English:Data Protection in Administration

Data Protection in Administration
Introduction
Administrative work depends on information. In a municipal office, public agency, school administration, health administration, company office, or training department, you may handle names, addresses, contact details, identification numbers, applications, invoices, personnel files, complaints, appointments, case notes, photographs, or access logs. Much of this is personal data: information relating to an identified or identifiable person.
This aiMOOC is designed for apprentices, trainees, and vocational students who carry out administrative tasks. It uses the General Data Protection Regulation as its main legal reference because the GDPR is central to data protection in the European Union. National laws, sector rules, collective agreements, professional duties, and local workplace policies may add further requirements. When a real case is unclear, follow your organisation's approved procedure and involve the responsible Data Protection Officer.

By the end of the course, you should be able to recognise personal data, apply the main processing principles, work safely with paper and digital records, react correctly to requests and incidents, and explain why data protection is part of professional administrative quality.
Learning Goals
- Personal data: Distinguish personal data from information that does not relate to an identifiable person.
- Data protection principles: Apply purpose limitation, data minimisation, accuracy, storage limitation, security, transparency, and accountability to everyday office tasks.
- Lawful processing: Explain why administrative processing needs an appropriate legal basis and a clear purpose.
- Information security: Use practical safeguards when working with email, files, passwords, paper records, phones, and shared systems.
- Data subject rights: Recognise requests for access, correction, deletion, restriction, portability, and objection and route them correctly.
- Data breach: Identify possible breaches and report them internally without delay.
- Privacy by design: Consider data protection before a new form, process, database, or digital service is introduced.
Why Data Protection Matters in Administration
Administrative staff often work at the point where information enters, moves through, and leaves an organisation. A single routine action can affect a person's privacy: sending an email to the wrong recipient, leaving a case file on a printer, discussing a customer in a public area, storing documents for too long, or asking for information that the process does not actually need.
Data protection is therefore not only an IT issue. It combines law, organisation, communication, records management, and information security. Good data protection helps people trust the organisation and helps employees work in a controlled, explainable way.

Personal Data and Special Categories
Personal data includes obvious identifiers such as a name or identification number, but it can also include online identifiers, location information, employee numbers, customer numbers, photographs, voice recordings, or combinations of details that make a person identifiable.
Some data receives additional protection under the GDPR. Special categories of personal data include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health data, and data concerning a person's sex life or sexual orientation. Administrative organisations may also process criminal-conviction data under specific legal conditions.
A useful professional habit is to ask: Whose data is this, why do we need it, who needs access, how long should it remain available, and what could happen if it is misused?
The Seven GDPR Principles in Office Practice
The GDPR sets out seven key principles. They can be translated into practical office behaviour.
| Principle | What it means in administration | Practical example |
|---|---|---|
| Lawfulness, fairness and transparency | Process data on a valid basis and explain the use clearly. | A form tells applicants why their data is collected and how long it will be kept. |
| Purpose limitation | Use data for specified and legitimate purposes. | Contact details collected for a permit application are not automatically reused for unrelated advertising. |
| Data minimisation | Collect only what is necessary for the task. | A visitor-registration form does not ask for a private phone number when it is not needed. |
| Accuracy | Keep relevant personal data correct and up to date. | An employee corrects a wrong postal address in the authorised record system. |
| Storage limitation | Keep identifiable personal data no longer than necessary. | Closed case files follow an approved retention and deletion schedule. |
| Integrity and confidentiality | Protect data against unauthorised access, loss, alteration, or disclosure. | Staff use access controls, secure transfer methods, locked storage, and approved devices. |
| Accountability | Be able to show how the organisation complies. | Procedures, training records, processing records, risk decisions, and incident logs are documented. |

