Michael Mattis

In the interview with Marc Oliver Giel from Datamog

In the interview with Marc Oliver Giel from Datamog

Datamog | Datenschutz IT Recht was founded in 2017 by lawyer Marc Oliver Giel to provide small and medium-sized enterprises (SMEs) in the information technology sector with a competent point of contact regarding data protection and compliance requirements. His more than 16 years of legal experience and particularly his expertise in IT law enable companies to implement data protection policies efficiently and cost-effectively. At Datamog, company decision-makers can access a wide range of data protection solutions, including audits, data processing agreements (DPAs), consulting services, creation of privacy policies, data protection management systems, and training, among others. Especially for smaller companies, data protection often does not receive the necessary attention. For organizations with 20 or more employees, Datamog offers the option of an external data protection officer to ensure compliance with data protection regulations. In the interview, we are speaking with the expert today in particular about common data protection claims or assumptions that exist in the business world, whose actual validity we aim to clarify.

DIGITAL FUTUREmag: Mr. Giel, what are the widespread myths about data protection that circulate in the public and online, and why do some of these rather curious ideas persist for so long?

Marc Oliver Giel: One myth keeps coming up, namely: companies with fewer than 10 or 20 employees don’t need to do anything regarding data protection. This is “dangerous half-knowledge.” There used to be a rule that only companies with 10 or more employees had to appoint a data protection officer. With a legislative amendment in 2019, the threshold was raised to 20 or more employees. Apparently, some management teams assumed that the data protection officer was responsible for ensuring data protection compliance in the company, and if no such officer needs to be appointed, there are no tasks to be completed. This, however, is incorrect. Even if no data protection officer needs to be appointed, the management is itself responsible for implementing data protection. There is no legal exception for micro-enterprises.

DIGITAL FUTUREmag: What practical tips do you have for companies with fewer than 20 employees to approach data protection in a meaningful and, above all, professional manner?

Marc Oliver Giel: I repeatedly see management teams relying on templates from associations, the internet, or even competitors, assuming that simply adding their company name would complete all tasks. In many cases, however, as an expert I must conclude: there is often no understanding of what obligations actually exist or how they can be effectively fulfilled. Listing them here would exceed the scope of this article. Therefore, my tip is as simple as it gets: Have a data protection officer or a lawyer specializing in data protection provide you with individual advice. After just one or two hours, you’ll have a rough to-do list with the 10 most important tasks, and management will understand why each step is necessary. You wouldn’t tell your skilled worker operating machinery, “Don’t ask why, just press the blue button every day at 12!” Instead, it’s better to explain why they should do it and what impact the blue button has.

DIGITAL FUTUREmag: Why is it important for B2B operators to pay attention to and protect personal data?

Marc Oliver Giel: Put simply: because it’s the law. But seriously: data protection isn’t bureaucratic for its own sake—it’s about implementing the right to informational self-determination. The simple translation is: every individual should be able to decide how their data is handled. When a company takes data protection seriously, it also shows appreciation for its customers, suppliers, business partners, and especially its employees. Some data protection violations by companies leave me baffled: How can a company justify illegally monitoring its own employees via video? I then ask myself: What use is it to an employee if they receive minimum wage, monthly fuel vouchers, and company pension plans, yet are spied on during their daily work? That’s grotesque!

DIGITAL FUTUREmag: Is data protection really an engine? What benefits does it bring for customers, suppliers, business partners, or employees, and why shouldn’t it be seen as bureaucratic harassment?

Marc Oliver Giel: To stay in your image of the locomotive: The technical principle behind a steam locomotive is simple. However, operating it is something only experienced individuals can do. Data protection works similarly. The core of data protection is crystal clear: protecting people’s informational self-determination. Achieving full data protection compliance requires expert advice. In other words: data protection can become a brake block if you don’t understand it and try to handle it on your own, hoping for the best. Let’s be honest: we only let highly trained and experienced employees operate industrial robots. Imagine the commercial management trying to program one. At every turn, we outsource company tasks to specialists (business consultants, advertising agencies, lawyers, tax advisors). Why not in data protection? Just last year—only four years after the General Data Protection Regulation (GDPR) came into effect—I saw with clients how data protection becomes a real competitive advantage: a supplier made further collaboration with my client dependent on successfully passing a data protection audit. Questions were asked, and an evaluation was conducted. If the rating falls below a certain threshold, no further collaboration takes place. Fortunately, my client passed.

DIGITAL FUTUREmag: What recommendations do you give SMEs to implement data protection effectively, and why is selecting a competent data protection officer important?

