Michael Mattis

In the interview with Dr. Ralf W. Schadowski, board member at the Federal Association of IT Experts BISG e.V. and active member of the Association for Data Protection and Data Security

In the interview with Dr. Ralf W. Schadowski, board member at the Federal Association of IT Experts BISG e.V. and active member of the Association for Data Protection and Data Security

Dr. Ralf W. Schadowski is an outstanding figure in the field of data protection and information security, bringing an impressive range of qualifications and experience. As Managing Director, he is responsible for the data protection and IT security-relevant management and strategic direction of companies. He is a certified and supervised European Data Protection Officer under ISO/IEC 17024, underscoring his high level of expertise in data protection matters. He also holds certifications as an ISO/IEC 27001 certified Lead Auditor and Implementer, as well as an ISO/IEC 27701 certified Lead Implementer. This demonstrates his ability to implement information security and data protection management systems at the highest level.

Dr. Schadowski is not only active in the context of certifications and audits, but also as a specialist group leader for data protection and board member of the renowned Federal Professional Association of IT Experts BISG e.V. Here, he advocates for the promotion of IT security and data protection expertise and corresponding best practices. In addition, the expert is involved in the Society for Data Protection and Data Security (GDD) e.V., a respected data protection and data security organization, where he shares his knowledge with other specialists and contributes to the shaping of data protection guidelines and practices. Thanks to his extensive expertise, Dr. Schadowski is a key figure and opinion leader in data protection and IT security in Germany. And thus the ideal discussion partner for us to find out whether data protection will be business-enhancing or -impeding for SMEs in the coming year.

DIGITAL FUTUREmag: Mr. Schadowski, with the introduction of the General Data Protection Regulation (GDPR) in the European Union, data protection in Germany and internationally has been further harmonized and strengthened. At least in theory. Has the GDPR achieved its goals?

Dr. Ralf W. Schadowski: The GDPR has ensured that many organizations have finally started implementing data protection requirements, but a great deal still haven’t even tackled the basic aspects of data protection. The data belongs to the data subject, and every organization must be able to demonstrate compliance with their fundamental rights. It’s unbelievable what we’ve had to uncover in the last 1,000 audits. It’s high time that those responsible face personal liability for negligence. That’s when things will start moving. On the other hand, the GDPR is sometimes implemented too rigidly and acts as an innovation brake. We need a sense of proportion here!

DIGITAL FUTUREmag: How can data protection be effectively integrated into the planning and implementation of digital transformation projects in companies to minimize risks?

Dr. Ralf W. Schadowski: At the end of the day, it's all about control over data. No organization wants to lose data or end up in the public eye. The requirements of the GDPR should be seen by responsible managing directors and board members as guardrails, not as a burden. Then data protection not only helps to keep personal data under control, but any data.

DIGITAL FUTUREmag: What best practices and strategies do you recommend to companies to meet data protection requirements in a constantly changing digital environment?

Dr. Ralf W. Schadowski: Data protectors have tools such as the processing records pursuant to Article 30 GDPR, in which organizations not only maintain documentation of their data protection obligations but also create valuable process documentation that stabilizes any organization. In the event of changes, such as the introduction of cloud technologies or system modifications, this ensures an orderly process that benefits the organization.

DIGITAL FUTUREmag: How can those responsible ensure compliance with applicable data protection regulations in different countries and regions, especially considering the global reach of digital business models?

Dr. Ralf W. Schadowski: Often, there is a lack of IT process and system documentation because internal departments are overloaded and cannot manage this alongside their other tasks. Once you have created the “image of the process and system landscape,” it is easy to keep track of everything, initiate the right measures at every processing location and path, and adapt them when changes occur. Order is half the battle. Internationally, we encounter numerous differing regulations and standards, which can be consolidated into an accepted company standard through a matrix evaluation. This allows global data flows to take place in compliance with the law.

DIGITAL FUTUREmag: To what extent can data protection serve as a competitive advantage and enabler for innovative business models, rather than an obstacle?

Dr. Ralf W. Schadowski: We currently serve 400 organizations across almost all industries, regionally and globally. Across the board, organizations receive “supplier audits,” also known as supply chain audits, whether GDPR, NIS2, DORA, CER, and so on. If an organization fails the audit, it immediately loses the contract, money, jobs, and so on. The requirements are not complicated; what is lacking is attention and interest in implementing basic data security requirements. Once implemented, organizations should demonstrate their maturity level externally.

DIGITAL FUTUREmag: How can a proactive data protection strategy help minimize the risk of data and privacy breaches while simultaneously increasing customer trust?

Dr. Ralf W. Schadowski: Organizations should create and implement a simple, affordable implementation and audit plan. The results should be communicated to business partners without being prompted. In today’s times, this strengthens trust not only in business relationships but also in the employer!

DIGITAL FUTUREmag: Which successful companies use data protection as an integral part of their strategy to strengthen customer trust and optimize their market position?

Dr. Ralf W. Schadowski: I am not allowed to name any companies. There are numerous publications showing which companies have lost data, been blackmailed, or received fines. Everyone has access to this information. Let’s learn from the mistakes made and ensure that the same does not happen again. With simple means and common sense, these organizations would not have made headlines.

DIGITAL FUTUREmag: What tools and technologies are available to companies to facilitate data protection compliance while also promoting business growth?

Dr. Ralf W. Schadowski: Depending on the industry and size of an organization, experienced data protection officers can build and operate a functional Data Protection Management System (DSMS) using standard tools. The effort is manageable and stabilizes the resilience of processes. Ready-made cloud-based DSMS tools provide guidance for beginners but require additional budget and lead to dependencies.

DIGITAL FUTUREmag: How can decision-makers ensure that ISO 27001 certification is not just a bureaucratic process but actually leads to improved information security?

Dr. Ralf W. Schadowski: As an experienced ISO 27001 Senior Implementer and Auditor, I have observed that most organizations, for the first time in the context of ISO 27001, systematically consider risk management and fundamental IT security principles. This is the real benefit for any organization seeking certification. The subsequent internal audits help them to be more alert to threats and become more resilient.

DIGITAL FUTUREmag: Artificial intelligence is gaining ground worldwide. What role do new technologies like this or the Internet of Things play in increasing data protection requirements?

Dr. Ralf W. Schadowski: Integrating AI into daily tasks is fascinating and, if used correctly, significantly accelerates work. IT-savvy staff must be sensitized by senior management through delegation to ensure proper application and prevent the loss of intellectual property. Companies that do not evaluate AI will fall behind.

DIGITAL FUTUREmag: I’m sure you’ve been waiting for this question: How would you overall assess the topic of data protection in relation to digitalization and the development of our economy – as an engine or as a brake?

Dr. Ralf W. Schadowski: Contrary to many media portrayals, a balanced approach to data protection enables global IT strategies while respecting our informational self-determination. This is easier than non-data protectionists might imagine and something we have been proving for a long time. Data protection is a tool, not a science.

DIGITAL FUTUREmag: Many thanks for your time and, in particular, for the insight into your important service offerings.