Skip to content

Implementation as work products

The data protection implementation path

7 chapters put decisions, responsibilities and evidence in a defensible order.

Back to Data protection

  1. 01

    Own

    Clarify mandate and roles

    Set up data protection as a leadership and operational task with clear responsibilities.

    Expected work products

    • Data protection policy
    • Role matrix
    • Review and escalation rhythm

    Based on: EU, ISO

  2. 02

    Make visible

    Inventory processing activities

    Capture purposes, data, persons, systems, recipients and owners completely.

    Expected work products

    • Record of processing activities
    • Data flow overview
    • Change process

    Based on: EU, DSK

  3. 03

    Justify

    Demonstrate lawfulness and transparency

    Reliably assign legal bases, information obligations and international transfers.

    Expected work products

    • Legal basis review
    • Privacy notices
    • Transfer documentation

    Based on: EU, EDPB

  4. 04

    Assess

    Steer risks and DPIAs

    Recognise risks to data subjects early and treat high risks in a structured way.

    Expected work products

    • Risk method
    • DPIA threshold assessments
    • DPIA and measures

    Based on: EU, ISO

  5. 05

    Protect

    Anchor TOMs and privacy by design

    Implement safeguards traceably in design, configuration and operations.

    Expected work products

    • Catalogue of technical and organisational measures
    • Privacy design check
    • Effectiveness evidence

    Based on: EU, ISO

  6. 06

    Execute

    Operate rights, deletion and incidents

    Make deadline-bound data protection processes workable across systems and roles.

    Expected work products

    • Data subject rights procedure
    • Deletion concept
    • Incident process

    Based on: EU, EDPB

  7. 07

    Control

    Vet service providers and improve the system

    Bring processing on behalf of a controller, controls, audits and changes into a robust feedback loop.

    Expected work products

    • Service provider register
    • Control and audit plan
    • Management review

    Based on: EU, DSK, ISO