That we more frequently design systems without personal data is a positive effect of the GDPR. These solutions are generally easier and cheaper to develop and maintain. As an IT architect, I recall two projects where the final design pleasantly surprised me.
The department responsible for 70% of an online shop’s revenue had new competition and wanted a completely new online shop with live pricing and new additional services that our seven-year-old online platform could not support. Since the CISO asked at every kick-off meeting whether we really needed personal data for the new systems, I started asking myself this question during the design phase. To my own surprise, we ended up developing and launching only three pages for displaying products, prices, and selecting additional products, with which the department could quickly compete and generate revenue.
Another example was the compliance department of a retailer searching for alternatives to implement the Supply Chain Act (Lieferkettegesetz). They had already considered various software solutions but were unsure whether they wanted to share all their suppliers’ information with a third party. When we discussed together the legal requirements and the retailer’s current systems, we found that a new system that documents the answers and requests regular updates not only met the legal requirements without processing the suppliers’ personal data, but could also be developed quickly by the company’s own IT department. Even before the responsible lawyer presented the requirements of the Supply Chain Act, he suggested this lean design of the system.
What positive effects of the GDPR have you observed in your professional life?