Since the introduction of the new General Data Protection Regulation (GDPR) in May 2018, uncertainty still prevails in many companies. On the one hand, this is due to the fact that case law on the GDPR is often still lacking – keyword landmark rulings – and on the other hand, it is due to the scope and form of the documentation that the GDPR demands – mostly in a rather unspecific way – from companies.

catworkx has decided to take a collaborative approach to implementation in-house, using Jira and Confluence, which also views data protection as a living process. The data protection management system (DSMS) developed in this way not only maps the required documentation structures of the GDPR, it also enables the greatest possible transparency of responsibilities for data protection in a company.

Overview of details

The requirements

  • DSMS Configuration
  • Jira Core (Atlassian)
  • Teamworkx Issue Picker for Jira (catworkx)
  • Teamworkx Issue Publisher for Jira (catworkx)

Information and registration system

  • Jira Service Management (Atlassian, optional)
  • JSU Suite Utilities for Jira (beecom)
  • Autowatch for Jira (Mohami)

Confluence Space Template (Verfahrensdokumentation)

  • Confluence (Atlassian)
  • Scroll PDF Exporter for Confluence (K15t, optional)
  • Table Filter and Charts for Confluence (StiltSoft)

The benefit

  • Meaningful mapping of the structures of the GDPR requirements
  • Collaborative approach to data protection
  • Data protection is implemented as a living, ongoing process

Diverging data protection requirements in companies

It has been in force since May 2018: the European General Data Protection Regulation (GDPR). One year after its introduction, Stefan Winkel, fully qualified lawyer and data protection consultant at intersoft consulting services AG, assesses the situation as follows: ‘I would say that the implementation or continued implementation of the requirements of the General Data Protection Regulation is still on the agenda of most companies. However, the panic of spring 2018 has largely dissipated, which in most cases has allowed for a more objective approach to the issue. A little composure after the initial excitement is certainly good for everyone involved.’

So there is no need to panic, because the majority of companies have taken the essential and necessary steps. However, it remains to be seen whether the implementation has always gone optimally in some areas. This is because some companies viewed the adaptation of business processes to the GDPR as a one-time task that also only affected a few employees in the company. In doing so, different departments, such as sales or human resources, have to meet diverging data protection requirements. This is one of the reasons why catworkx takes a collaborative approach to implementing the GDPR, in which the implementation of data protection is seen as a living process in which workflows and versioning must be controlled and mapped.

One of the key requirements of the GDPR is accountability as per Art. 5 (2). The controllers in companies must be able to demonstrate compliance with data protection. Further documentation requirements can also be found, for example, in Art. 30 (record of processing activities) and 35 (data protection impact assessment) of the GDPR. This results in three essential areas for the structure of a data protection management system (DPMS):

A record of processing activities

that documents which personal data is collected and processed in certain processing activities in a company.

A reporting system

with a clearly defined process for reporting data breaches and data breaches.

An information system

that allows data subjects to request which of their data has been stored or to request the deletion of their data.

Furthermore, the DSMS must meet the following requirements:

  • Documentation of the technical and organisational measures (TOM)
  • Documentation of data protection impact assessments (DSFA)

It quickly became clear that the usual forms of documentation could not be used to implement the GDPR at catworkx. For example, it is common practice to create and update the necessary documentation for the GDPR using Office programs. The catworkx approach of understanding data protection as a living process is difficult to reconcile with such an approach.

With Jira and Confluence to a data protection management system

It was obvious to approach the implementation of process documentation at catworkx with the tools that we use every day – in other words, with the Atlassian tools Jira and Confluence, enhanced with a few additional modules from the Atlassian ecosystem. The special thing about the approach is the maintenance of the relevant procedures, the technical and organisational measures (TOM) and the data protection impact assessment (DSFA) are mapped in Jira via processes. The accompanying documentation for this is automatically sorted and stored in Confluence. The use of processes with their easy-to-design individual workflows enables sustainable documentation based on the division of labour, which includes release by the data protection officer (DPO) as needed and promotes annual review and adjustment of procedures and measures.


In detail, the DSMS at catworkx consists of the following Jira process types:

The internal procedure

by which the controller's processing activities are documented.

The order data processing procedure

in which the processing activities of the processor are documented.

