How data protection and information security shape your business relationships
Reading time: 11 minutes
Your GDPR compliance and the quality of your information security determine whether customers and business partners can place their trust in you. In our blog, we show you how the fundamental need for trust shapes business relationships, how data protection and information security differ, what role your choice of communications infrastructure plays in your duty of care, and how you can create a security culture that underpins your long-term trustworthiness.
The fundamental prerequisite for any relationship: trust
Being able to speak openly and knowing that information is kept secure is crucial for relationships both between business partners and between service providers or organisations and their customers, clients or patients. This openness requires the certainty that what is shared remains where it belongs.
In the past, this need had a physical location, such as a closed meeting room or a locked filing cabinet. Today, many of our business, administrative and other processes take place digitally. The door to the room or filing cabinet has been supplemented by an organisation’s IT infrastructure.
For customers and business partners, this infrastructure is often invisible, they have no control over it. But even for you, the qualities of your infrastructure may be less clear than you think: you may well have made purchasing decisions years ago without being aware of the nature and legal basis of the IT services. Have your decisions ensured that the trust your customers and partners place in you is justified and can be sustained in the long term?
Data protection as an economic factor
In public debate, privacy is usually discussed as a fundamental individual right – something that citizens demand from the state or from platforms. Yet it is also an economic factor: Client meetings, contract negotiations, medical reports, journalistic sources and internal strategy discussions are all forms of communication that rely on confidentiality.
A lack of trust, on the other hand – for whatever reason – leads to a reduced quality of the business relationship. And this is the case even before a data protection incident occurs:
- For instance, a client who becomes more cautious when describing a situation because they are unsure where their words might end up receives poorer advice.
- A patient who withholds a sensitive detail will receive a less accurate diagnosis.
- A supplier who keeps the critical points of a cost calculation to themselves undermines joint planning.
These examples illustrate just how much stable relationships depend on trust, reliability and secure communication. What does this mean in our interconnected digital world?
Data protection in practice: communication channels
IT infrastructure manages not only data, but also the conditions under which people are prepared to reveal something about themselves. The characteristics of the communication channels play a central role in this: When transmitted digitally, information travels a significantly longer and often less secure path than many of those involved realise.
Protection through transport encryption is limited
Most business emails are now encrypted using TLS whilst in transit. Many people and organisations conclude from this that the content is automatically protected as a result. However, transport encryption only encrypts the connection between the servers. It therefore only protects emails whilst in transit.
On the providers’ servers, the message may well be stored in plain text. The communication could therefore be analysed, read or disclosed in response to an official order. Only end-to-end encryption or server-side encryption, where the provider does not hold the key, changes this.
Even if the content is protected, the metadata remains visible – for example, who communicated with whom and when, how the frequency of communication has changed over the weeks, or how large the attachments sent were. Important conclusions can be drawn from this metadata.
Understanding and applying email encryption in a business and public sector context
Data protection and information security
The terms ‘information security’ and ‘data protection’ are often used interchangeably in everyday language. Whilst there is indeed some overlap between them, they are not identical.
The difference between data protection and information security
Information security protects information and the systems that process it – regardless of whether it relates to individuals. It pursues the protection objectives of confidentiality, integrity and availability. It applies to all information, from engineering drawings to patient records.
Data protection, on the other hand, protects individuals with regard to the processing of their personal data and addresses the legal basis, purpose limitation, transparency and the rights of data subjects. The underlying principle is self-determination: everyone should be able to decide for themselves who knows what about them and what happens to that information. Because this does not happen automatically in dealings with public authorities and companies, there are rules in place to safeguard this right to self-determination, such as the General Data Protection Regulation (GDPR).
Information security and data protection go hand in hand, but one does not guarantee the other: A company may have excellent technical safeguards in place in terms of information security and still breach data protection regulations simply because it lacks the legal basis for processing. Conversely, data protection documentation may be exemplary, whilst information security may have gaps.
Article 32 of the GDPR links the two by requiring state-of-the-art security of processing, thereby making information security measures a data protection obligation. The choice of IT infrastructure therefore affects both data protection and information security: A provider that can be compelled by law to disclose data – e.g. a US hyperscaler under the US CLOUD Act – poses a problem for your credibility and the assessment of your corporate due diligence.
This applies in particular to professional groups such as lawyers, doctors or tax advisers, who are subject to specific professional obligations. Furthermore, the Trade Secrets Act can only protect information if appropriate confidentiality measures have been put in place. Furthermore, in supply chains, even though the companies themselves are not actually subject to these obligations, e.g. the German NIS-2 Implementation Act.
Demonstrating information security: ISO 27001 and the C5 catalogue
ISO 27001 as proof of due diligence
ISO/IEC 27001 is the international standard for information security management systems. The standard certifies that a management system exists, is documented and is functioning. However, it says nothing about which legal system the provider is subject to or who can compel them to disclose information. For example, a US hyperscaler may be certified to ISO 27001 and yet still be subject to the US CLOUD Act. The standard answers the question of how diligently work is carried out, but not to whom the provider is accountable.
