GDPR and your dashboards: what to sort out
GDPR does not forbid analysis. It asks that you know what you hold, why and for how long. What that means in practice for your reports.
GDPR mostly frightens smaller companies. And that fear leads to two bad reactions: sorting out nothing, or no longer daring to measure anything. Both are wrong.
For reporting, GDPR comes down to a handful of habits. This is not legal advice, but it is what I apply in practice.
Usually you do not need people
Most management information is about revenue, margin, costs and stock. There is not a single person in any of that.
You run into people in three places: with private customers, with your staff (pay, absence) and in your web analytics. A company as a customer is not personal data, the contact person at that company is.
So ask one question per report: do I need to know who, or is how many enough? Almost always, how many is enough. Absence per department, not per name. Customers per segment, not per person.
Aggregate early
Do not carry personal data into your reporting layer if the report does not need it. What is not in your database cannot leak.
If you do need to follow individuals, for example how often a customer comes back, use a customer number instead of a name. But know that it is still personal data as long as someone can link the number to a name. It reduces the risk, it does not remove it.
Know what for and for how long
Data you collect to invoice, you also use to report. That is usually fine, provided you can explain what you use it for.
The retention period is harder. For analysis, history is gold, but you may not keep personal data forever. The solution is simpler than it looks: keep the history aggregated. The name disappears, the count stays. Five years from now you still know how many customers came back in March, without knowing who.
Who else touches your data
Every party that processes data on your behalf is a processor under GDPR. Your payroll provider, your cloud database, and also whoever builds your reports. With each of them there should be a data processing agreement.
Anyone who builds a dashboard for you and has access to your data should put that agreement in front of you. If they do not, ask for it. And ask where the servers are while you are at it. Inside the EU is simplest.
The same goes for AI. Pasting a customer list into a public chatbot is also processing by a third party, just without an agreement.
Access and leaks
Who gets to see what is half the work, and that was the subject of the previous article. The other half is what you do when it goes wrong anyway.
If personal data leaks, you generally have to report it to the data protection authority within 72 hours. In Belgium that is the Gegevensbeschermingsautoriteit. The typical leak at a smaller company is not a hacker. It is an Excel export with names in it that goes to the wrong address.
What GDPR does not ask
GDPR does not forbid analysis. It asks that you know what you hold, why you hold it and how long you keep it. Anyone who can explain that for their reporting is right for the vast majority of it.
The claim
For reporting, GDPR is not a brake but a design rule: measure how many, not who, unless you really need who.