Data-protection compliance starts with a map of product, customer, employee and partner data. The business must then align legal basis, contracts, security controls, retention and incident response, with current requirements rechecked before launch.
Legal support for this matter: Corporate Compliance
Map the data and the roles
List what enters the product, website, support, HR, analytics and payment flows; who collects it, decides the purpose, processes it and stores it, and in which country. One data map often reveals the real role of a vendor, group company or cloud provider.
Purpose, legal basis and transparency
Tie each data flow to a specific purpose and appropriate legal basis. Consent is not a universal answer for every activity. The privacy notice should match the actual product, and any change should be tested against a new purpose or recipient.
Security and vendors
Define access levels, authentication, logging, backups, vulnerability handling and offboarding. A vendor agreement should address instructions, confidentiality, security, sub-processors, incident notice and return or deletion of data.
Requests and data quality
Create a process to identify requests for access, correction, deletion or another action and retain a record of the response. Do not delete information needed for legal or security purposes without analysis; verify the current exception and timing for the case.
Incidents, retention and the audit file
After an incident, preserve logs and facts, contain harm, identify who must be notified and do not rewrite records to create a later explanation. Maintain a retention schedule, access log, training record, risk assessment and vendor controls, and update the program as the product changes.
Important noteThis material is general information, not personalised legal advice. Recheck current law, official practice, fees and deadlines against your facts before acting.