We live in an information society where data and information play an ever-growing role in our lives. Thanks to technological progress and increasing bureaucracy, countless pieces of data are transferred, processed, and traded every day. For many digital processes, data collection has become essential and is now standard practice.

We adapt our strategies and workflows to technological possibilities and integrate data transmission and processing into our daily operations. Online shopping, in particular, shows how strongly data processing influences our everyday lives. In these sensitive areas, where personal data is processed, data protection regulates the proper transmission and processing of data flows and protects them from misuse.

Learn more: Metadata: Properly Protecting Information in Digital Documents

 

Data Protection Basics — Defining Data Protection

The basic idea behind data protection is to protect individuals with regard to how their personal data is handled. At its core, this protection mechanism safeguards data that is directly or indirectly linked to a person.

The focus here is especially on the protection of personal data. This includes general contact details that relate to an identified or identifiable person, such as your name, phone number, address, email address, and more. Data that allows conclusions to be drawn about you is also subject to data protection. Our main goal with data protection is to protect your freedom and your data. You have the right to determine what happens with your own data and to control its processing.

In summary, data protection and its fundamentals aim to prevent the misuse of data processing and violations of your privacy.

Learn more: What Is Double Opt-In and Why Does It Matter?

 

Legal Foundations of Data Protection

The protection of personal data is legally governed, among other things, by the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The GDPR is a directly applicable European Union regulation that doesn't need to be transposed into national law, but it does contain opening clauses. These national provisions are supplemented and specified by the BDSG. There's always a connection back to the GDPR.

Learn more: Data Processing Agreement (DPA) — heyData Creates Transparency

Protecting Data Within a Company

Data protection law governs all relevant provisions on processing personal data within companies. Every company operating in the EU is required to comply with data protection regulations. Data belonging to customers, employees, or business partners must be protected, or the company risks fines or sanctions. Ignoring the basics of data protection can also damage a company's reputation.

Learn more: The External Data Protection Officer — The Optimal Solution for Your Company

Data Protection Basics

Due to budget or time constraints, some companies neglect GDPR compliance. To help you avoid such problems, heyData has put together a short checklist of data protection basics for companies:

  1. Data Protection Officer: Within a company, data protection can be represented internally or externally. heyData can help you implement data protection securely and efficiently.
  2. Processing Activities: Make sure you maintain a record of processing activities. This should define responsibilities, the type of data processing, and retention periods.
  3. Privacy Policy: Every data subject must be informed via a privacy policy. Website operators are required to provide this policy on their site.
  4. Confidentiality Obligation: Anyone working with personal data must be contractually bound in writing to confidentiality regarding company-related data.
  5. Data Processing Agreement (DPA): heyData is your go-to partner for questions about data processing agreements. Learn about your rights and obligations when processing personal data.
  6. Data Protection Measures: Technical and organizational measures must be implemented. Develop a company concept that ensures compliance with data protection basics — secure access codes, user accounts, and general operational workflows.
  7. Employee Awareness: Data protection has to be lived by every employee. Without your team's commitment, compliance with data protection basics can't be achieved. It's important to regularly raise awareness among those involved. Make use of your internal or external data protection officer's expertise for training.

Learn more: Record of Processing Activities — The Key Role for Data Protection and Transparency in the Modern Workplace

 

Cookies — The Notification Requirement

Cookies are used on websites as a marketing tool. They partly serve to optimize the online experience and to create user profiles. This can benefit you, for example, through personalized advertising or purchase suggestions. However, this process stores personal data in the form of IP addresses. Consent to the use of cookies is therefore mandatory under the GDPR. Explicit consent for cookie use is essential on websites and in online shops.

Data Protection Basics — Data Security

Data security goes hand in hand with data protection. It's not just about protecting personal data, but also about practical IT security measures. To comply with data protection basics, you should always be able to demonstrate a data security concept that covers not only personal data, but all data flows being processed.

Data security can be strengthened and ensured through the following measures:

  1. Up-to-date web browsers
  2. Up-to-date software (updates)
  3. Up-to-date firewall and antivirus software
  4. User accounts with defined permission levels
  5. Strong passwords
  6. Employee awareness training
  7. Caution with unknown attachments
  8. Permission management for downloads
  9. Avoiding publication of personal data
  10. Encryption software
  11. Backups

Summary of Data Protection Basics

The basics of data protection can be summed up in a few points, but implementing them is the real challenge. heyData is your professional and reliable partner in this field. We'll discuss and explain these core points with you:

  • Lawfulness
  • Transparency
  • Fairness
  • Purpose limitation
  • Data minimization
  • Storage limitation
  • Integrity
  • Confidentiality
  • Security

These points form the core of the GDPR and should be observed. Many companies aren't aware of the full implications, but several of these terms were newly defined by the GDPR. Violations of these principles can result in fines of up to €20,000,000 or 4% of the previous year's revenue.

heyData is your partner — and with us, data protection becomes a philosophy you live by!