Marc Oliver Giel: If a company has done nothing regarding data protection yet, there are two phases: the setup phase and the maintenance phase. During the setup phase, project work dominates. I recommend small work packages to my clients that must be implemented within a specific timeframe. After that, the next package follows. This way, you steadily make progress without paralyzing operations. In the maintenance phase, only one to two meetings per year are needed. You can recognize a good data protection advisor by the fact that they quickly create a to-do list for you and implement it in a structured way. Incidentally, I make sure not to overwhelm my clients. My motto in this regard is: It’s better for the setup phase to take a little longer than for the management not to understand what it’s about and what needs to be done.

DIGITAL FUTUREmag: What role does the consent of individuals to the processing of their personal data play in the context of data protection? How should companies lawfully obtain and manage it?

Marc Oliver Giel: Unfortunately, the introduction of the GDPR in 2018 was often misused as a panacea. From everywhere, I received notes like “You have to sign this because of the new data protection regulations.” From a professional point of view, this was unfortunately nonsense, because if, for example, I order something from an online retailer, my name and address are absolutely necessary for delivery. In such cases, obtaining consent is utter nonsense. If consent is actually required, it must be given voluntarily, it must be informed, verifiable, and for a specific purpose, and it can be revoked at any time. A newsletter subscription serves as an example that is comprehensible even for laypeople: I subscribe to the newsletter voluntarily, I am not under any obligation. The linked privacy policy informs me about the purpose and my rights. My registration is logged via the newsletter system, so it is verifiable. And I can “object” at any time via the unsubscribe link in every newsletter, i.e., unsubscribe.

DIGITAL FUTUREmag: How can companies ensure that they comply with the principles of data minimization and purpose limitation when collecting and processing data to guarantee data protection?

Marc Oliver Giel: In contact forms and registration forms, I recommend marking mandatory fields with an asterisk. This way, the affected person knows what is absolutely necessary and which data, such as a mobile number, is provided voluntarily. When using CRM systems, the task becomes a bit more difficult. In the past, I often saw sales teams storing extensive private information about business partners or customers. Such profiling usually no longer meets the requirement of “data minimization” and must be discontinued. Purpose limitation is often achieved by using separate storage systems (in analog systems) or separate databases (in digital processing). Example: The data from a newsletter system (name, email address) must not simply be copied into my CRM or ERP system. Imagine a large cabinet with many small drawers. Each drawer represents a “purpose.” If you put data into one drawer, you must not later remove it and sort it into another drawer. That would be a violation of purpose limitation. If you absolutely need the data in another drawer, you must collect it for that purpose. This is why privacy policies today are so long and sometimes complicated. Because all these “purposes” should be listed there.

One more example: If you collect your customers’ date of birth to verify their age, you put the date of birth into the “age verification” drawer. If you later want to identify customers over the phone and ask for their date of birth, that is illegal. Because identification is a different purpose, i.e., another drawer, and the date of birth must not simply be reorganized.

DIGITAL FUTUREmag: To what extent has the increasing digitalization and the use of technologies such as artificial intelligence (AI) and big data analytics changed the challenges in data protection? What measures are required to keep pace with these developments?

Marc Oliver Giel: It is clear that data protection is lagging behind the technical development of AI systems. At the European level, an AI regulation is currently being prepared. This includes, among other things, detailed regulations for so-called "high-risk AI systems." At the national level, two new data protection-related aids have just been published. The Baden-Württemberg State Commissioner for Data Protection is the publisher of a 32-page discussion paper, "Legal Bases in Data Protection When Using Artificial Intelligence." The Hamburg Commissioner for Data Protection issued a 5-page checklist for the use of LLM-based chatbots. In the future, there will likely be further publications. Companies that wish to use AI systems in their operations would be well advised to make use of such aids.

If companies want to quickly test AI systems, they should refrain from transmitting personal data. In the discussion, some suggest suspending the use of AI until the legal and ethical framework has been established. However, there is a valid objection to this: losing technological ground in the meantime. My pragmatic approach is therefore: Until specific regulations are introduced, all existing GDPR provisions must be complied with as fully as possible when using AI. Data protection officers can also provide advice on this.

The topic of big data is somewhat older in terms of data protection law and therefore more mature. In most cases, data protection is not the "show-stopper." In other words, for many use cases, there are practical solutions.

DIGITAL FUTUREmag: Thank you for jointly cleaning up and tidying up data protection issues. I believe we were able to clarify a lot together and shed some light on the matter.