Privacy
Focus topic

Compliance and privacy governance

Organise responsibilities, processing records, policies and evidence so that data protection can be managed in daily business.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

Privacy governance is the organisational framework in which a business takes responsibility for processing personal data. It includes clear roles, an up-to-date record of processing activities, suitable policies and evidence showing how risks and controls are handled.

The focus is not a general explanation of the GDPR or a detailed treatment of individual data subject rights. It is the practical question of how management, business units, IT, HR, marketing and external providers work together so that data protection decisions are not left to chance.

The review of processors and service providers, the handling of personal data breaches and employee data raise distinct questions. A sound governance framework connects them without treating them as one undifferentiated checklist.

Written by Mag. Bernhard Brandauer, Rechtsanwalt

Initial orientation

Where does your privacy governance stand?

Answer three short questions. The result indicates which organisational gap should be addressed first.

01 Question 1

Are data protection responsibilities clearly assigned in the business?

This means more than job titles. It includes concrete responsibility for decisions, approvals and evidence.

Ergebnis

Ihre Orientierung

01

Clarify responsibility first

Define who is responsible for each processing activity, who supplies the operational information and who records risks or approvals. Only then can you assess whether records, policies and controls fit together.
Connect roles with provider questions →
02

Bring the record up to date

Start with the processes actually used. Priorities often include new software, external platforms, HR processes, customer communication and higher-risk processing. The record is a management tool, not a one-time filing exercise.
View the checklists →
03

Standardise evidence and controls

Assign evidence to the relevant processing activity. The key question is not how many documents exist, but whether an external reviewer can understand which decision was taken, which risk was assessed and which measure was checked.
See incident documentation →
04

The basic structure is in place

Keep the framework alive. Review it when tools, providers, responsibilities or processes change and connect it with operational teams rather than treating it as a separate privacy archive.
Classify new processing activities →
Governance building blocks

What belongs in a workable privacy framework?

The elements depend on each other. A record without ownership is as weak as a policy that nobody checks in practice.

What belongs in a workable privacy framework?
Building block Purpose Practical sign
Responsibility Assign decisions and approvals A named function can explain purpose, means and risk.
Processing record Capture processing activities and key facts Processes, recipients, retention and measures can be found.
Policies Set consistent working practices People know how to handle data, tools and requests.
Controls Check implementation and change Deviations are detected, assessed and followed up.
Evidence Make decisions traceable Risk assessments, approvals and improvements are documented.

The right level of detail depends on the size, structure, processing activities and risks of the business.

Accountability starts with management

Article 5(2) GDPR requires the controller not only to comply with the principles but also to demonstrate compliance. Article 24 requires appropriate technical and organisational measures and a review of their effectiveness. Privacy therefore becomes a management and organisational task, not an isolated IT project.

In practice, responsibility must be allocated. Who decides the purposes and means of processing? Who describes the operational process? Who reviews contracts, risks and security measures? Who decides when a new system is needed quickly? An internal responsibility matrix should answer these questions. It does not replace legal advice, but it prevents important decisions from disappearing between departments.

  • Management carries the organisational responsibility for the framework.
  • Business units describe the actual process and its purpose.
  • IT and information security explain the technical conditions.
  • A data protection officer advises and monitors where one is appointed.
  • A provider does not become a controller merely because it processes data technically.

The processing record is the map of operations

Article 30 GDPR requires many businesses to maintain a record of processing activities. Although a narrow exception may be assessed in individual cases, an up-to-date record is often an important management tool. It shows which processes exist, where data flows begin and end, and which functions participate in a processing activity.

A useful entry normally describes the purpose, categories of people and data, recipients, transfers to third countries, retention periods and general technical and organisational measures. Its quality becomes visible when something changes. When a new CRM, payroll platform or analytics tool is introduced, the process should show who triggers the review and how the record is updated.

Connect the record with a change process. Procurement, an IT ticket or a privacy review can act as a signal. The result is a living overview rather than a static spreadsheet. For external providers, the dedicated focus on processors and service providers addresses the contractual and operational detail.

Policies must support the working day

A policy is useful only if it helps people make concrete decisions. A general instruction to handle data securely does not say who approves a new SaaS tool, how an export is reviewed or when a potential breach must be escalated. Effective policies therefore connect a clear objective with an achievable action.

