© Copyright Acquisition International 2025 - All Rights Reserved.

Article Image - Data Protection by Design and Default
Posted 29th July 2024

Data Protection by Design and Default

The very thought of keeping up-to-date with new regulations, cyber threats and improving data protection can send shivers down the spines of companies across all sectors. Such is the threat and the sheer number of ways that personal data can be compromised, that aligning data protection across an organisation is often no small task.

Mouse Scroll AnimationScroll to keep reading

Let us help promote your business to a wider following.

Data Protection by Design and Default
Data protection

Data Champions can implement technology that can help DPOs manage data and protection simply and effectively

Mark Roebuck, DPO and Founder of ProvePrivacy

The very thought of keeping up-to-date with new regulations, cyber threats and improving data protection can send shivers down the spines of companies across all sectors. Such is the threat and the sheer number of ways that personal data can be compromised, that aligning data protection across an organisation is often no small task.

Of course, data protection is not just about the threat from cybercriminals but also compliance obligations, weak controls, internal mistakes and system errors. There is also the risk of implementing new practices where protecting personal data is not considered adequately. For those companies that hold particularly sensitive data, the task is all the more challenging as the risk to data subjects can be considered higher making the landscape in which they sit complex and ever-changing.

The role of the Data Protection Officer

All companies are now data-driven in some form or another with huge amounts of data residing in systems. Therefore, the role of the Data Protection Officer (DPO) within companies has grown in importance over the past decade. DPOs have significant responsibilities and a huge range of tasks in front of them, but the main one is to ensure that practices and policies that protect personal data are implemented across all departments and functions.

For many organisations the DPO position is mandated by articles 37, 38 and 39 of GDPR regulations. As well as being responsible for advising on how to protect privacy, DPOs must also ensure that organisations can evidence compliance with data protection regulation and that they don’t fall foul of other aspects of GDPR relating to transparency, accountability and accuracy.

In the event of a serious incident, data breach or complaint, DPOs will act for the data subject and as an intermediary between the organisation and the data protection regulator such as the Information Commissioner’s Office (ICO). They are also the go-to person when problems relating to data privacy occur within the organisation.

‘Data protection by design and default’

It is clear therefore, that DPOs have a wide range of tasks spanning the whole of the organisation.  One of the main elements is to ensure that practices and policies that protect data are implemented in every department.  One behaviour which can very much help the DPO in this regard is the implementation of ‘data protection by design and default’. This essentially ensures that any system, service, product and/or business practice is designed with the protection of personal data as a default consideration.

The DPO is consulted at all stages of the implementation of a process, which means that systems are developed where data remains protected without the individual having to change or do anything. It also means that data protection is weaved through everyday business processes. The ‘default’ nature of this means that once a procedure or system is implemented staff can rest assured that data is protected making their task somewhat easier.

It is no longer effective to have one individual sitting above multiple departments

‘Data protection by design and default’ is a fundamental project requirement within UK GDPR data protection legislation. It requires a risk assessment of all data protection and processing activities to be performed at the conception and design stage of a project and throughout the entire project lifecycle, as well as when procedures, data sources or contracts with data processors change.

However, for the DPO implementing this across multiple departments and untold numbers of systems is difficult. They may not have the right level of knowledge to effectively implement this in every specific system.

In too many organisations the DPO is considered by the rest of the company as the first line of defence concerning the protection of personal data and they are expected to act accordingly.  The issue though is that the DPO does not own the data or the procedures.

The threat to personal data from cybercriminals as well as the individual complexities within particular departments means that it is not effective to have one individual sitting above multiple departments implementing a generalised approach.

Turning to Data Champions

Instead, companies should be devolving responsibility for data protection to ‘Data Champions’ within departments, ensuring that the data owners themselves are the first line of defence. This means that there is specific expertise and knowledge of the nuances of systems and approaches within departments.  It also means that departments are equipped to build in data protection by design, when change is being affected and the DPO can remain in an advisory capacity.

The appointment of Data Champions means that there is a better chance of finding specific vulnerabilities that might be missed by a DPO sitting above. The DPOs role is still critical as they will be ultimately responsible for providing advice but the responsibility for personal data remains within specific touchpoints/individual departments of the business.

The Data Champion has a greater understanding of the department’s need for personal data, how it is used and how it can be protected by default. By putting Data Champions in place data protection by design and by default becomes easier to achieve.

