Due to the gre­at demand of our cus­to­mers and inte­res­ted par­ties on the topic of GDPR and Direc­to­ry of Pro­ce­du­res, SEC4YOU offe­red a GDPR work­shop in Novem­ber 2017, which spe­ci­fi­cal­ly high­lights the imple­men­ta­ti­on of GDPR mea­su­res and offers affec­ted com­pa­nies the oppor­tu­ni­ty to start direct­ly at the work­shop with the mea­su­res or to sup­port their own pro­ject with tem­pla­tes and decis­i­on bases.

The work­shop was aimed at public and pri­va­te com­pa­nies from all sec­tors that pro­cess or store per­so­nal data. Con­tra­ry to the wide­spread opi­ni­on that the GDPR only appli­es to lar­ge com­pa­nies, this ques­ti­on was ans­we­red con­clu­si­ve­ly by work­shop lea­der Man­fred Scholz as well as by two lawy­ers present:

The GDPR affects all com­pa­nies that pro­cess per­so­nal data — regard­less of com­pa­ny size and legal form — as of 25.5.2018!

After explai­ning the histo­ry of the GDPR and the posi­ti­on of Aus­tria in the Euro­pean vote, the par­ti­ci­pan­ts agreed on the essen­ti­al com­pon­ents of the GDPR imple­men­ta­ti­on. As an important task within the GDPR mea­su­res, the new requi­re­ment of kee­ping a regis­ter of pro­ces­sing acti­vi­ties in Aus­tria was discussed.

Direc­to­ry of pro­ces­sing acti­vi­ties by means of software?

Con­tra­ry to the opi­ni­on of indi­vi­du­al pro­vi­ders, a soft­ware tool for main­tai­ning the direc­to­ry of pro­ces­sing acti­vi­ties should not be in the fore­ground of a GDPR pro­ject, as the initi­al crea­ti­on can usual­ly be done in Excel or Word for small and medi­um-sized com­pa­nies. In lar­ge com­pa­nies, or if the main­ten­an­ce effort for kee­ping and regu­lar­ly che­cking or revi­sing the direc­to­ry is to be done by seve­ral employees or in dis­tri­bu­ted com­pa­nies, the intro­duc­tion of a spe­cial tool can also save costs.

The Direc­to­ry of Pro­ces­sing Acti­vi­ties — DSGVO VV

As has been cus­to­ma­ry in Ger­man data pro­tec­tion for over 10 years as a “pro­ce­du­ral direc­to­ry” or “pro­ce­du­ral over­view”, the GDPR now also requi­res com­pa­nies to main­tain a direc­to­ry of pro­ces­sing acti­vi­ties. Experts see a dif­fe­rence here to the DSG 2000 whe­re in Aus­tria a basic obli­ga­ti­on to report cer­tain data appli­ca­ti­ons in the data pro­tec­tion regis­ter is requi­red (until May 2018) or was requi­red (from May 2018).

An important fea­ture of a pro­ce­du­re direc­to­ry is that the data-pro­ces­sing com­pa­ny pro­ces­ses are recor­ded and not the appli­ca­ti­ons themselves.

=> What the­r­e­fo­re does not belong in a direc­to­ry of pro­ces­sing acti­vi­ties? e.g. MS CRM, Excel or Exchange.

The important con­tents of the direc­to­ry of pro­ces­sing acti­vi­ties have been summarized.

In the role of the con­trol­ler must be recorded:

  • Name and cont­act details of the con­trol­ler, if appli­ca­ble joint con­trol­ler or a repre­sen­ta­ti­ve (EU).
  • Name and cont­act details of the data pro­tec­tion officer
  • Pur­po­se of the processing
  • Cate­go­ries of data subjects
  • Cate­go­ries of per­so­nal data
  • Cate­go­ries of recipients
  • Trans­fer to third count­ries (gua­ran­tees, if applicable)
  • Dele­ti­on periods
  • Gene­ral descrip­ti­on of tech­ni­cal and orga­niza­tio­nal mea­su­res (TOM accor­ding to Art 32 para.1).

On the other hand, pro­ces­sors have the fol­lo­wing recor­ding obligations:

  • Name and cont­act details of the data con­trol­ler, joint data con­trol­ler or repre­sen­ta­ti­ve (EU), if applicable.
  • Name and cont­act details of the data pro­tec­tion officer
  • Cate­go­ries of processing
  • Trans­fer to third count­ries (gua­ran­tees, if applicable)
  • Gene­ral descrip­ti­on of tech­ni­cal and orga­niza­tio­nal mea­su­res (TOM accor­ding to Art 32 para.1)

In the last part of the work­shop, exem­pla­ry examp­les were pre­sen­ted how a direc­to­ry of pro­ce­du­res looks like and the SEC4YOU tem­p­la­te V1.1 of the direc­to­ry of pro­ces­sing acti­vi­ties was presented.

Con­tents of the workshop

This is the recor­ding of the work­shop con­tents wit­hout sound.

Fur­ther artic­les on the topic of data pro­tec­tion / DSGVO