A data-flow view is useful because it forces you to see where data comes from, where it goes, who receives it, and where it is stored. For a new administrative process, drawing the flow can reveal unnecessary copies, unclear responsibilities, or insecure transfers.
Roles and Responsibilities
A data subject is the person the personal data concerns. A controller decides the purposes and essential means of processing. A processor processes personal data on behalf of a controller. A Data Protection Officer advises and monitors the organisation on data-protection matters and acts as an important contact point. A Data Protection Authority is an independent supervisory authority.
Public administrations in the EU are generally required to appoint a DPO, except for courts acting in their judicial capacity. A trainee does not replace the DPO and should not make high-risk legal decisions alone. Your responsibility is to follow procedures, protect the information you handle, recognise warning signs, and escalate questions promptly.
Controller and Processor in a Practical Example
Imagine a local authority uses an external company to host an online appointment system. The authority determines why appointment data is needed and which services are offered, so it is normally the controller for that processing. The hosting company may act as a processor when it handles the data on the authority's documented instructions. A proper contractual or other legal arrangement must define the processor's data-protection duties.
This distinction matters because responsibilities cannot be left vague just because a task is outsourced.
Lawful Processing in Administrative Work
Personal data may only be processed when a legal basis applies. Depending on the situation, the GDPR recognises consent, contract, legal obligation, vital interests, tasks in the public interest or exercise of official authority, and legitimate interests.
For public administration, legal obligation and public task or official authority are especially important. Do not assume that consent is always the safest choice. Consent must be freely given, specific, informed, and unambiguous, and in situations with a clear power imbalance it may not be the appropriate basis. The correct basis depends on the actual law and purpose of the process.
Before you collect information, be able to answer:
- What is the exact administrative purpose?
- Which data is necessary for that purpose?
- What legal basis supports the processing?
- Who should receive or access the data?
- What retention rule applies?
- What information must be given to the person?
The Data Life Cycle
Data protection applies through the whole life cycle of a record.
| Stage | Good administrative practice |
|---|---|
| Collection | Ask only for necessary information and provide the required privacy information. |
| Use | Work only within the defined purpose and authorised process. |
| Storage | Use approved systems, correct permissions, secure cabinets, and reliable backups where required. |
| Sharing | Check the recipient, purpose, legal basis, transfer method, and minimum necessary content. |
| Archiving | Follow approved archival rules where records must be preserved for legal or public-interest reasons. |
| Deletion or destruction | Remove records securely when the retention period ends and no lawful reason requires further storage. |
Do not create uncontrolled shadow files merely because copying is convenient. Duplicate spreadsheets, local downloads, personal cloud storage, and unapproved messaging apps can make retention and access control much harder to manage.
Everyday Information Security
Data protection depends on both technical and organisational measures. Your behaviour is one of those measures.

Email and Messaging
Before sending a message that contains personal data, check the recipient, attachment, purpose, and amount of information. Use BCC when recipients should not see one another's addresses. Avoid forwarding long email chains without checking what personal data is included. Use only approved communication channels.
Be especially cautious when a message creates urgency, asks you to bypass a normal process, requests credentials, changes bank details, or contains an unexpected link or attachment.

Screens, Passwords, and Access Rights
Lock your screen when leaving your workstation. Use strong, unique credentials and multi-factor authentication where your organisation provides it. Never share your account merely because a colleague wants to finish a task quickly. Access rights should follow the need-to-know principle: people receive the access necessary for their role, not access to everything.
If your role changes, access should be reviewed. If you notice that you can open records you clearly do not need, report the excessive access instead of exploring the data.
Paper Files, Printers, and Conversations
Paper records also contain personal data. Collect printouts immediately, use locked storage where required, and dispose of confidential records through the approved destruction process. Do not leave visitor lists, payroll information, applications, or medical certificates visible on desks in public or shared areas.
Avoid discussing identifiable cases in corridors, lifts, cafés, public transport, or other places where unauthorised people can listen.
Data Subject Rights
Under the GDPR, individuals have rights over their personal data. These include the right to be informed, access, rectification, erasure in applicable circumstances, restriction of processing, data portability in applicable circumstances, objection, and protections relating to certain automated decisions and profiling.
Administrative staff should be able to recognise a rights request even when the person does not use legal terminology. For example, “Please send me everything you hold about me” may be an access request. “This address is wrong” may be a rectification request.
Do not ignore the request, delete relevant records because a request arrived, or promise an outcome before it has been assessed. Record the date, follow the approved identity-verification and routing procedure, and involve the responsible team or DPO. Under the GDPR, organisations generally must respond to rights requests without undue delay and at the latest within one month, subject to the rules and possible extensions in the Regulation.
Personal Data Breaches
A personal data breach is a security incident involving accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It is broader than hacking.
Examples include an email sent to the wrong person, a lost unencrypted device, a stolen file, documents placed in the wrong envelope, ransomware that makes records unavailable, or inappropriate internal access.

