Skip to content

GDPR and information security in practice

How you start your day right

The General Data Protection Regulation — better known as GDPR — and the Danish Data Protection Act are not just something lawyers deal with. They set the daily framework for how you as an office worker may collect, use and store information about people. The better you understand the principles, the easier it is to make the right decisions in a busy day.

§The basic principles you work by

GDPR is built on some central principles that recur in almost every task: data minimization (you may only collect the information you really need), purpose limitation (data may only be used for the purpose it was collected for) and storage limitation (data must be deleted when the purpose is fulfilled). Furthermore, the data subject — the person the information concerns — has a number of rights: right of access, right to rectification of incorrect information and under certain conditions right to have information deleted.

  • 01Data minimization: collect only what the task requires
  • 02Purpose limitation: only use data for the original purpose
  • 03Storage limitation: delete data when the purpose is fulfilled
  • 04The registered person's rights: access, correction and deletion

§If something goes wrong: breach of personal data security

If there is a breach of personal data security — for example an email with personal information sent to the wrong recipient or a lost USB stick with a personnel register — there are clear rules for what should happen. According to Article 33 of the data protection regulation the data controller must notify the Data Authority of the breach without undue delay and if possible no later than 72 hours after the company becomes aware of it. If the notification occurs later than 72 hours it must be accompanied by an explanation of the delay. The exception is if it is unlikely that the breach poses a risk to the rights of the affected individuals.

§Documentation obligation always applies

Regardless of whether a breach must be reported to the Data Protection Authority or not, the company has a duty to document all breaches of personal data security — what happened, what consequences it had, and what measures were put in place. That documentation must make it possible for the Data Protection Authority to check whether the rules have been complied with. As a student, your task is to know the procedure at your workplace: who do you inform if you discover an error?

§Information security in daily practice

Good data protection is as much about habits as about law. Lock your screen when you leave your desk. Never send sensitive information such as CPR numbers or health data in a plain, unencrypted email if a secure solution exists. Be critical of calls or emails asking for personal information — they can be phishing attempts or social engineering, where someone is trying to get access or data from you by impersonating someone else.

SituationRiskYour action
Mail med CPR-nummerData falls into the hands of unauthorized personsUse encrypted/secure transmission
Suspicious email about loginPhishing attemptDo not click — contact IT or nearest manager
Unlocked screen at lunchUnauthorized parties see dataLås skærmen, hver gang du rejser dig
Possible data breach detectedMissing notification within 72 hoursReport it to the responsible party immediately

Data protection is not a one-time task for a lawyer — it is a habit you build from your first day in the office.