authorities’ guidelines answer it expressly. That the assessment will have to be updated later is not a reason to postpone it. Whether the consultation arises at all only the assessment shows, and so the schedule hangs on when the assessment begins and not on when it ends.
Frequently asked questions
When is it too late for an assessment?
For effective design the latest point is the selection, because Art. 25(1) GDPR ties the measures to the determination of the means. For lawfulness the latest point is the start of the processing. Both can be made up afterwards, but the period in between remains uncovered and stands in the accountability record.
Is the supplier's certification enough?
Not as proof. Art. 28(5) GDPR provides that an approved certification mechanism may be used as an element by which to demonstrate sufficient guarantees. The assessment remains with the controller, and it turns on the actual configuration and on the instructions agreed.
Does the impact assessment have to be finished before the project starts?
It has to be carried out prior to the processing, not prior to the project. Under the supervisory authorities' guidelines it is to be started as early as is practicable, even where individual processing operations are still unknown, and it is updated as the project proceeds. That an update may be needed later is expressly not a reason to postpone it.
What happens if the assessment shows a high risk?
Where a high risk remains despite mitigating measures, the supervisory authority has to be consulted before the processing under Art. 36(1) GDPR. It has up to eight weeks for this, and the period may be extended by six weeks. A project plan that does not allow for this case has not abolished it.
More questions from this area
Automated individual decisions
Pre-selection is not a preliminary stage of the decision where the selection follows it to a significant degree.
Special categories of data
Art. 9(1) GDPR prohibits the processing, and a permission under paragraph 2 sits alongside the legal basis in Art. 6 GDPR rather than replacing it.
Transfer impact assessment
The regulation does not know the term transfer impact assessment.
Data protection impact assessment
An impact assessment under Art. 35 GDPR is not a formality at the end of a project.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.