Data Champions can help DPOs manage data and protection effectively

The introduction of Data Champions can be more effective with the implementation of supporting technology that can help DPOs build a Record of Processing Activities to gain a holistic view of data allowing them to more simply and effectively monitor and manage data protection. Identifying data protection risks, maintaining policies and procedures and providing colleagues, with training that allows them to better understand the threats and vulnerabilities can all be implemented with one, simple to use, platform.

Categories: Innovation, News


You Might Also Like
Read Full PostRead - Eye Icon
Focus Starts 2016 Strong by Helping its Partner Firms Close Three Mergers
M&A
25/01/2016Focus Starts 2016 Strong by Helping its Partner Firms Close Three Mergers

Focus Financial Partners (‘Focus’) today announced the closing of merger deals for three of its partner firms – Benefit Funding Services Group, Bridgewater Wealth & Financial Management and Buckingham Asset Management. The Focus partner firms are poised

Read Full PostRead - Eye Icon
Why Remortgaging is a Game-changer For Modern Home-owners
Finance
22/01/2021Why Remortgaging is a Game-changer For Modern Home-owners

In the UK, whilst the numbers can fluctuate, roughly 39,000 remortgages occur on a monthly basis. In fact, in the first quarter of 2019, almost 40% of property loans were remortgages - with good reason. Getting on the property ladder is usually one of the main

Read Full PostRead - Eye Icon
Innovative Bites Acquires Hancocks
M&A
13/04/2017Innovative Bites Acquires Hancocks

Confectionery powerhouse Innovative Bites has today, Wednesday 12 April 2017, acquired Hancocks Holdings, the UK’s leading supplier of wholesale sweets, from H2 Equity Partners and management.

Read Full PostRead - Eye Icon
The Main Differences Between Sole Proprietorships & S-Corps
M&A
01/11/2021The Main Differences Between Sole Proprietorships & S-Corps

One of the biggest decisions a self-employed freelancer turned business owner has to make is deciding what type of business entity works best for them. If you’re the only owner of your company, your options often narrow down to two: an S-Corp or sole proprie

Read Full PostRead - Eye Icon
Four Reasons To Get Law Enforcement Transcription Service
News
28/09/2023Four Reasons To Get Law Enforcement Transcription Service

Many think that law enforcement transcription is another small, inconsequential cog in the American Criminal Justice System. It’s a requirement in certain instances, optional in others, and, in some cases, can completely be eschewed. However, many fail to re

Read Full PostRead - Eye Icon
Handling Fleet Accidents: A Field Guide For Managers & Operators
Leadership
05/01/2023Handling Fleet Accidents: A Field Guide For Managers & Operators

Accidents are a part and parcel of managing a large and active fleet, and is something that fleet managers and operators should be ready for at all times.

Read Full PostRead - Eye Icon
Maximizing ROI: How SharePoint Consultants Drive Business Value
News
19/02/2024Maximizing ROI: How SharePoint Consultants Drive Business Value

SharePoint, developed by Microsoft, is a powerful platform designed to facilitate collaboration, document management, and information sharing within organizations. While the platform offers a plethora of features and capabilities, maximizing its return on inve

Read Full PostRead - Eye Icon
HRG Group, Inc. Announces Armored AutoGroup Acquisition By Spectrum Brands
M&A
30/04/2015HRG Group, Inc. Announces Armored AutoGroup Acquisition By Spectrum Brands

HRG Group, Inc., a diversified holding company focused on owning and acquiring businesses that it believes can, in the long term, generate sustainable free cash flow or attractive returns on investment, announced that its majority owned subsidiary, Spectrum Br

Read Full PostRead - Eye Icon
Linxens Acquires Smartrac’s Secure ID & Transaction
Finance
07/11/2016Linxens Acquires Smartrac’s Secure ID & Transaction

Acquisition marks a transformational step in the development of Linxens Diversifies its product range in RFID antennas and inlays The new group will generate more than €500 million in revenue and employ 3,500 people worldwide



Our Trusted Brands

Acquisition International is a flagship brand of AI Global Media. AI Global Media is a B2B enterprise and are committed to creating engaging content allowing businesses to market their services to a larger global audience. We have 14 unique brands, each of which serves a specific industry or region. Each brand covers the latest news in its sector and publishes a digital magazine and newsletter which is read by a global audience.

Arrow