HIGH-LEVEL, PROFESSIONAL IMPLEMENTATION OF DATA PRIVACY AND THE GDPR BY DSMS
GEMDAT OÖ GmbH & Co. KG Success Story
THE CUSTOMER
GEMDAT OÖ GmbH & Co. KG provides customized IT solutions to approximately 430 Austrian municipalities and more than 100 associations. With over 40 years of experience, GEMDAT is the leading IT provider for municipalities in Upper Austria. Its solutions are scalable to accommodate municipalities of various sizes.
Focus on core business activities thanks to a clear overview and significant time savings
Situation
In addition to numerous IT services, GEMDAT’s service package also includes the role of external data protection officer. To maintain an overview of the more than 400 municipalities it serves, work with maximum efficiency, and implement top-tier data protection management, GEMDAT relies on the AKARION GRC Cloud.
The standards here are naturally high: Especially in the public sector, exemplary handling and highly professional implementation of data privacy and the GDPR are essential.
Solution
Key aspects essential to GEMDAT—such as processing activities, audits, and the resulting recommendations for action—are perfectly mapped in the AKARION GRC Cloud. Thanks to the multi-tenant functionality and inheritance logic, which enable changes to be rolled out centrally, GEMDAT’s data privacy coordinators can provide optimal support to the municipalities. Added to this is the significant added value of a simple and secure whistleblowing module, which applies in Austria to municipalities with 10,000 or more residents.
The major challenge lies in the need for up-to-date information, explains Christoph Obermayr, who is responsible for data privacy and security at GEMDAT: “The municipalities are largely structured similarly, yet the tasks vary slightly.” The GRC Cloud meets these requirements very well, which plays a particularly important role during the annual audit. Progress can be precisely documented using the GRC Cloud tool.
GEMDAT has set up its own template account in the AKARION GR Cloud and uses it for its entire client base. The templates can still be customized individually. This results in enormous time savings. A particular advantage is that the client and the external data protection officers—namely GEMDAT—can access the same data set at the same time.
Result
By using the AKARION GRC Cloud, GEMDAT saves a tremendous amount of time and can maintain and even improve the quality of its support services. An additional benefit is that all key topics are mapped within a single tool, allowing GEMDAT to focus on technical matters. The template is then immediately put to use for 400 municipalities. On a smaller scale, this also applies to the topic of whistleblowing. For GEMDAT’s clients, it is also important that AKARION is ISO 27001 certified.
“In the case of data breaches, the GRC Cloud helps tremendously with its detailed documentation,” Christoph Obermayr continues. “The GRC Cloud excellently addresses the requirements of the GDPR. In the risk matrix, you can immediately determine whether a notification to the affected parties or the data protection authority is necessary.”
Managing Director Daniel Holzer adds that a key factor in choosing to work with AKARION was the company’s strong customer focus and collaborative approach. Conversely, AKARION has also benefited from the partnership with GEMDAT, as the modules have consistently met new requirements. The GRC Cloud offers extensive functionality while remaining highly customizable. GEMDAT is an excellent example of what it means to work in a corporate setting. Many of the outcomes resulting from the collaboration between GEMDAT and AKARION also benefit other customers in similar fields of activity. The GRC Cloud’s mission is to provide companies with a roadmap for these issues. With this support, customers can then efficiently address these very issues.





