Skip to content

Data protection · from obligation to process

Data protection that holds up in everyday work.

This knowledge hub translates the GDPR, supervisory practice and privacy management into understandable decisions, reliable evidence and free working templates.

Articles
8
Check questions
20
Templates
6
Chapters
7

Source-based orientation

Articles

  1. 01GovernanceData protection management system: from individual tasks to a manageable systemA privacy management system connects responsibilities, processing activities, risks, controls and evidence. Only then can data protection be operated.8 min
  2. 02InventoryCreating the RoPA: how the record becomes a steering instrumentA good record reflects real processing and links legal basis, data flows, recipients, deletion, risks and the people responsible.9 min
  3. 03LawfulnessReviewing legal basis, purpose limitation and data minimisation togetherA legal basis does not legitimise an arbitrary scope of data. Purpose, necessity and transparency must be documented as one connected decision.8 min
  4. 04Service providersProcessing on behalf of a controller: vetting service providers beyond the contractA data processing agreement is the frame. Robustness comes from selection checks, concrete instructions, evidence of measures and ongoing oversight.9 min
  5. 05ProtectionTOMs and privacy by design: deriving safeguards from the riskTechnical and organisational measures must fit the processing context and remain effective across the entire lifecycle.8 min
  6. 06RiskConducting a DPIA: working through high privacy risk in a structured wayA data protection impact assessment does not start with a long report, but with a solid threshold assessment and a clear processing scenario.10 min
  7. 07OperationsTranslating data subject rights and deletion into real operational processesDeadlines can only be met when identification, search, decision, execution and evidence are prepared across systems and the people responsible.9 min
  8. 08IncidentsPersonal data breach: organising the first 72 hours so you can actNot every security incident is notifiable. But every suspicion needs a fast, documented assessment of data, consequences and countermeasures.8 min

How it connects

The data lifecycle

Data protection becomes manageable when every processing activity follows a traceable lifecycle from planning to deletion and decisions remain verifiable.

GOV
GovernanceOwn
Roles, policies, decisions and reviews make accountability organisationally viable.
VVT
Processing inventoryUnderstand
Purpose, data, persons, systems, recipients and owners form the shared working basis.
LAW
LawfulnessJustify
Legal basis, transparency, purpose limitation and data transfers are justified per processing activity.
PIA
Privacy riskAssess
Risk screening, DPIAs and privacy by design protect rights and freedoms early.
OPS
Privacy operationsExecute
Data subject rights, deletion, permissions and incidents work as measurable processes.
ASS
AssuranceProve
Service provider controls, audits, metrics and improvements keep the system effective.

From knowledge into operation

Do not lose the results in yet another file.

KaitoSec connects requirements, owners, risks, controls and evidence in one working model.

Written independently on the basis of the GDPR, DSK and EDPB publications, ISO/IEC 27701:2025 and our own practice templates. Not legal advice.

Content as of: 21.07.2026