Skip to content

Dataprotection Management

The EU General Data Protection Regulation (GDPR) has imposed high requirements on the handling of personal data since 2018. Organizations must not only work in compliance with data protection regulations, but also demonstrably document this. This is exactly where the Data Protection Management System (DPMS) of the fuentis Suite 4 comes in: It offers a structured, software-supported solution for managing all data protection-relevant processes.

The DPMS module is an integral component of the fuentis Suite 4 (codename Phoenix) and works seamlessly with other modules such as ISMS, BCMS, and Incident Management. This integration enables a holistic governance strategy where data protection is not considered in isolation, but in the context of overall information security.


1. Register of Processing Activities (RoPA)

Section titled “1. Register of Processing Activities (RoPA)”

The Register of Processing Activities (RoPA) forms the heart of the DPMS. It documents all processing activities of personal data in your organization in accordance with Art. 30 GDPR.

Structural Setup:

  • RoPA (main level): Represents the entire register of an organizational unit
  • Processing Activities (PAs): Individual processing activities within the RoPA
  • Hierarchical Organization: Each entity (organizational unit) can maintain its own RoPA

Documented Information per Processing Activity:

  • Processing purposes and legal bases
  • Categories of data subjects and data
  • Recipient categories (incl. third country transfers)
  • Deletion periods and retention duration
  • Responsible departments and contact persons

VVT

2. Technical and Organizational Measures (TOMs)

Section titled “2. Technical and Organizational Measures (TOMs)”

TOMs are essential security precautions for protecting personal data. The DPMS distinguishes between:

Levels of TOM Application:

  • Global TOMs: At RoPA level (apply to all subordinate processing activities)
  • Specific TOMs: Related to individual processing activities

TOM Categorization by Protection Goals:

  • Confidentiality: Access control, encryption, pseudonymization
  • Integrity: Input control, transfer control, data carrier destruction
  • Availability: Backup concepts, emergency plans, recovery procedures
  • Resilience: Penetration tests, monitoring, incident response

Practical TOM Library: The DPMS offers a predefined library with best-practice TOMs based on:

  • Standard Data Protection Model (SDM)
  • General Data Protection Regulation (GDPR)

TOMs

Contract Management includes:

  • Data Processors: External service providers who process data on behalf
  • Joint Controllers: Partners with shared data responsibility
  • Data Transfers: Documentation of third country transfers incl. safeguards

Automated Compliance Checks:

  • Contract terms and termination periods
  • Updates of Standard Contractual Clauses (SCC)
  • Monitoring of adequacy decisions

Integration with Incident Management: Data breaches are initially recorded in the Incident Management System (IMS) and transferred to the DPMS when relevant.

72-Hour Notification Obligation Management:

  • Automatic deadline calculation from awareness
  • Escalation mechanisms for critical incidents
  • Templates for supervisory authority notifications

Risk Assessment according to GDPR Criteria:

  • Type of data concerned (special categories acc. to Art. 9 GDPR)
  • Number of affected persons
  • Possible consequences for data subjects
  • Remedial measures taken

Sicherheitsvorfall

1. Initial Inventory:

  • Creation of RoPA structure per entity/tenant
  • Import of existing processing registers (Excel/CSV)
  • Mapping to business processes from Asset Management

2. Continuous Maintenance:

  • Regular reviews by data protection officers
  • Updates for process changes
  • Versioning and change history

3. Compliance Evidence:

  • Generation of GDPR-compliant reports
  • Audit trails for audits
  • Dashboard visualizations for management

ISMS-DPMS Synergy:

  • TOMs from the ISMS can be referenced as data protection measures
  • Joint risk assessment for information security and data protection
  • Unified controls for ISO 27001 and GDPR

BCMS Integration:

  • Recovery times for critical data processing
  • Emergency plans for data breaches
  • Business impact analysis under data protection aspects

Asset Management Linkage:

  • Automatic assignment of IT systems to processing activities
  • Hardware lifecycle and data deletion
  • Location-based data protection requirements

Verbunden mit Assetmanagement


Practice Tip: Step-by-Step Implementation

Start with critical processing activities (HR, customer data, health data) and expand gradually. Use the prioritization function by risk and data volume.

Efficiency Gains through:

  • Predefined templates for standard processing activities
  • Bulk import/export functions
  • Automatic linking of similar TOMs
  • AI-supported suggestions for legal bases

Multi-Stakeholder Approach:

  • Departments: Record their processing activities
  • IT Department: Documents technical TOMs
  • Data Protection Officers: Review and approve
  • Management: Receives aggregated compliance dashboards

PDCA Cycle in Data Protection:

  • Plan: Conduct data protection impact assessments
  • Do: Implement and document TOMs
  • Check: Regular audits and reviews
  • Act: Adjust and optimize measures

Available Report Types:

  1. Processing Register (Art. 30 GDPR-compliant)
  2. TOM Overview by protection goal and status
  3. Partner Register with contract status
  4. Data Breach Log for supervisory authorities
  5. Audit Trail for internal/external audits
  1. Holistic Approach: The DPMS is not an isolated solution, but deeply integrated into the fuentis Suite 4. Data protection is considered in the context of information security (ISMS), business continuity (BCMS), and incident management.

  2. GDPR Compliance by Design: All functions are aligned with the requirements of the GDPR and international data protection standards – from processing documentation through TOM management to breach notification.

  3. Scalability: Whether small organization with few processing activities or corporation with hundreds of companies – the DPMS adapts flexibly through its multi-tenant architecture.

  4. Practice Orientation: Predefined templates, best-practice TOMs, and automated workflows significantly reduce implementation effort and enable quick successes.

  5. Future-Proofing: Through open APIs, continuous updates, and integration of new compliance requirements, the DPMS remains current even with changing regulatory frameworks.


DPMS: Data Protection Management System

RoPA: Register of Processing Activities

PA: Processing Activity - Individual processing activity

TOM: Technical and Organizational Measure - Security precaution for data protection

Data Breach: Data protection violation - Security incident involving personal data

DPO: Data Protection Officer

DPIA: Data Protection Impact Assessment

Joint Controller: Shared data responsibility

Processor: Data processor - External service provider

SDM: Standard Data Protection Model - German reference model for data protection

Multi-Tenancy: Ability to isolate data between organizational units