Privacy governance, controlled data processing and international data flows

Data Protection

Data Protection – Compliant, Risk-Based and Practical

Data protection is an essential element of responsible corporate governance. Companies must process personal data lawfully, transparently and securely under the EU General Data Protection Regulation (GDPR) and the applicable national requirements.

The requirements are not limited to customer data. Employee information, supplier contacts, applications, video recordings and data generated by digital business processes may all require appropriate safeguards and documented decisions.

Typical review and action areas

  • Are records of processing activities under Article 30 GDPR complete and current?
  • Have processing risks and special categories of personal data been assessed?
  • Is a data protection impact assessment under Article 35 GDPR required?
  • Are technical and organisational measures under Article 32 GDPR documented and appropriate?
  • Are processor agreements under Article 28 GDPR complete and current?
  • Are retention and deletion periods implemented consistently?
  • Are procedures in place for data-subject requests?
  • Can personal data breaches be identified, assessed and, where required, reported in time?
  • Are cloud services, international transfers and external service providers adequately addressed?

Where the statutory conditions are met, a personal data breach must generally be notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours in accordance with Article 33 GDPR.

Data protection and business risk

Data protection deficiencies can lead to supervisory measures, compensation claims, business disruption and reputational damage. The GDPR provides for differentiated maximum fines depending on the infringement. The actual consequences always depend on the facts and circumstances of the individual case.

External Data Protection Officer for International Companies

Collegium Auditores has successfully provided external Data Protection Officers to companies of different sizes and in different sectors for many years.

Our work includes ongoing advice to the controller, monitoring compliance, advising on data protection impact assessments, and supporting the handling of data-subject requests, data breaches and supervisory-authority reviews.

A particular focus is supporting companies from North America and Asia that offer goods or services in the European Union or process personal data relating to individuals in the EU. We assess which GDPR obligations apply and help establish appropriate governance, responsibilities and evidence.

Where relevant, we also support the appointment of a representative in the European Union under Article 27 GDPR. The role of an external Data Protection Officer under Articles 37 to 39 GDPR is legally distinct from the role of an EU representative under Article 27 GDPR.

External data protection officer advising an international company

Data protection audits

We review the current state of your data protection management system and help identify and prioritise improvements. An audit may cover:

  • governance and responsibilities;
  • records of processing activities;
  • legal bases and transparency information;
  • data-subject rights;
  • processors and service-provider oversight;
  • technical and organisational measures;
  • retention and deletion concepts;
  • data protection impact assessments;
  • breach and notification processes;
  • international transfers;
  • training and awareness; and
  • privacy integration into new projects and systems.

We document results in a traceable manner, assess identified deviations and support the development of an appropriate action plan.

International experience

Our practical experience includes national and international organisations in financial services, aviation, industry, logistics, healthcare, procurement and supply, and internationally active corporate groups. Where appropriate, we cooperate with qualified international specialist partners on cross-border matters.

Contact

Would you like to strengthen the organisational and technical implementation of data protection in your company? Contact us to discuss the relevant risks, requirements and next steps.

office(at)collegium-auditores.de