Implementation as work products
The data protection implementation path
7 chapters put decisions, responsibilities and evidence in a defensible order.
- 01
Own
Clarify mandate and roles
Set up data protection as a leadership and operational task with clear responsibilities.
Expected work products
- Data protection policy
- Role matrix
- Review and escalation rhythm
Based on: EU, ISO
- 02
Make visible
Inventory processing activities
Capture purposes, data, persons, systems, recipients and owners completely.
Expected work products
- Record of processing activities
- Data flow overview
- Change process
Based on: EU, DSK
- 03
Justify
Demonstrate lawfulness and transparency
Reliably assign legal bases, information obligations and international transfers.
Expected work products
- Legal basis review
- Privacy notices
- Transfer documentation
Based on: EU, EDPB
- 04
Assess
Steer risks and DPIAs
Recognise risks to data subjects early and treat high risks in a structured way.
Expected work products
- Risk method
- DPIA threshold assessments
- DPIA and measures
Based on: EU, ISO
- 05
Protect
Anchor TOMs and privacy by design
Implement safeguards traceably in design, configuration and operations.
Expected work products
- Catalogue of technical and organisational measures
- Privacy design check
- Effectiveness evidence
Based on: EU, ISO
- 06
Execute
Operate rights, deletion and incidents
Make deadline-bound data protection processes workable across systems and roles.
Expected work products
- Data subject rights procedure
- Deletion concept
- Incident process
Based on: EU, EDPB
- 07
Control
Vet service providers and improve the system
Bring processing on behalf of a controller, controls, audits and changes into a robust feedback loop.
Expected work products
- Service provider register
- Control and audit plan
- Management review
Based on: EU, DSK, ISO