Auteurs

Dr. Axel Frhr. von dem Bussche, LL.M. (L.S.E.), CIPP/E

Associé

Read More

Dr. Paul Voigt, Lic. en Derecho, CIPP/E

Associé

Read More
Auteurs

Dr. Axel Frhr. von dem Bussche, LL.M. (L.S.E.), CIPP/E

Associé

Read More

Dr. Paul Voigt, Lic. en Derecho, CIPP/E

Associé

Read More

19 août 2020

Data protection compliance – Global project steering

  • Quick Read

In order to keep efforts and costs down, global enterprises often implement "one size fits all" uniform solutions on a worldwide level (eg HR data systems, compliance policies, cyber security, use of centrally provided shared services etc). Due to different legal standards in various countries, such worldwide implementation often leads to frictions regarding local law and culture.

Depending on the specific project, a classification into the following phases may be helpful in rollouts relating to data protection.

Analysis Phase: Shaping the project

  • Collecting relevant facts and shaping the result desired by the client.
  • Allocating involved jurisdictions and local counsels (tailored legal network).
  • Legal analysis: How can the desired global implementation be justified with minimum local alterations (pragmatic business-oriented approach).
  • Shaping uniform paperwork for implementation (global template), including:
    • summary of facts and legal analysis for local counsels
    • questionnaire for local counsels
    • suggestion for a compliant master solution.

Rollout Phase: Collecting "add on" input from local counsels

  • Global rollout of "global template" to local counsels:
    • pragmatic approach – in order to keep costs down, local counsels may only suggest amendments to the global template where strictly required by local laws
    • fixed fee for work of local counsels, where appropriate
    • fixed deadline for work of local counsels, where appropriate.
  • Follow-up communication with local counsels (including follow-up communication) if the desired result was not achieved yet.
  • Summary of local implementation risks/local to-dos.
  • Step plan for implementation, including local to-dos.

Rollout Phase: Collecting "add on" input from local counsels

  • Internal and external steering of implementation requirements.
  • Implementation of local to-dos according to "implementation step plan":
    • local authority filings
    • preparation and conclusion of contracts
    • collection of consent declarations
    • draft of notices to employees and contract partners
    • "shaping" of the implementation according to local requirements/standard.

Please click here to download the article as PDF file.

Call To Action Arrow Image

Latest insights in your inbox

Subscribe to newsletters on topics relevant to you.

Subscribe
Subscribe

Related Insights

Technologie, Médias et Communications (TMC)

NIS 2 Implementation and Cybersecurity Strengthening Act: Germany tightens IT security requirements

Paul Voigt and Alexander Schmalenberger look at Germany's progress on NIS2 implementation.

4 septembre 2023

par Dr. Paul Voigt, Lic. en Derecho, CIPP/E et Alexander Schmalenberger, LL.B.

Cliquer ici pour en savoir plus
Protection des données et cybersécurité

China: A practical insight into China SCCs and their impact on businesses

Michael Tan, Julian Sun, Paul Voigt and Wiebke Reuter look at what China's new SCCs mean for businesses looking to export personal data from China to the EU.

24 avril 2023
In-depth analysis

par plusieurs auteurs

Cliquer ici pour en savoir plus
Protection des données et cybersécurité

Cyber Incident Response and Data Breach Notification (Germany)

8 mars 2023
In-depth analysis

par Dr. Paul Voigt, Lic. en Derecho, CIPP/E

Cliquer ici pour en savoir plus