Skip to main content
Data Protection / GDPR

Data protection management system

A data protection management system is the systematic framework of roles, processes, policies and records through which an organisation implements, reviews and evidences its GDPR obligations on a permanent basis.

A data protection management system (DPMS, in German "Datenschutzmanagementsystem" or DSMS) is not a single document but the standing organisational structure a controller uses to govern data protection. The GDPR does not use the term itself, yet Art. 24(1) GDPR demands its substance: the controller must implement appropriate technical and organisational measures to ensure and be able to demonstrate compliance, and must "review and update those measures where necessary". Art. 24(2) GDPR adds that, where proportionate, this includes implementing appropriate data protection policies. Read together with the accountability principle in Art. 5(2) GDPR, this amounts to an obligation to run a closed management cycle rather than a series of isolated one-off measures.

A DPMS is usually built along the PDCA cycle (plan, do, check, act) and rests on four building blocks. First, roles and responsibilities: executive management as the controller under Art. 4(7) GDPR, a data protection officer with the tasks set out in Art. 39 GDPR, data protection coordinators embedded in the business units, and named process owners. Second, core processes: the record of processing activities under Art. 30 GDPR, threshold analysis and data protection impact assessments under Art. 35 GDPR, handling of data subject requests within the one-month deadline of Art. 12(3) GDPR, breach notification within 72 hours under Art. 33 GDPR, vendor management with processor agreements under Art. 28 GDPR, and retention and deletion concepts. Third, the rule set: a data protection policy, supporting guidelines, templates and training. Fourth, the evidence base: logs, approvals, audit reports and metrics.

Effectiveness only emerges from the check and act phases: internal audits, a management review, metrics such as turnaround time for access requests or training coverage, and a documented corrective action plan whenever gaps appear. No formal certification is mandatory. Useful reference models are the Standard Data Protection Model (SDM) published by the German supervisory authorities, ISO/IEC 27701 as a privacy extension to an ISO/IEC 27001 information security management system, and approved codes of conduct under Art. 40 GDPR or certifications under Art. 42 GDPR. In practice a DPMS pays off twice: it reduces the likelihood of infringements, and under Art. 83(2)(d) GDPR the degree of responsibility, taking into account the measures actually implemented, is weighed when a fine is calculated. Where an information security or compliance management system already exists, the DPMS should be integrated into it rather than run in parallel.

Legal Basis

Art. 24 GDPR (in conjunction with Art. 5(2), Art. 30, Art. 32, Art. 35 and Art. 39 GDPR); supplementary guidance in ISO/IEC 27701 and the German Standard Data Protection Model (SDM)

Practical Example

A mid-sized machinery manufacturer with 450 employees has so far managed data protection through a spreadsheet and the calendar of its external data protection officer. After a complaint to the supervisory authority, which requests the record of processing activities and proof that applicant data is deleted within two weeks, the compliance lead introduces a DPMS. She appoints a data protection coordinator in every business unit, migrates the record of processing activities into a central tool with named owners and review dates, makes a threshold analysis a mandatory gate before any new software is rolled out, tracks access and erasure requests with a deadline dashboard, and schedules annual internal audits plus a management review. Six months later she can export the requested documentation up to date at any time and additionally evidence that applicant data is deleted automatically after six months. What began as an ad-hoc response has become an auditable routine.

FAQ

The GDPR never uses the phrase "data protection management system", but Art. 24 GDPR requires exactly its function: appropriate measures that ensure and demonstrate compliance and that are reviewed and updated where necessary. Combined with the accountability principle in Art. 5(2) GDPR, a structured management system is therefore effectively mandatory. Its scope and depth scale with the nature, scope, context and risks of the processing involved.
An ISMS protects information from the organisation's perspective and targets confidentiality, integrity and availability. A DPMS protects the rights and freedoms of natural persons and additionally covers legal bases, purpose limitation, data subject rights, retention periods and third-country transfers. The two overlap heavily on technical and organisational measures, and ISO/IEC 27701 extends an existing ISMS with privacy requirements, which makes integrating both systems the pragmatic route.
The mandatory core comprises the record of processing activities under Art. 30 GDPR, processor agreements under Art. 28 GDPR, documented legal bases and consents, the retention and deletion schedule, threshold analyses and data protection impact assessments under Art. 35 GDPR, the internal breach register under Art. 33(5) GDPR, and documentation of data subject requests, training and security measures. Audit reports, management reviews and corrective action plans should complete the picture so that effectiveness can be demonstrated.

How preeco supports you

Learn how our software supports you with this topic.

Learn more