Data protection · from obligation to process
Data protection that holds up in everyday work.
This knowledge hub translates the GDPR, supervisory practice and privacy management into understandable decisions, reliable evidence and free working templates.
- Articles
- 8
- Check questions
- 20
- Templates
- 6
- Chapters
- 7
Start from the work product
Read no more than the next step needs.
01
Assess your starting point
20 questions cover governance, processing activities, data protection risks, data subject rights, service providers and incidents. Your answers stay local.
02
Structure the implementation
7 chapters connect decisions to concrete outcomes.
03
Start from a template
6 open working aids for workshops, registers and reviews.
Source-based orientation
Articles
- 01GovernanceData protection management system: from individual tasks to a manageable systemA privacy management system connects responsibilities, processing activities, risks, controls and evidence. Only then can data protection be operated.8 min
- 02InventoryCreating the RoPA: how the record becomes a steering instrumentA good record reflects real processing and links legal basis, data flows, recipients, deletion, risks and the people responsible.9 min
- 03LawfulnessReviewing legal basis, purpose limitation and data minimisation togetherA legal basis does not legitimise an arbitrary scope of data. Purpose, necessity and transparency must be documented as one connected decision.8 min
- 04Service providersProcessing on behalf of a controller: vetting service providers beyond the contractA data processing agreement is the frame. Robustness comes from selection checks, concrete instructions, evidence of measures and ongoing oversight.9 min
- 05ProtectionTOMs and privacy by design: deriving safeguards from the riskTechnical and organisational measures must fit the processing context and remain effective across the entire lifecycle.8 min
- 06RiskConducting a DPIA: working through high privacy risk in a structured wayA data protection impact assessment does not start with a long report, but with a solid threshold assessment and a clear processing scenario.10 min
- 07OperationsTranslating data subject rights and deletion into real operational processesDeadlines can only be met when identification, search, decision, execution and evidence are prepared across systems and the people responsible.9 min
- 08IncidentsPersonal data breach: organising the first 72 hours so you can actNot every security incident is notifiable. But every suspicion needs a fast, documented assessment of data, consequences and countermeasures.8 min
How it connects
The data lifecycle
Data protection becomes manageable when every processing activity follows a traceable lifecycle from planning to deletion and decisions remain verifiable.
- GOV
- GovernanceOwn
- Roles, policies, decisions and reviews make accountability organisationally viable.
- VVT
- Processing inventoryUnderstand
- Purpose, data, persons, systems, recipients and owners form the shared working basis.
- LAW
- LawfulnessJustify
- Legal basis, transparency, purpose limitation and data transfers are justified per processing activity.
- PIA
- Privacy riskAssess
- Risk screening, DPIAs and privacy by design protect rights and freedoms early.
- OPS
- Privacy operationsExecute
- Data subject rights, deletion, permissions and incidents work as measurable processes.
- ASS
- AssuranceProve
- Service provider controls, audits, metrics and improvements keep the system effective.
From knowledge into operation
Do not lose the results in yet another file.
KaitoSec connects requirements, owners, risks, controls and evidence in one working model.
Written independently on the basis of the GDPR, DSK and EDPB publications, ISO/IEC 27701:2025 and our own practice templates. Not legal advice.
Content as of: 21.07.2026