If you suspect a breach, report it internally immediately using the approved incident channel. Preserve useful facts and do not hide the mistake. The controller must assess the risk. Where notification to the competent Data Protection Authority is required, the GDPR sets a deadline of without undue delay and, where feasible, within 72 hours after becoming aware of the breach. High-risk breaches may also require communication to affected individuals. Your organisation's incident team or DPO should guide these decisions.
First Actions for a Trainee or Apprentice
- Stop further disclosure if you can do so safely and within your authority.
- Inform the designated supervisor, incident contact, service desk, or DPO without delay.
- Record what happened, when it happened, which records may be affected, and what immediate action you took.
- Do not delete evidence, conceal the incident, contact affected people independently, or negotiate with attackers unless authorised.
- Continue to follow instructions from the responsible incident team.
Privacy by Design, Privacy by Default, and DPIAs
Data protection by design and by default means considering privacy from the start rather than adding it after a system or process is already running. Default settings should avoid unnecessary collection, excessive access, and unlimited retention.
For example, when designing an online form, you can ask whether every field is necessary, whether free-text boxes could collect too much information, who needs access, whether the data must be exported, how long it will be kept, and how users receive privacy information.
A Data Protection Impact Assessment is required under the GDPR when planned processing is likely to result in a high risk to people's rights and freedoms. A DPIA helps describe the processing, assess necessity and proportionality, identify risks, and define measures to reduce those risks. Trainees can contribute practical knowledge about workflows, but the organisation should involve qualified staff and the DPO.
Practical Case Study: A Training Allowance Application
You work in an administrative office that processes applications for a training allowance. The old paper form asks for the applicant's name, address, bank details, health information, marital status, private social-media account, and a copy of an identity document. Staff scan every form, save copies in a shared folder available to the whole department, and keep the paper originals indefinitely.
Analyse the workflow using the GDPR principles. Some information may be necessary, while other information may not be justified. Access should be limited to staff who need it. Retention needs a defined rule. Sensitive information requires particular care. Copies of identity documents should not be collected merely “just in case.” A better process begins with the legal purpose, then determines the minimum information, access, security, transparency, and retention needed to achieve that purpose.
Workplace Decision Checklist
Before handling personal data, use this short professional checklist.
| Question | What to do |
|---|---|
| Do I need this data? | Collect or open only what is necessary for the task. |
| Am I allowed to use it for this purpose? | Check the approved process and legal basis. |
| Who needs access? | Limit access and recipients to authorised people. |
| Is the transfer secure? | Use approved systems and verify recipients. |
| How long should it remain? | Follow the retention or archival schedule. |
| Could this be a request or breach? | Route it immediately through the correct internal procedure. |
| Am I unsure? | Ask a supervisor, specialist team, or DPO before taking a risky action. |
Reliable Reference Points
For real workplace decisions, use authoritative guidance and the legal text rather than memory alone. Useful reference points include the General Data Protection Regulation, your national Data Protection Authority, and your organisation's own approved privacy, retention, access-control, and incident-response procedures.
The European Commission explains GDPR principles, rights, legal grounds, and obligations for public authorities. The European Data Protection Board publishes guidance on breach handling and other GDPR topics. These sources are especially useful when a classroom example becomes a real administrative case.
Interactive Tasks
Quiz: Test Your Knowledge
Which GDPR principle says that you should collect only data necessary for a defined purpose? (Data minimisation) (!Storage limitation) (!Accuracy) (!Accountability)
What should you do first when you suspect that personal data was sent to the wrong recipient? (Report the incident internally without delay) (!Wait until the next staff meeting) (!Delete all related records) (!Contact the media)
Which role determines the purposes and essential means of processing personal data? (Controller) (!Processor) (!Data subject) (!Recipient)
Which practice best follows the need-to-know principle? (Give staff only the access required for their role) (!Give every employee access to all files) (!Share one login across the team) (!Keep access after a role changes)
Which item can be personal data? (Employee identification number) (!Empty cardboard box) (!Blank sheet of paper) (!Unlabelled office chair)
Which legal basis is especially common for public authorities carrying out statutory duties? (Public task) (!Advertising preference) (!Office tradition) (!Personal curiosity)
What does storage limitation require? (Keep personal data no longer than necessary) (!Keep every record forever) (!Delete every record immediately) (!Store all records on personal devices)
What is a good response to a request for access to personal data? (Record and route the request through the approved procedure) (!Ignore it unless legal words are used) (!Promise immediate deletion of all records) (!Forward the request to unrelated colleagues)
Which action best supports data protection by default? (Use settings that limit unnecessary access) (!Open all records to every user) (!Collect extra fields for possible future use) (!Disable retention controls)
What is the main purpose of a Data Protection Impact Assessment? (Assess and reduce high risks in planned processing) (!Replace all staff training) (!Create marketing slogans) (!Remove the need for security controls)
Memory Game
| Data minimisation | Collect only the personal data necessary for the purpose |
| Controller | Decides why and how personal data is processed |