The data protection impact assessment

in which the risks for the individual procedures are assessed according to risk, severity of damage and probability of occurrence.

The technical and organisational measures

in which the prescribed measures to ensure the protection and security of the processing of personal data are documented.

The versioning

in which each procedure is subject to a cyclical review – usually once a year – or when an amendment to the GDPR comes into force.

The respective processes in Jira are dynamically and automatically transferred to a previously defined process directory in Confluence and documented. This is where the Teamworx Issue Publisher for Jira from catworkx comes into play. This is how a dynamic process directory is created in Confluence, in which all the individual processes are documented with their respective measures. catworkx's collaborative approach to data protection also becomes clear, because individual measures are assigned to the respective managers, for example in the human resources department, sales or internal IT. Data protection officer Stefan Winkel notes: ‘For departments with different areas of focus, such as in the operational and administrative areas, there are also different areas of focus in terms of data protection. It is therefore definitely advantageous to assign internal responsibilities accordingly and to build up relevant expertise in the departments. At the same time, it must be possible to keep an eye on the big picture in order to prevent the formation of islands. This can be done well with a process management tool, such as the one used at catworkx, for example.’
Another special feature of the catworkx approach is the versioning of the individual processes and the measures derived from them. Because one thing is clear: for the area of technical and organisational measures, Art. 32 para. 1 lit. d of the DSGVO requires a regular review. But the directory of processing activities or other mandatory documentation must also be kept up to date. ‘Consistent management of existing documentation using a process management tool can greatly simplify the management of existing measures,’ explains Stefan Winkel.

Oliver Groht, Co-Founder catworkx

With our GDPR solution, we have consistently used Jira and Confluence in such a way that the two tools provide the greatest added value for the user in a simple way. With our experience, we were able to set up a solution within four weeks that can even hold a candle to large specialised solutions.

Oliver Groht Co-Founder catworkx

Built-in escalation automation

The individual procedures are regularly reviewed to ensure that data protection always remains up to date. In view of the still uncertain legal interpretation of the GDPR, this is an advantage should, for example, changes in the law occur. Another advantage of the catworkx solution is the ability to create dashboards in Jira that can be used to access reports on the status of data protection at any time, possibly with a necessary escalation level.
Implementing the DSMS with Jira and Confluence also adds value to the information system, because requests for information about the processing of personal data or deletion can be made via a Jira service management. The process for providing information is different from the process for reporting a data protection violation. In the latter case, a report must be made to the supervisory authority within 72 hours of becoming aware of the data protection violation, in accordance with Art. 33 of the GDPR. Therefore, the configured workflow in this process ensures escalation automation.

Awareness of data protection is being raised

Stefan Winkel draws a positive balance for the implementation of the GDPR at catworkx: ‘As with most other companies, the implementation of the necessary measures at catworkx was initially carried out by a few people. However, the ongoing operation of data protection concepts is handled differently from company to company. At catworkx, the decision was made to involve employees extensively in maintaining the data protection concept. In this way, the necessary tasks were distributed across as many shoulders as possible. A positive side effect of this arrangement is that employees also come into contact with the topic from time to time, beyond the obligatory data protection training. I think this is basically a very good approach for catworkx.’
This is because the advantage of the data protection management system (DSMS) developed by catworkx lies, on the one hand, in the ready-made structure with which the measures for data protection in companies and authorities are recorded in a clear and comprehensible manner. On the other hand, catworkx DSMS impresses with its collaborative approach, which takes into account the respective responsibilities. And it understands data protection not as a one-time process, but as an ongoing, changeable process that can be well controlled by the versioning function.

Contact us!

We advise you on the entire Atlassian ecosystem and are happy to support you in optimising licence models and costs.

This may also be of interest to you

Referenz

Inventory management with Jira and Confluence from Atlassian

The catworkx approach for lifecycle management of IT inventory: The lifecycle of the inventory is modeled as a specific Jira workflow and various inventory categories are mapped and managed as task types. Confluence is perfectly suited for the documentation.

Wissen 4/14/23

General Data Protection Regulation of idea management

Walldorf-based dacuro GmbH provides the external data protection officer for companies, helps with the fulfillment of documentation obligations and advises on all aspects of data protection. Fulfilling the requirements of the GDPR without blocking everyday life is the claim of dacuro GmbH. The team of lawyers and IT specialists provides support for all GDPR challenges, whether they are of a legal or technical nature.

