23 YEARS

Ensuring information protection

Case Study

LIDL

Lidl is the leading German company in the distribution sector, with a presence throughout Europe and more than 450 supermarkets in Spain.

Needs

As a measure to improve the protection of personal data and enhance internal security, the company decided to initiate a project to comply with the LOPD 15/1999 regulation. The objective was to implement practices for handling personal data safely and efficiently.

Description of the consultancy

The primary objective of the project has been to develop a LOPD Adaptation Plan, which includes the creation of a Security Document and the implementation of an Action Plan with the necessary level of detail to comply with the requirements of the LOPD Regulation. This project aims to achieve the following objectives:

  • Establish LIDL’s general guidelines for personal data security (DCP).
  • Identify the information systems that handle DCP, defining the file structure and user profiles with access to personal data.
  • Develop the necessary regulations and procedures to comply with the law, to regulate the use of DCP.
  • Establish the security organization responsible for administering, managing, and controlling DCP security.
  • Conduct a diagnostic assessment to identify any security gaps in the current system.

Results

After completing this project, the company implemented all the measures identified in the project regarding data protection. It has successfully addressed security improvements that were identified during the project execution. A notable achievement is that the entire organization, including both the headquarters and branches, has been educated about the appropriate handling of personal data. Furthermore, procedures have been established to ensure compliance with personal data protection regulations.