The C5 criteria catalogue
The C5 criteria catalogue of the German Federal Office for Information Security (BSI) is not a certification, but rather an attestation for cloud providers. To obtain this, the provider must disclose framework conditions, such as the location of data processing, where sub-processors can access data, the place of jurisdiction or the how they handle investigation requests from government bodies.
The catalogue does not stipulate where the data must be processed or which law the provider must be subject to, but it does require the provider to disclose this information. It therefore ensures transparency regarding potential access. For an increasing number of sectors and public institutions, the BSI C5 certification is becoming a key criterion in the selection of their cloud services and partners.
Understanding due diligence as an opportunity
The core potential of information security and data protection lies in the growing trust that must be nurtured. Business relationships that last for years are based on the repeated experience that one can trust the other. A company that views data protection and information security as a means of building relationships is doing more than simply fulfilling a duty of care.
Moreover, many organisations now seek written confirmation of trustworthiness from their service providers and suppliers: in supplier questionnaires, vendor assessments and tender documents. Those who can meet these requirements win contracts.
Which channels and tools you should check
Sensitive information flows particularly via communication channels such as email and video conferencing, as well as shared files and folders. Migrating to a sovereign cloud or a sovereign digital workplace is an important step. Nevertheless, other components should also be checked for GDPR compliance and information security:
- Check CRM systems, messaging apps and newsletter tools.
- Caution is also advised with tools for applicant management or online appointment booking.
- Sharing links to data in cloud storage should have an expiry date so that they do not remain active for years on end.
- The use of shadow IT undermines the principles of confidential communication and, through external AI assistants, leads to a new level of data leakage and security risks.
- Your website also processes personal data. You may not even realise how many third-party providers have access to the data tracked on your own website. Nevertheless, the responsibility under data protection law lies with you and not with the third-party provider. You must therefore pay close attention to which third-party providers are actually involved in your specific case.
Competencies and culture: Trust is built in day-to-day work
Technical measures are only as effective as the people who implement them. Customers and business partners can immediately recognise your security culture by the way your staff handle their documents.
A culture of error acceptance is a security measure
Your practised culture of error acceptance determines whether someone who clicks on a phishing link reports it immediately or keeps it to themselves for days. If you penalise mistakes, you may end up delaying the time it takes for an incident to be reported. Conversely, if you explicitly encourage prompt reporting, you will speed up the process. Time is of the essence here, as it determines the extent of the damage.
Clear rules rather than blanket bans
The use of shadow IT arises from a genuine need for which the authorised tool is either missing or takes too long to become available. You should therefore establish sensible internal policies for the use of new tools that take data protection and information security into account. Clarify the following questions to prevent the unsafe use of tools:
- What type of information is permitted to be transmitted via which channel?
- What may and may not be entered into external AI assistants, translation services or converters?
- Who is granted which authorisations upon joining, and who revokes them upon leaving?
A security culture needs role models
Whether staff handle confidential information with care also depends on the example set for them. If you, as senior management, visibly follow the security measures yourselves, take queries seriously and do not penalise employees for reporting errors, your behaviour within the organisation will have a greater impact on your staff than any operational instruction. The fact that leadership must lead by example in this regard is now also enshrined in law: Within the scope of the German NIS-2 Implementation Act, members of senior management must themselves attend training courses in order to be able to assess risks and protective measures.
Cybersecurity
To ensure that confidential communication remains possible at all, a company must actively secure its systems against attacks. Essential measures include multi-factor authentication, keeping systems up to date, a well-thought-out authorisation scheme and backups that are separate from the production system.
Cybersecurity is not a one-off investment, but an ongoing commitment that must be upheld by senior management. If you treat it as solely the responsibility of the IT department, you are underestimating how directly a security incident will reflect on your own reliability.
Resilience: What determines your reliability in an emergency
Crises are tests of your reliability. Whilst it is unrealistic to expect everything to run flawlessly, well-managed outages on your part can actually strengthen your credibility. This is because, in the event of an IT outage or cyberattack, customers and business partners pay close attention to how you handle the situation.
In this context, you should also ask yourself how your customers find out about an incident: from you? Or from someone else? The extent to which you retain control over communication channels depends on whether all staff know how to respond and whether you have an immediately deployable contingency solution ready in the event of a failure of your primary digital communication system. How long you remain unreachable and how well this situation is managed will shape your business relationships for much longer than the outage itself.
Staying able to act in an emergency
Conclusion: Your reliability is only as good as your infrastructure
You fulfil part of your obligations under the GDPR and information security through your own actions: you clarify responsibilities, document data processing activities and train staff. However, the quality of your information security and data protection is structurally and fundamentally influenced by your choice of communications infrastructure. Your choice helps determine how resilient and successful your business relationships are, both now and in the future.
mailbox protects your communications and your information