GDPR in IT operations — what data protection means in your day-to-day
Personal data, processing basis, security and breach — inserted into IT work
Almost all IT work touches personal data: user accounts, log files, email, camera footage, backups. The Data Protection Regulation – in everyday language GDPR (General Data Protection Regulation) – is an EU regulation that applies directly in Denmark and is supplemented by the Danish data protection law. It applies as soon as you process information about identifiable people, and 'processing' covers almost everything: collect, store, display, change, share and delete. As a technician you are rarely the data controller, but you are the one who in practice sets up the security – so the rules affect your work every day.
§The underlying principles
The regulation is built on some basic principles you can use as check questions every time a system handles personal data. They fundamentally deal with only processing what is necessary for a clear purpose safely and not longer than necessary.
- 01Legality and correct mechanism
- 02Purpose limitation: data collected for one purpose cannot simply be reused for another
- 03Data minimization: collect and store only what the task actually requires
- 04Accuracy: information must be kept correct and up to date
- 05Storage limitation: delete data when the purpose is fulfilled — don't save 'for safety's sake'
- 06Integrity and confidentiality: data must be protected against unauthorized access, loss and modification
- 07Responsibility: you must be able to document that you comply with the rules
§Treatment basis and special categories
You must not process personal data just because it is convenient — there must be a legal basis for processing. This could be an agreement with the person, a legal obligation, a legitimate interest or consent. Certain information is particularly sensitive — e.g. health, trade union membership, race, religion and biometric data used for identification — and is surrounded by heightened requirements. As a technician, the point is: know what data a system contains, because sensitive data require stronger protection than an ordinary name and an email address.
§Data controller and data processor
The data controller determines the purpose and means of processing — typically the company you work in or for. A data processor processes data on behalf of the data controller — it is e.g. a supplier of a cloud service. When data is placed with an external supplier, there must be a data processor agreement that binds the supplier to protect data and only process it as instructed. If you choose or recommend a service, it's important to check whether that agreement is in place and where the data is physically located.
§Technical and organizational measures
The regulation requires a security level that matches the risk but deliberately does not mention specific products or numerical values — it must be adapted to how sensitive the data is and what could go wrong. In practice it is the same tools you know from IT security: access control based on least privilege encryption of sensitive data and portable devices encryption of data during transport logging of access system updates and tested backups. The new part is the requirement to be able to document that reasonable choices have been made.
§The registered person's rights
People whose data is processed have rights that IT often needs to help fulfil in practical terms: the right to insight into what data exists, the right to have incorrect information corrected, the right to have data deleted in certain cases, and the right to have your data delivered in a usable format. A system should be built so that you can actually find, correct, deliver and delete a specific person's data — if you can't, the rights become difficult to fulfil.
§When a fracture occurs
A breach of personal data security is when data is accidentally destroyed lost changed or becomes known to unauthorised persons — e.g. a stolen laptop an incorrectly sent email with personal information or a hacking attack. A breach must generally be reported to the Data Protection Authority within a fixed deadline and if it poses high risk to individuals they must be notified themselves. That is why it is crucial that you as a technician can quickly discover and document a breach — it is one of the reasons logging and monitoring are non-negotiable.
“The Danish Data Protection Authority is the Danish authority that oversees compliance with the rules. As a technician, you don't need to be a lawyer — but you must be able to recognize when an issue is a data protection matter and who to notify.”
— Professional basic rule in IT operations with personal data.