Look out for privacy issues!

Christiane Steinmetz explains the biggest traps and how they can be avoided

Data protection doesn’t only apply to legal texts but also to our everyday lives. We often just don’t think about it. An email that goes unchecked, a photo shared without consideration – and things can get tricky. In her interview, our Data Protection Officer Christiane Steinmetz explains which cases are actually critical, what everyone can easily bear in mind, and what needs to be done in the event of a real privacy breach.


In your private life, have you ever breached data protection guidelines and if so, what did you do? 

I imagine each of us has been in the situation with someone asking where a colleague is. “He/She is sick,” is a common response all too easily said. I have done it, too. Strictly speaking, however, this counts as disclosing a person’s health data without his/her consent, so it’s a GDPR breach. Still, you won’t have to worry about being fined.

What’s the biggest misconception employees have when it comes to the topic of Privacy?

A lot of people think that Privacy includes secret corporate data, such as patents, work instructions, or research results. But Privacy Laws actually only protect people’s details, i.e. personal data. This can include information such as an employee’s sick leave, religion, salary category, private phone number, emergency contact, or how many children someone has. Corporate secrets must still be kept confidential, of course. But it’s internal guidelines and regulations that apply to those.

What is the “most dangerous” thing someone may accidentally do during the workday without realizing?

The most dangerous situations relating to data protection occur when things are done without considering the privacy stipulations. A good example is publishing photos on social media: You took a picture at a corporate event and uploaded it to LinkedIn without asking those in it. This can quickly lead to resentment. The following therefore applies in general: First, consider data protection, then act. Internal regulations already exist for many situations, including social media. If in doubt, I’m happy to answer questions. That’s what I’m here for.

What specific tasks are part of your work as a Data Protection Officer? 

As the Data Protection Officer, I make sure that, when dealing with personal data, we’re on the safe side and don’t risk being fined. I consult specialist departments during projects and explain what is permitted in accordance with GDPR and what needs to be borne in mind. The exciting thing is that data protection is crucial everywhere in our company: from HR and Marketing to Sales and Production. Personal data may even appear on made-to-measure products. And that data needs to be protected. Training sessions and creating e-learning programs make up a large part of my work so that data protection stays relevant during our workday. I also provide support with privacy notices and I check service providers, primarily in IT. And because new laws and decisions keep being added, I never get bored.

What process needs to be followed in practice when a data protection incident happens? 

If a data protection incident happens, for example, an email with sensitive data is sent in error, one thing is absolutely crucial: Report it immediately, no matter whether you made the mistake yourself or just happened to notice it. From the moment the incident becomes public, a legal deadline of 72 hours starts during which we assess the case and may have to report it to the supervisory authority. Every hour counts, even at weekends or on public holidays. A lot of people think: “Oh well, it was just a minor thing.” But oftentimes, it’s the details that are key. An email with a visible mailing list may be harmless or it may contain sensitive data. That’s why I always advise: Better phone me once too often rather than not often enough. Report incidents relating to personal data straight away and we’ll take care of the necessary steps together. You can also use the Whistleblowers’ Portal on our website for anonymous reports.

Is there a simple rule you can give to each employee, whether Admin or Production, on how to prevent privacy breaches most effectively?

There are two basic principles everyone can implement: One is common sense with the right change of perspective: How would I feel if I was the person whose data I have in front of me? The second rule is: as little data as possible, as much as necessary. So ask yourself: “Do I really need all this data that I’m trying to obtain from the other person via an online form? Or can it be cut back or can some things changed to voluntary?”

About Christiane Steinmetz

  • Joined Bauerfeind in 2008 right after leaving high school
  • Dual degree in Business Management at Gera Vocational Academy, Master’s Degree completed in Hof
  • In charge of Data Protection for Bauerfeind since 2018
  • Lives with her family and 12 horses close to Gera