Datenschutz und Informationsschutz

← Implement regulatory requirements securely

Data protection & information protection

Protect personal and sensitive information with clear rules, effective controls and an operable model.

Data protection primarily answers whether and under what conditions personal data may be processed. Information protection ensures that data – personal or business critical – remains appropriately classified, accessible, protected and available. Both come together in data flows, access rights, technical and organisational measures (TOMs) and traceable operating processes.

Relationship to services and technologies

Datenschutz und Informationsschutz

The focus is on protection needs, control objectives and evidence. Specific Microsoft technologies and their introduction are in Technology context and at IT Security & Compliance described.

Background

Data now resides in specialist applications, email, collaboration and cloud services. Without a common picture of data types, responsibilities and protection needs, approvals on demand, unclear filings and exceptions that are difficult to check arise. Pure guidelines won't solve this; nor does a product replace the professional decision about the purpose, legal basis or need for protection.

Technical context

Abstrakte Illustration: Shield/Check und Dokumente in Blau.

The GDPR is the data protection framework for personal data. Information protection also considers the confidentiality, integrity and availability of all relevant information. TOMs combine both perspectives: They translate risks into organisational and technical protective measures. The concrete IT and cloud practice is covered GDPR in IT and cloud; the structure of the technical and organisational measures and Datenklassifizierung & Purview are standalone in-depth topics.

Typical starting questions

Which cloud processing, service providers and data flows need to be clarified?

Relevant in-depth topic: GDPR in IT and cloud

How are TOMs documented and checked in a risk-oriented manner?

Relevant in-depth topic: Technical and organisational measures

How to classify and protect data in Microsoft 365?

Relevant in-depth topic: Data classification and Microsoft Purview

What companies need to clarify specifically

Managementteam trifft nachvollziehbare Entscheidungen in einem IT-Projekt anhand gemeinsamer Informationen.
  • Which data, processing and information values are particularly in need of protection.
  • Who is responsible for data, classifies it, releases it and decides exceptions.
  • What access is required and how it is regularly checked.
  • How retention, deletion, transfer and recovery are implemented in practice.
  • Which protocols, configurations and processes demonstrate the measures.

From requirements to implementation

Protection requirements

Risk: incorrect treatment of data
Organisational measure: Classification model and owner
Technical implementation: Labels and appropriate protection rules
Possible evidence: Data classification, approvals

Access

Risk: Unauthorized insight
Organisational measure: Role and recertification process
Technical implementation: strong registration, needs-based permissions
Possible evidence: Access Reviews, Protocols

Data sharing

Risk: Data leakage
Organisational measure: Internal and external sharing rules
Technical implementation: DLP and release controls
Possible evidence: Policies, incident reports

Availability

Risk: Data loss or failure
Organisational measure: Restart and testing processes
Technical implementation: Backup, recovery, monitoring
Possible evidence: Test and operating evidence

Limitations and dependencies

Abstrakte Illustration: Dokumente, DSGVO/Compliance und Checkmark in Blau.

ADIUMENTO does not provide any data protection legal advice and does not make a binding assessment of any legal basis or individual case. Such questions are clarified by the responsible data protection officers and legal advisors. The technical implementation requires reliable data responsibility, processes and the participation of the specialist departments.

Orientation

Frequently asked questions

Is Microsoft Purview enough for data protection?

Purview can support information protection and compliance functions. It does not replace data protection assessment, a classification model, clear roles and continuous maintenance.

Which action has priority first?

Transparency often comes first: relevant data flows, protection needs and access. Only then can technical controls be selected and prioritised sensibly.

Next sensible step

Abstrakte Illustration: Shield/Check und Dokumente in Blau.

Start a joint technical inventory with those responsible for data protection: record data, access, protection needs and open control questions for a defined area. Offers the appropriate implementation framework IT Security & Compliance.