Typical subjects include new software, access rights, remote work, retention and deletion, data subject requests, marketing, photographs, video and the reporting of suspected breaches. Employee data also involves employment law and co-determination issues. These specific questions are addressed in the focus topic on employee data protection.

Short decision aids and targeted training can be more effective than lengthy rulebooks. Record when a policy is reviewed and which event triggers an unscheduled update.

Assess risks and follow up measures

Governance is especially important for higher-risk processing. Article 25 GDPR requires data protection by design and by default. Article 32 requires a level of security appropriate to the risk. Depending on the processing, a data protection impact assessment under Article 35 may also be required.

A risk decision should not stop at a label. Describe the processing, possible consequences for people, the assumed likelihood and the measures that reduce the risk. If a risk remains open, assign an owner, priority and next step so that the issue can be managed rather than forgotten.

A simple risk register can support ongoing management. It should connect with the processing record, security measures, contracts and incident management. In the event of a personal data breach, documentation should allow the assessment and response to be reconstructed promptly.

  • Capture new or materially changed processing activities early.
  • Check access, retention and security measures rather than only describing them.
  • Assign a priority, owner and date to each material risk.
  • Turn incident and review findings into documented improvements.

Controls make compliance credible

A governance framework does not have to be perfect before it is useful. It must show that the business checks whether its assumptions remain correct. Proportionate spot checks may cover access rights, deletion routines, provider documentation, training or entries in the processing record. The review should reflect the risk and not only the easiest documents to inspect.

Record the date, scope, result, deviation and follow-up measure. A negative finding is not a failure if it is identified and addressed. The real weakness is an asserted control that nobody can evidence or explain.

For marketing, cookies and tracking, consent records and change signals should feed into governance. The focus topic on marketing, cookies and tracking examines this particular interface.

When external support can help

External support can be useful where there are several companies, complex data flows, new technology, international providers or increased risk. Governance should also be reviewed during a reorganisation, acquisition or major IT project, not only after go-live.

For a focused review, the current processing record, organisation chart or responsibility matrix, relevant policies, provider overview, risk assessments, security concept, deletion rules and evidence of training and controls are usually helpful. These materials show whether the gap lies in responsibility, process, documentation or implementation.

The firm can review the legal classification and organisational structure together with the responsible people. This keeps the result connected to the business instead of turning it into a collection of templates with no operational owner.

Frequently asked questions

Questions businesses often ask about privacy governance

Does every business have to maintain a record of processing activities? +
Article 30 GDPR provides for a record and contains a narrow exception for certain organisations with fewer than 250 employees. Whether the conditions are met depends, among other things, on the type, regularity and risk of the processing. An up-to-date record is therefore often useful even where an exception is considered.
Who is responsible for data protection compliance? +
The controller is generally the entity that decides the purposes and means of processing. Within the business, responsibilities for the operational process, IT, security, approvals and evidence should also be assigned. A data protection officer advises and monitors where the statutory requirements for appointment are met.
How often should privacy governance be reviewed? +
There is no single review interval for every business. The appropriate rhythm depends on risk, the speed of change and the type of processing. A review should also be triggered by new tools, providers, organisational changes, security incidents or material changes to a process.
Which documents should management keep available? +
Common materials include a responsibility matrix, processing record, policies, provider overview, risk and impact assessments, security measures, deletion rules and evidence of training, controls and improvements. The actual requirements depend on the processing activities and risks of the business.

Sources

  • General Data Protection Regulation, in particular Articles 5, 24, 25, 30, 32 and 35

    Foundations for accountability, records, privacy by design, security and impact assessment.

  • Austrian Data Protection Act, in particular section 1

    The Austrian framework for the protection of personal data.

  • European Data Protection Board guidelines and recommendations

    Guidance on responsibility, privacy by design and risk-based organisation.

  • Information from the Austrian Data Protection Authority

    Practical material for controllers, processing records and impact assessments.

BRANDaktuelle Legal News

Subscribe to legal news

Receive new articles and legal information from the firm with BRANDaktuelle Legal News.

Subscribe to legal news

Discuss privacy governance for your business

We review with you how responsibilities, records, policies and evidence fit your actual processing activities.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich