Folders and a digital checklist side by side — representing compliance-by-design in digitalised processes
Back to blog
Premium
GDPRGoBDCompliance

Legally Sound from Day One: Processes That Withstand Audits, GDPR, and GoBD

Sven HennessenProcesses

Optimising a process immediately changes who sees which data, who makes which decisions, and how they can be proven. Those who think about compliance only at the end build twice. What compliance-by-design means in practice, why data protection is less of a brake than feared, and how to build in legal certainty from the start.

Picture this moment: the system is finished. Go-live was a success. Six months later, an auditor wants to know who approved a purchase order worth €80,000 in March — and the system can't show it. The access and role structure doesn't match the data protection documentation. Rework begins that is more expensive than the preparation would have been.

This is not a theoretical risk. It's the most common pattern in digitalisation projects that stall: the technical solution is in place, but the rights and roles structure doesn't match the data protection documentation. Or an auditor wants to trace who approved which order value when — and the system can't show it. Then rework begins that is more expensive than the preparation would have been.

Optimisation always touches compliance obligations too

Three regulatory frameworks are most relevant in practice, and all three place requirements that flow directly from an optimised process:

GDPR: Anyone who processes personal data (and almost all business processes do) must implement Privacy by Design under GDPR Art. 25: not retrofit data protection, but build it in from the start. That covers: who may access which data, how long data is stored, and who can prove, if needed, that processing was lawful.

GoBD (German principles of proper accounting): These apply to every process that generates or handles receipts, orders, invoices, or bookings. Concretely: data must be immutable, complete, and machine-readable at any time. Anyone digitalising their order process must ensure that a tax auditor three years later can still trace which user triggered which order with which justification.

Sector-specific regulation: Pharma, medical devices, food, financial services — depending on the industry, further requirements apply: batch traceability, FDA compliance, MiFID II. These change with the process, not just with the audit.

Premium article

Read the full article

Enter your email and we'll send you a link to the complete article — it's free.