Referenz

Customer Relationship Management with Jira and Confluence

TOPMOTIVE Group, a leading provider of catalog and information systems in the automotive aftermarket, used Atlassian tools to bundle and provide sales-related information in one system.

Referenz

Managing projects with Confluence and Jira at ASI

In 2016, the IT department of Austrian Standards was given the task of converting 160 systems to a decentralised system in 2 years. catworkx accompanied the successful change in the corporate culture

Referenz

Confluence and Jira Service Management in use at JKU

At the JKU Linz, 21,000 people study in over 60 subjects. In 2018, a service portal was created using Jira Service Management and Confluence based on the motto “Help customers help themselves.

Referenz

Updating and expanding the Jira reporting system

PS Parkhaus Service Nürnberg manages 13 garages. In 2011, catworkx implemented a Jira system for message tracking, which was updated and expanded in 2019.

Blog 7/13/21

Composite UI with Design System and Micro Frontends

Discover how to create scalable composite UIs using design systems and micro-frontends. Enhance consistency and agility in your development process.

Blog 11/10/23

Part 1: Data Analysis with ChatGPT

In this new blog series we will give you an overview of how to analyze and visualize data, create code manually and how to make ChatGPT work effectively. Part 1 deals with the following: In the data-driven era, businesses and organizations are constantly seeking ways to extract meaningful insights from their data. One powerful tool that can facilitate this process is ChatGPT, a state-of-the-art natural language processing model developed by OpenAI. In Part 1 pf this blog, we'll explore the proper usage of data analysis with ChatGPT and how it can help you make the most of your data.

Service

Value Added Reselling

Our Value Added Reselling approach creates a trusted partnership that maximizes SAM efficiency and ROI for our customers.

Logo Atlassian Confluence
Technologie

Confluence from Atlassian

Create, organize, and collaborate on tasks - all in a single place. Confluence is a workspace for teams and organizations where you can store your documentation and collaboratively develop and share knowledge. Dynamic pages give your team a place to create, capture, and collaborate around projects or idea development.

Blog 7/15/21

Building a micro frontend consuming a design system | Part 3

In this blopgpost, you will learn how to create a react application that consumes a design system.

Training

Jira Essentials with Agile Mindset (Data Center)

Over the course of "Jira Essentials with Agile Mindset (Data Center)" training course participants learn the basics of Jira.

Headerbild zu Smart Insurance Workflows
Service

Smart Insurance Workflows

Using a design thinking approach, we orient workflows to the customer experience and design customer-centric end-to-end processes.

Teaserbild zu Data Integration Service und Consulting
Service

Data Integration, ETL and Data Virtualization

While the term "ETL" (Extract - Transform - Load / or ELT) usually described the classic batch-driven process, today the term "Data Integration" extends to all methods of integration: whether batch, real-time, inside or outside a database, or between any systems.

Headerbild IBM Cloud Pak for Data System
Technologie

IBM Cloud Pak for Data System

With the Cloud Pak for Data System (CP4DS), IBM provides the optimal hardware for the use of all Cloud Pak for Data functions industry-wide and thus continues the series of ready-configured systems ("Appliance" or "Hyperconverged System").

Icon Atlassian Jira Service Management
Produkt 8/8/22

Jira Service Management

Powerful and intuitive service management solution for IT and service teams

Risiko Management im Bereich der Governance immer wichtiger
Referenz

Introduction of an Identity Management System (IDM)

Introduction of an identity management system (IDM) in a corporate division with the focus on automating the joiner/mover/leaver processes. In addition, data cleansing was to take place in the user area to also enable a reduction in licensing costs.

Blog 9/27/22

Creating solutions and projects in VS code

In this post we are going to create a new Solution containing an F# console project and a test project using the dotnet CLI in Visual Studio Code.

Standort

Interested in Idea and Innovation Management?

Get in touch with our experts in ideas and innovation management.

Headerbild zu IBM Watson Studio
Technologie

IBM Watson Studio

IBM Watson Studio is an integrated solution for implementing a data science landscape. It helps companies to structure and simplify the process from exploratory analysis to the implementation and operationalisation of the analysis processes.

Bleiben Sie mit dem TIMETOACT GROUP Newsletter auf dem Laufenden!