Compliance and privacy governance
Organise responsibilities, processing records, policies and evidence so that data protection can be managed in daily business.
Mag. Bernhard Brandauer, Rechtsanwalt
BRANDAUER Rechtsanwälte
Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.
Privacy governance is the organisational framework in which a business takes responsibility for processing personal data. It includes clear roles, an up-to-date record of processing activities, suitable policies and evidence showing how risks and controls are handled.
The focus is not a general explanation of the GDPR or a detailed treatment of individual data subject rights. It is the practical question of how management, business units, IT, HR, marketing and external providers work together so that data protection decisions are not left to chance.
The review of processors and service providers, the handling of personal data breaches and employee data raise distinct questions. A sound governance framework connects them without treating them as one undifferentiated checklist.
Written by Mag. Bernhard Brandauer, Rechtsanwalt
Where does your privacy governance stand?
Answer three short questions. The result indicates which organisational gap should be addressed first.
Are data protection responsibilities clearly assigned in the business?
This means more than job titles. It includes concrete responsibility for decisions, approvals and evidence.
Ihre Orientierung
Bring the record up to date
Standardise evidence and controls
The basic structure is in place
What belongs in a workable privacy framework?
The elements depend on each other. A record without ownership is as weak as a policy that nobody checks in practice.
| Building block | Purpose | Practical sign |
|---|---|---|
| Responsibility | Assign decisions and approvals | A named function can explain purpose, means and risk. |
| Processing record | Capture processing activities and key facts | Processes, recipients, retention and measures can be found. |
| Policies | Set consistent working practices | People know how to handle data, tools and requests. |
| Controls | Check implementation and change | Deviations are detected, assessed and followed up. |
| Evidence | Make decisions traceable | Risk assessments, approvals and improvements are documented. |
The right level of detail depends on the size, structure, processing activities and risks of the business.
Accountability starts with management
Article 5(2) GDPR requires the controller not only to comply with the principles but also to demonstrate compliance. Article 24 requires appropriate technical and organisational measures and a review of their effectiveness. Privacy therefore becomes a management and organisational task, not an isolated IT project.
In practice, responsibility must be allocated. Who decides the purposes and means of processing? Who describes the operational process? Who reviews contracts, risks and security measures? Who decides when a new system is needed quickly? An internal responsibility matrix should answer these questions. It does not replace legal advice, but it prevents important decisions from disappearing between departments.
- Management carries the organisational responsibility for the framework.
- Business units describe the actual process and its purpose.
- IT and information security explain the technical conditions.
- A data protection officer advises and monitors where one is appointed.
- A provider does not become a controller merely because it processes data technically.
The processing record is the map of operations
Article 30 GDPR requires many businesses to maintain a record of processing activities. Although a narrow exception may be assessed in individual cases, an up-to-date record is often an important management tool. It shows which processes exist, where data flows begin and end, and which functions participate in a processing activity.
A useful entry normally describes the purpose, categories of people and data, recipients, transfers to third countries, retention periods and general technical and organisational measures. Its quality becomes visible when something changes. When a new CRM, payroll platform or analytics tool is introduced, the process should show who triggers the review and how the record is updated.
Connect the record with a change process. Procurement, an IT ticket or a privacy review can act as a signal. The result is a living overview rather than a static spreadsheet. For external providers, the dedicated focus on processors and service providers addresses the contractual and operational detail.
Policies must support the working day
A policy is useful only if it helps people make concrete decisions. A general instruction to handle data securely does not say who approves a new SaaS tool, how an export is reviewed or when a potential breach must be escalated. Effective policies therefore connect a clear objective with an achievable action.
Typical subjects include new software, access rights, remote work, retention and deletion, data subject requests, marketing, photographs, video and the reporting of suspected breaches. Employee data also involves employment law and co-determination issues. These specific questions are addressed in the focus topic on employee data protection.
Short decision aids and targeted training can be more effective than lengthy rulebooks. Record when a policy is reviewed and which event triggers an unscheduled update.
Assess risks and follow up measures
Governance is especially important for higher-risk processing. Article 25 GDPR requires data protection by design and by default. Article 32 requires a level of security appropriate to the risk. Depending on the processing, a data protection impact assessment under Article 35 may also be required.
A risk decision should not stop at a label. Describe the processing, possible consequences for people, the assumed likelihood and the measures that reduce the risk. If a risk remains open, assign an owner, priority and next step so that the issue can be managed rather than forgotten.
A simple risk register can support ongoing management. It should connect with the processing record, security measures, contracts and incident management. In the event of a personal data breach, documentation should allow the assessment and response to be reconstructed promptly.
- Capture new or materially changed processing activities early.
- Check access, retention and security measures rather than only describing them.
- Assign a priority, owner and date to each material risk.
- Turn incident and review findings into documented improvements.
Controls make compliance credible
A governance framework does not have to be perfect before it is useful. It must show that the business checks whether its assumptions remain correct. Proportionate spot checks may cover access rights, deletion routines, provider documentation, training or entries in the processing record. The review should reflect the risk and not only the easiest documents to inspect.
Record the date, scope, result, deviation and follow-up measure. A negative finding is not a failure if it is identified and addressed. The real weakness is an asserted control that nobody can evidence or explain.
For marketing, cookies and tracking, consent records and change signals should feed into governance. The focus topic on marketing, cookies and tracking examines this particular interface.
When external support can help
External support can be useful where there are several companies, complex data flows, new technology, international providers or increased risk. Governance should also be reviewed during a reorganisation, acquisition or major IT project, not only after go-live.
For a focused review, the current processing record, organisation chart or responsibility matrix, relevant policies, provider overview, risk assessments, security concept, deletion rules and evidence of training and controls are usually helpful. These materials show whether the gap lies in responsibility, process, documentation or implementation.
The firm can review the legal classification and organisational structure together with the responsible people. This keeps the result connected to the business instead of turning it into a collection of templates with no operational owner.
Questions businesses often ask about privacy governance
Does every business have to maintain a record of processing activities? +
Who is responsible for data protection compliance? +
How often should privacy governance be reviewed? +
Which documents should management keep available? +
Sources
- General Data Protection Regulation, in particular Articles 5, 24, 25, 30, 32 and 35
Foundations for accountability, records, privacy by design, security and impact assessment.
- Austrian Data Protection Act, in particular section 1
The Austrian framework for the protection of personal data.
- European Data Protection Board guidelines and recommendations
Guidance on responsibility, privacy by design and risk-based organisation.
- Information from the Austrian Data Protection Authority
Practical material for controllers, processing records and impact assessments.
Related topics
Governance connects several privacy areas. These topics provide a deeper look at individual processes.
BRANDaktuelle Legal News
Subscribe to legal news
Receive new articles and legal information from the firm with BRANDaktuelle Legal News.
Subscribe to legal newsDiscuss privacy governance for your business
We review with you how responsibilities, records, policies and evidence fit your actual processing activities.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000