Every day, we leave behind personal data dozens of times. Whether filling out a form, shopping online, sharing information on social media or simply connecting to Wi-Fi, we are constantly interacting with data. This data can either be protected or exposed, and its processing can directly affect individuals’ privacy and organisations’ reputation.Data Protection Day on 28 January serves as a collective reminder of these realities. This day is not a celebration but an opportunity to make data protection more visible, to question the security habits of institutions and individuals, and to make visible their rights, digital footprints, and the consequences of these habits.The date of 28 January is referenced because it was on 28 January 1981 that the Council of Europe opened the Convention 108 for signature, which aims to protect individuals against the automatic processing of personal data.
The Council of Europe launched Data Protection Day in 2006 to strengthen awareness, and the day is commemorated annually on 28 January.
Data Protection or Information Security?
Data protection encompasses governance aspects such as the purpose for collecting personal data, how long it is stored, with whom it is shared, and how the individual’s rights are exercised. Information security, on the other hand, covers organisational and technical controls that support the confidentiality, integrity, and availability of data. In organisations, these two areas deliver sustainable results when they work together on the same data flows.
Examples include personnel files, customer records, call centre records, camera recordings, web forms, ticketing tools, email inboxes, backup media, and cloud storage areas, which may contain personal data. Therefore, data protection objectives are realised through information security controls. These include access rights management, strong authentication, log records, encryption, data masking, backup, penetration testing, incident response, supplier security, awareness training, and process audits.
Systematising data protection with ISO 27001
ISO/IEC 27001 defines the requirements for establishing and maintaining an Information Security Management System. ISO states that the standard promotes a holistic approach that supports risk management and cyber resilience objectives.
Addressing data protection objectives using the ISO 27001 approach provides clarity within the organisation.
- Asset inventory and classification
It becomes clear which systems personal data is stored in, who has access to it, and in which processes it is processed.
- Risk assessment and control selection
The risks with the greatest impact are prioritised. Controls are selected and implemented according to the nature of the business.
- Management of policies and procedures
Corporate standards are established in areas such as access management, change management, incident management, supplier management, backup, and disposal.
- Incident response and records
Steps to be taken, responsible parties, and evidence records are clarified in cases of suspicious access, suspected leaks, or incorrect sharing.
- Internal audit and continuous improvement
Applications are reviewed at regular intervals. Weaknesses are strengthened in a planned manner.
This structure is a systematic management discipline that carries the awareness raised by Data Protection Day into the rest of the year.
A short plan for organisations during the week of 28 January
A small but effective plan can be implemented to ensure this day is not just a single post.
- Data flows can be reviewed
Select the processes that generate the most personal data. For example, recruitment, customer registration, call centres, web forms, and marketing automation.
- A quick checklist can be created
Are access permissions up to date? Are logs functioning? Are retention periods defined? Are disposal steps being implemented? Do supplier contracts include data security clauses?
- Publish short awareness content
Compile 10-minute mini-training sessions for teams, common mistakes, examples of suspicious emails, and points to consider when sharing data.
- Add an internal audit schedule
By creating a data-focused internal audit plan within the scope of ISO 27001 or existing security processes, the system can be implemented.
Data Protection Day on 28 January is a good starting point for organisations to manage personal data more rigorously. At CFECERT, we help organisations manage their risks with ISO/IEC 27001 training and certification services at our information security centre. If you would like to assess your organisation’s current situation, clarify your ISMS roadmap, and plan for certification, please contact us at info@cfecert.co.uk.