Ailance Alt TM Logo
Ailance Alt TM Logo

„Data protection is just red tape and hinders digitalization“—Let’s put an end to such prejudices!


Data protection promotes efficiency and security in businesses. Discover how data protection can reduce bureaucracy, lower costs, and improve security. Take advantage of the benefits of data protection-compliant processes!

The number of devices, applications, and (online) services that personal data The volume of data being processed has risen sharply in recent years. Data is also increasingly being exchanged between service providers and partners.

So it’s hardly surprising that many companies find it difficult to maintain an overview and organize everything in such a way that data is processed securely, confidentially, and in compliance with the law. This also includes having a functional, up-to-date, and complete backup in place „just in case.“ Gaining an overview may be time-consuming, but—much like bookkeeping—it’s simply necessary. After all, how else can you maintain an overview of licensing costs, contracts, and security measures—including backups?

The GDPR offers a solution here that is usually mandatory but can also be very helpful: the Record of Processing Activities. This provides an appropriate overview and, with some expansion, can help ensure that no relevant applications or service providers are overlooked. Beyond ensuring compliance with data protection requirements, this can also help identify risks, for example.

Examples of this: The data is processed in an online application provided by a smaller service provider. What happens if the provider goes bankrupt? Will the data still be accessible then? Or suppose you plan to use Microsoft 365 online applications. Have you considered that while this data is stored in multiple data centers, no backups are performed? That’s something the Microsoft 365 customer—for example, your company—must handle on its own!

No more sleepless nights due to inadequate IT security

If an organization has a clear overview of all the applications, services, and devices it uses, it can systematically secure them. Some providers even offer free options for this. For example, many operating systems for PCs and laptops include easy-to-use hard drive encryption. Some online providers allow users to secure their logins with two-factor authentication, such as via a smartphone app or text message. If an employee, under stress, then falls for a PhishingIf a user enters their email address and sends a cybercriminal the login credentials for an online application, the cybercriminal will still be unable to gain access thanks to two-factor authentication and, consequently, cannot cause any (financial) damage. If a laptop is lost or stolen, the data is available in a nearly up-to-date version thanks to a well-designed backup, and no one can view the data on the laptop because of the activated hard drive encryption. In the latter case, this could even be the reason why the company is not required to notify the individuals whose data was stored on the laptop.

Clear Up Misunderstandings with the Data Protection Officer

As you’ve seen from the examples above, data protection often doesn’t prevent digitalization projects. On the contrary: Some projects, such as the example of the young CEO, result in better data protection as a side effect. In other projects, the data protection officer can use their knowledge of potential risks to ensure that new data processing activities are not only compliant with the law but also secure. What company wouldn’t want that—especially in an era when cybercriminals are so active?

Time and again, misunderstandings arise due to differing perspectives. Yet those in charge and the data protection officer often ask themselves—in some cases, fundamentally—the same questions.

As the person responsible for data processing or related projects, take advantage of this opportunity and actively involve your data protection officer early on. If in doubt, ask what your data protection colleague is getting at with a particular question. Often, they are simply trying to clarify necessary details or are already mentally assessing certain security risks. Together, you can achieve excellent, secure, and data protection-compliant processing practices.

Picture of Marcus Belke

Marcus Belke

Marcus Belke is the CEO of 2B Advice GmbH. He drives innovation in data protection compliance and risk management and is responsible for the further development of Ailance, the next-generation compliance platform.

Share this post:

„Data protection is just red tape and hinders digitalization“—Let’s put an end to such prejudices!