| Processor | Handles personal data on behalf of a controller |
| Rectification | Correction of inaccurate or incomplete personal data |
| Retention | Period for which records are kept |
| Breach | Security incident affecting personal data |
Drag and Drop
| Match the correct terms. | Topic |
|---|---|
| Collect only what the task needs | Data minimisation |
| Correct inaccurate records | Accuracy |
| Limit records to authorised staff | Confidentiality |
| Remove records after the approved period | Storage limitation |
| Show how rules are followed | Accountability |
Crossword Puzzle
| Consent | Which lawful basis depends on a freely given and informed agreement? |
| Controller | Who determines the purposes and essential means of processing? |
| Processor | Who handles data on behalf of a controller? |
| Accuracy | Which principle requires relevant personal data to be correct? |
| Encryption | What security method makes data unreadable without the required key? |
| Retention | What term describes how long records are kept? |
LearningApps
Cloze Text
Open-Ended Tasks
Easy
- Data Spotting Walk: Inspect a fictional or teacher-prepared office workspace and list where personal data appears on screens, paper, labels, calendars, or storage areas; do not use real confidential records.
- Clean Desk Poster: Create a one-page visual guide showing how an apprentice can protect paper records, screens, notes, and printouts at the end of a work session.
- Phishing Red Flags: Produce an annotated image or short slide showing at least five warning signs in a fictional phishing email and explain the safe response.
- Privacy Vocabulary Interview: Interview a classmate about the meanings of controller, processor, data subject, DPO, retention, and breach, then write a short correction guide for any misunderstandings.
Standard
- Application Form Audit: Review a fictional administrative form and justify which fields are necessary, which should be optional, and which should be removed under data minimisation.
- Data Flow Map: Draw the journey of data through an administrative process from collection to deletion, including users, systems, transfers, and storage points.
- Rights Request Role Play: Record a short role-play video in which a citizen or customer makes an access or rectification request and an apprentice responds professionally without promising an unauthorised outcome.
- Retention Interview: Interview a records manager, supervisor, or teacher about how retention periods are decided and compare the answer with an approved retention schedule or classroom example.
Advanced
- Breach Response Simulation: Analyse a scenario in which an attachment is sent to the wrong recipient, create an incident timeline, identify immediate containment steps, and explain which facts the responsible team needs for its risk assessment.
- Privacy by Design Prototype: Redesign a fictional online administrative form so that required fields, optional fields, privacy information, access rights, and retention choices reflect data protection by design and by default.
- DPIA Workshop: In a group, prepare a simplified DPIA for a fictional high-risk administrative system, describing purpose, necessity, risks to people, and proposed safeguards.
- Administration Data Protection Video: Produce a three-minute training video for new apprentices that demonstrates correct handling of email, paper files, access rights, rights requests, and incident reporting.
Learning Assessment
- Principle Transfer: Given a new administrative workflow, identify at least three data-protection principles that apply and justify specific changes to the workflow.
- Legal Basis Reasoning: Compare two fictional cases and explain why public task, legal obligation, consent, or another basis may or may not be suitable without treating legal bases as interchangeable.
- Security Decision: Evaluate a proposed method for sending sensitive records and recommend proportionate technical and organisational safeguards.
- Rights Request Analysis: Read an informal customer email, decide which data-subject right may be involved, and design a compliant internal handling path.
- Breach Triage: Analyse a realistic incident, separate immediate containment from formal notification decisions, and explain why escalation speed matters.
- Privacy by Design Review: Critique a new digital service before launch and propose changes to data fields, permissions, retention, transparency, and risk controls.
Evidence of Learning
Evidence of learning should show that you can combine knowledge with professional action. Strong evidence includes accurate explanations of personal data and GDPR principles; correct use of terms such as controller, processor, DPO, data subject, breach, and retention; safe handling of email, paper files, passwords, permissions, and shared systems; a data-flow map or process audit; a completed case analysis; a realistic response to a rights request; a breach-response record; and a privacy-by-design or DPIA-style project.
Transfer is especially important. You should be able to apply the same reasoning to an unfamiliar administrative process: define the purpose, identify the minimum necessary data, check authority and access, protect the transfer and storage, follow retention rules, recognise rights and incidents, and ask for specialist support when needed.
OERs on the Topic
Useful openly accessible reference material:
- European Commission: Principles of the GDPR
- European Commission: Application of the GDPR, including public authorities
- European Data Protection Board: Personal data breaches
Linked Learning Areas
Data protection in administration connects legal compliance with office practice, digital security, records management, public service, customer communication, human resources, and responsible use of information. Apprentices and vocational students should learn not only the rules but also how to recognise risk, document decisions, use approved systems, and escalate uncertain situations.
aiMOOC Projects
MOOCwiki · Deutsch
Nach dem Lernen ist vor dem Lernen
Entdecke direkt den nächsten Lernkurs. Weitere Inhalte erscheinen, wenn Du weiter nach unten scrollst.
Zur MOOCwiki-HauptseiteMediathek
Code entdecken · Spiele & interaktive Welten →Jahresüberblicke · Fächer & Klassen →Mediathek
Mediathek wird aus dem Wiki geladen ...
Keine passenden Inhalte gefunden. Bitte ändere Suche oder Filter.
NEWSLernweltNOAH fragen