Picture this moment: the system is finished. Go-live was a success. Six months later, an auditor wants to know who approved a purchase order worth €80,000 in March — and the system can't show it. The access and role structure doesn't match the data protection documentation. Rework begins that is more expensive than the preparation would have been.
This is not a theoretical risk. It's the most common pattern in digitalisation projects that stall: the technical solution is in place, but the rights and roles structure doesn't match the data protection documentation. Or an auditor wants to trace who approved which order value when — and the system can't show it. Then rework begins that is more expensive than the preparation would have been.
Optimisation always touches compliance obligations too
Three regulatory frameworks are most relevant in practice, and all three place requirements that flow directly from an optimised process:
GDPR: Anyone who processes personal data (and almost all business processes do) must implement Privacy by Design under GDPR Art. 25: not retrofit data protection, but build it in from the start. That covers: who may access which data, how long data is stored, and who can prove, if needed, that processing was lawful.
GoBD (German principles of proper accounting): These apply to every process that generates or handles receipts, orders, invoices, or bookings. Concretely: data must be immutable, complete, and machine-readable at any time. Anyone digitalising their order process must ensure that a tax auditor three years later can still trace which user triggered which order with which justification.
Sector-specific regulation: Pharma, medical devices, food, financial services — depending on the industry, further requirements apply: batch traceability, FDA compliance, MiFID II. These change with the process, not just with the audit.
