From startup to scaleup: how to deal with data protection and compliance

As your company evolves from startup to scale-up and beyond you will face a changing set of data protection and security challenges. In this article we illustrate this using the journey of a fictional B2B digital health startup.

As your company evolves from startup to scale-up and beyond you will face a changing set of data protection and security challenges. In this article we illustrate this using the journey of a fictional B2B digital health startup.

Startup: Understanding the scope of data you collect

Acme Digital Health (Acme DH) is a fictional company that wants to sell AI based digital health services to hospitals. More specifically, their early idea is for a system that summarises doctors notes in order to generate discharge letters. Acme DH is based in Germany and that is the first target market.

Early on, any company should start thinking about the basics of GDPR. While Acme DH is trying to work out its proper product-market fit, they already have a good idea what they will build. Their challenge at this stage is understanding which data they need to collect and the implications of these decisions. This could be a good time to complete their first DPIA.

A DPIA (Data Protection Impact Assessment) is a formal risk assessment to make sure you are complying with GDPR’s “privacy by design and by default” principles. A DPIA makes you look at each and every element of the project, process or system and analyse the impact that it has on data protection. That includes aspects like what data is being collected, how it is processed, and what legal basis you can rely on. It is a great tool during any contract due diligence.

What personal data will be collected?

Working out what types of personal data you will be processing can be challenging while you are still trying to work out your product-market fit. Acme DH know they will need access to health data, which GDPR defines as a “special category” of personal data. This data will be quite broad as it will include details of any treatments patients have received, their observations, and their medical history. Additionally, it will include a large number of identifiers, such as insurance numbers, names, dates of birth, etc.

How will the data be processed?

Having worked out which data is being collected, Acme DH needs to establish how that data is actually processed. GDPR has a really broad definition of processing. Basically, any and every action you take with personal data is processing. For Acme DH, the key question is likely to be where they perform the AI processing to create the summary. And how will they train that AI. In this case, Acme DH wants to use an EU-based cloud AI for the processing, requiring the data to be sent outside of the hospital. They also want to train their algorithms with real data. All these decisions should be written in a Register of Processing Activities.

Legal basis for processing

GDPR requires all data processing to be ”lawful”. This means you must determine a valid legal basis for any data processing. Acme DH will need both an Article 5 basis (for the general personal data they collect) and an Article 9 basis (for the health data). We wrote extensively about choosing a legal basis before. Briefly, for Acme DH there are likely to be a couple of options:

  • Public interest for health reasons. GDPR article 9 allows health data to be processed to ensure “high standards of quality and safety of health care and of medicinal products or medical devices”.
  • Explicit (informed) consent of the patients. This requires every patient to explicitly give consent to their data being processed in this way. This is probably going to be required for any data that is also being used for training their AI.

For the sake of our example, let’s assume Acme DH chooses to go with explicit consent for the additional flexibility it offers.

GTM: GDPR compliant from the start

As soon as Acme DH launches they need to have certain minimum GDPR requirements in place.

Privacy Policy and Notice

Every company needs to have a privacy policy, which is a detailed internal document explaining exactly how you handle personal data as a company. You will also need to display a Privacy Notice to any users.

A privacy notice is a simple-to-understand document that sets out details of how you process personal data. It explains exactly which data is collected, why it’s collected (the legal basis), how it is processed, how long the data is kept, and whether the data is shared with anyone else. This is essential to meet the transparency principle set out in the GDPR.

Register of Processing Activities

We already mentioned this document. The register of processing activities or RoPA is a living document that explains exactly which data you are collecting, why you collect it, where and how it is processed, and how long it is kept for. This document should be updated regularly and will be important if you are every audited for GDPR compliance.

Data Processing Agreements

Acme DH will need to have data processing agreements (DPA) in place with all their technical partners (cloud services, AI providers, etc). They will also need to have a DPA with each client. This document is a formal contract setting out how any personal data is processed and protected. It should include details such as where data and backups are stored, how long data are kept, and which services are able to access the data.

Data Protection Officer (DPO)

A data protection officer is an independent 3rd party data protection expert appointed to help you handle GDPR issues. These include data subject rights, data breaches, and more. Every country has different rules relating to DPOs. In Germany, a DPO is needed pretty early on, and we strongly recommend any company to appoint one. However, as a pre-launch startup, Acme DH likely only needs a “nameplate” DPO. That will change once they sign their first contract.

Winning the first contract: ISO 27001 and other proofs of competence

In the B2B digital health space, winning your first contract can be pretty challenging. Hospitals in particular are wary about trusting an unproven company. Therefore, your big challenge is to prove that you can be trusted as a potential partner. One of the best ways to do this is via external certifications.

ISO 27001

The classic first certification we recommend for B2B startups is ISO 27001. This widely recognised standard assesses whether a company meets stringent requirements for cybersecurity. Acme DH can use ISO 27001 to prove they are taking security seriously, and have proper processes and policies in place. Once, this would have been a hugely expensive certificate to obtain. But now, platforms like ours coupled with a competitive market for certification bodies mean you can get the certificate for a few thousand euros.

BSI certifications

Within Germany, there are a number of specific certificates issued by the BSI (federal cybersecurity institute). For digital health applications, BSI TR-03161 Requirements for applications in healthcare is the most relevant. Acme DH might want to consider complying with this standard even if they don’t undergo certification.

Cyber Resilience Act (CRA)

The above advice primarily applies for B2B startups. In the B2C space things are more relaxed. However, this will change as we see the roll out of the Cyber Resilience Act (CRA) between now and the end of 2027. This may apply to Acme DH if their service will be connected to the Internet. Here are the key points:

  • Secure by default will be the new watchword. If your product can connect to the internet, it must automatically be secured.
  • All products will have to declare they meet the requirements. For some products, such as fitness trackers, this has to be assessed by a notified body.
  • All vulnerabilities and suspected cybersecurity incidents must be reported in a central ENISA database.
  • Manufacturers must issue security patches for the entire support lifecycle of the product (expected to be 5 years by default).

Scale Up: Going the extra distance for complete compliance

Once a company reaches scale up, the compliance requirements evolve. Here are the key differences.

In-house expertise

Most scale up companies choose to appoint someone in-house to help coordinate compliance matters. This person doesn’t need deep expertise in every field, but they should have some knowledge in cybersecurity or data protection. Ideally, they should also be able to call on external experts.

Experienced DPO

The most important thing at this stage is that your DPO is no longer just a nameplate. As a scale up you face much bigger data protection risks, and the authorities will also expect you to achieve a much higher level of compliance. That means you now need a really experienced DPO who can also call on a team of people to support them if you suffer a data breach. BTW it’s worth remembering, if one of your service providers suffers a breach, you also have to react to this.

Additional certifications

At this stage, you might need to increase the number of certifications you have. Acme DH might look at getting the relatively new ISO 42001 for AI. If they want to target the US market, they could apply for SOC 2 certification. The aim isn’t to just collect certificates for the sake of it. You are trying to select certificates that will demonstrate your commitment to compliance, or which are required to break into new markets or to bid for specific contracts and expand your business.

Conclusions

As we have seen, as a company grows they face a constantly changing landscape for data protection and cybersecurity. As a result, they need to handle compliance differently. Here at Chino.io we have developed a flexible compliance framework that is designed to grow and evolve with your company. Hopefully, this article has given you some idea of what to expect, especially in the B2B digital health space. Of course, much of the above also applies in other spaces, especially if you are handling any sensitive or special category data.

Streamline Your Compliance With Chino.io Today

Discover our
Templates