Data protection as part of the HSEE project organisation
Digital HSEE processes create transparency, but they often process personal information. ADLER HSEE Xperts therefore considers data protection and data security as early as the design of onboarding, access, attendance management, action tracking and reporting.
Data needs, purpose, roles, access, retention periods and security measures are defined together. The data protection officer is involved early. This creates a traceable process that brings together technical benefit and the protection of personal data.
Data protection from the outset
Data protection is not added afterwards. Purpose limitation, data minimisation, transparency, storage limitation as well as data protection by design and by default are considered as early as process and system planning. Access rights follow the defined tasks; data security is guided by the nature, scope and risk of the processing.
Roles and responsibilities
Before a specific implementation, it is clarified who is the controller, joint controller or processor. Depending on the contract and system landscape, these roles can sit with ADLER, with clients or with other parties involved. Responsibility is therefore not attributed to one party across the board.
The role of the data protection officer
The data protection officer advises and monitors data-protection-relevant processes within the scope of their statutory tasks. They are properly and early involved, but do not replace the responsibility of the respective controller or processor. Where a high risk is likely, it is examined whether a data protection impact assessment is required.
Project principles
- process only the data required, for defined and legitimate purposes
- inform data subjects clearly about the processing
- document roles, legal bases, recipients and processing arrangements
- design authorisations, transfer, storage, safeguarding and deletion in a risk-appropriate way
- provide for particularly sensitive data only after a separate legal and security assessment
- handle data protection incidents through defined notification and assessment processes
- involve the data protection officer in relevant planning, changes and reviews
Frequently asked questions
How does ADLER take the GDPR into account in HSEE projects?
ADLER aligns data-protection-relevant processes with the GDPR principles, documents data flows and roles and considers appropriate technical and organisational measures. The specific legal assessment depends on the respective project and processing operation.
When is the data protection officer involved?
The data protection officer is involved early when HSEE processes, systems or changes affect the protection of personal data. They advise and monitor within the scope of their statutory tasks.
Does involving the data protection officer amount to a compliance guarantee?
No. The data protection officer supports and monitors. Responsibility under data protection law remains with the respective designated controllers and processors.