ORYS Group
Home
Expertise
About Case studies Blog Careers
Cybersecurity

Data protection: compliance as a daily practice

The European framework does not ask for a tidy folder. It asks you to demonstrate, at any moment, that you know which data you hold, why you hold it, and for how long.

A data protection expert in a modern office

Compliance with the European data protection framework is often run as a project: a few weeks of effort, a set of documents, a shared folder, and the subject is considered closed. Months later, the record of processing no longer reflects the organisation, nobody knows who handles an access request, and the retention policy has never deleted a single record. Yet the regulation does not ask for a folder. It asks the controller to be able to demonstrate compliance at any time. That is a difference in nature, not in degree.

Paper compliance and lived compliance

Compliance on paper shows the same symptoms from one audit to the next:

  • the record of processing was completed once, during the initial remediation, and never moved again;
  • privacy notices are legally accurate but unreadable for the people they address;
  • the retention policy sets durations that nothing technically enforces;
  • nobody knows where an erasure request lands, or who is expected to answer it;
  • processor contracts were signed without anyone checking what they actually permit.

None of these is a dramatic failure. Together they describe an organisation that produced documentation without changing its practices. The accountability principle points the other way: it places the burden of proof on what you do, not on what you wrote.

The record of processing as a steering tool

The record of processing activities is the most underused document of the whole framework. Treated as a formality, it becomes a table of vague purposes. Treated as a steering tool, it becomes the map of how data lives in the organisation: which purposes, which categories of people and data, which lawful bases, which recipients, which retention periods, which processors, which transfers.

A current record surfaces what no other document shows: duplicate collection across teams, orphaned processing whose owner has left, tools deployed without legal ever hearing about them. Above all, it lets you answer a rights request in minutes rather than weeks.

One habit changes everything: the record is updated when the decision is made — new tool, new supplier, new form — not during an annual review that reconstructs the past from memory.

Qualify, minimise, purge: the structural decisions

Breaking the consent reflex

The regulation offers several possible grounds: consent, performance of a contract, a legal obligation, vital interests, a public interest task and legitimate interests. Consent is only one of them, and it is the one organisations invoke wrongly most often. Valid consent must be freely given, specific, informed and unambiguous, and as easy to withdraw as it was to give — so using it for processing that the service cannot function without promises a reversibility you cannot honour.

In practice, running a customer account usually rests on performance of the contract, invoicing on a legal obligation, and system security or fraud prevention on legitimate interests — provided you genuinely balanced that interest against people's rights and kept a record of the reasoning. The choice of basis is not a stylistic one: it determines which rights apply. Portability does not cover every processing activity, and a badly qualified basis weakens everything built on top of it.

A retention policy that actually runs

Minimisation is the cheapest security control available: data you never collect cannot leak. Every field on a form should be justified by a precise purpose; otherwise it should go.

Storage limitation follows the same logic but nearly always fails in the same place. A retention policy is real only when it combines three things: a justified duration for each purpose, a technical mechanism that enforces it automatically, and evidence that the purge actually ran. Without the last two, the duration is merely an intention. The blind spots are always the same: backups, exports, test environments fed with production data, mailboxes.

Inform clearly, make rights workable

Information people can actually read

Transparency is not satisfied by an exhaustive text nobody reads: it calls for information that is concise, intelligible and easily accessible. A useful notice answers, in a few lines, the questions people actually have — who processes my data, for what purpose, on what basis, who receives it, for how long, and how do I exercise my rights.

Organising responses to requests

People hold rights of access, rectification, erasure, restriction, objection and portability. The difficulty is not legal but organisational: the response must come within the prescribed time — one month, extendable by two further months where requests are complex or numerous, provided the person is told within the first month. Meeting that deadline means knowing in advance who receives the request, who qualifies it, how identity is verified, and in which systems the data sits.

Impact assessments, processors and transfers

A data protection impact assessment (DPIA) is required where processing is likely to result in a high risk to people's rights and freedoms. The regulation explicitly targets systematic evaluation of personal aspects based on automated processing with significant effects, large-scale processing of special categories of data, and large-scale systematic monitoring of a publicly accessible area; supervisory authorities also publish their own lists. Carried out early, a DPIA shapes the design; carried out at the end, it merely records it.

Using a processor must be framed by a contract meeting the requirements of Article 28: documented instructions, confidentiality, security measures, control over sub-processors, assistance to the controller, the fate of the data at the end of the contract, and the information needed for audits. Two points deserve particular attention: the real list of sub-processors, and where the data — and the support teams — are located. Any transfer outside the Union must rest on a valid mechanism: an adequacy decision, standard contractual clauses or binding corporate rules.

Security, breaches and the human factor

Security is an obligation to apply measures appropriate to the risk, judged against the state of the art and the nature of the data: encryption in transit and at rest, segregated environments, least-privilege access management with periodic reviews, usable logging, tested backups. These are not a separate chapter of compliance; they are its technical expression.

When a breach occurs, the decisive reflex is fast qualification. Every breach must be documented internally; those likely to result in a risk to people must be notified to the supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of them; where the risk is high, the individuals concerned must be informed as well. The clock starts on awareness, which means the alert has to travel — everyone needs to know what to report and to whom.

Compliance is not measured by the volume of documents produced, but by how long it takes to answer a simple question: where is this data, why do we hold it, and until when?

This is where the data protection officer matters, less for formal expertise than for positioning: involved in good time in data-related questions, performing the role without instructions on how to carry it out, free of conflicts of interest, and able to reach the highest level of management. A DPO consulted after the decisions is not a DPO. And because most incidents begin with an ordinary gesture — an attachment, an over-broad share — regular awareness work remains the first line of defence.

The next step

If you do one thing this quarter, do this: open your record of processing, pick your five most sensitive activities and check four points for each — is the lawful basis the right one, is the retention period enforced by a technical mechanism, is the information readable, and does the processor contract cover what the supplier actually does. The gaps you find become your action plan.

This article sets out general principles and does not constitute legal advice: each processing activity must be qualified against its own purpose and context, with your data protection officer or your legal counsel.

Keep reading

Related articles

Make your compliance live, not just look complete

Our experts help you put the record of processing back in motion, qualify your lawful bases, make retention periods enforceable and organise responses to rights requests.