Answer first

Data-protection compliance starts with a map of product, customer, employee and partner data. The business must then align legal basis, contracts, security controls, retention and incident response, with current requirements rechecked before launch.

Legal support for this matter: Corporate Compliance

Map the data and the roles

List what enters the product, website, support, HR, analytics and payment flows; who collects it, decides the purpose, processes it and stores it, and in which country. One data map often reveals the real role of a vendor, group company or cloud provider.

Purpose, legal basis and transparency

Tie each data flow to a specific purpose and appropriate legal basis. Consent is not a universal answer for every activity. The privacy notice should match the actual product, and any change should be tested against a new purpose or recipient.

Security and vendors

Define access levels, authentication, logging, backups, vulnerability handling and offboarding. A vendor agreement should address instructions, confidentiality, security, sub-processors, incident notice and return or deletion of data.

Requests and data quality

Create a process to identify requests for access, correction, deletion or another action and retain a record of the response. Do not delete information needed for legal or security purposes without analysis; verify the current exception and timing for the case.

Incidents, retention and the audit file

After an incident, preserve logs and facts, contain harm, identify who must be notified and do not rewrite records to create a later explanation. Maintain a retention schedule, access log, training record, risk assessment and vendor controls, and update the program as the product changes.