Data protection
is often lumped together with
data security. However, data protection is aimed exclusively at the collection, processing and use of
personal data. Of course, this also places demands on data security, so the transition is often fluid. Legal obligations have existed since May 25, 2018 based on the EU
General Data Protection Regulation (EU-GDPR).
The correct handling of personal data under data protection law is a MUST for EVERY entrepreneur, regardless of whether he is now is obliged to appoint an internal or external
company data protection officer
due to the number of employees who handle personal data (from 20 employees; in Germany since November 26, 2019) or his area of activity. Particular attention must be paid to the collection, storage, use and deletion of personal data! For example, when sending newsletters to customers and prospects of a company as well as when using video cameras to monitor entrance and work areas.
In my opinion, it is particularly important to develop an
understanding of data protection in the company. Apart from the formal implementation (documentation of the processing operations, contracts for order data processing, training of employees, etc.), it is not enough to be able to present THE data protection officer. The entire workforce MUST understand what data protection is basically about and where the company or organization - i.e. a group of people - runs the risk of disregarding the GDPR rules of the game. How quickly do you seemingly simply open the door for someone in a friendly manner?
Social engineering is the method by which cybercriminals often gain access to data far too quickly. Ultimately, the management remains responsible!
Make your employees a human firewall.
A "data breach", i.e. the disclosure of personal data to third parties, must be reported to the relevant supervisory authority within 72 hours and communicated to those affected. Are you prepared for this in your company - also during the Christmas holidays ?!