What data protection really means in practice – beyond technology and theory
Data protection is a responsibility – 7 Lessons Learned from case management practice with Comitas
Digital case management projects often focus on encryption, hosting, and access rights. But anyone familiar with the day-to-day realities of social organizations knows that data protection encompasses much more. Through collaboration with government agencies, counseling centers, and professionals, Comitas has not only developed IT solutions but also gained deeper insights. Here are seven key takeaways from practical experience—and they'll stay with you.
1. Data protection often fails due to everyday logic.
Violations of data protection laws or GDPR regulations arise not only from security gaps, but also from unclear everyday procedures. If it is not clear where which social data is stored or who is authorized to process it, even technical safeguards are of little use. Data protection needs to be practical for everyday use – otherwise, it will be circumvented.
2. Professionals must be able to live data protection intuitively.
Especially in social services, the roles are diverse: counseling, administration, quality assurance. Data protection only succeeds if digital tools are designed to adapt to practical application – not the other way around. Those who understand the solution will protect data naturally.
3. Every project brings new ethical questions with it.
The implementation of digital case files forces teams to rethink responsibility: What really belongs in the system? How much closeness to the client can be documented? Experience shows that data protection is often also a question of attitude – and requires space for discussion.
4. Data protection is not a topic "for later"
Data protection is often only examined at the end of a digital project. However, experience shows that considering data sovereignty and security issues from the outset saves considerable effort later on and prevents conflicts. A clear approach from planning to training is crucial.
5. Technological solutions alone will not solve a trust problem.
Even the best case management software cannot replace the trust that clients and professionals place in the organization. Data protection must be embedded in the culture – not as a mere obligation, but as a matter of course.
6. Data protection needs advocates – internally and externally.
For data protection to be truly practiced, it requires people who champion it: in project management, in the specialist team, and in IT. This can only succeed if data protection is not treated in isolation.
7. Digitalization and data protection must reinforce each other.
Digitalization in the social sector is not at odds with the protection of sensitive information – quite the opposite. The best projects demonstrate that when systems are understandable, consistent, and well-designed, data protection becomes easier, not more difficult. It's not about control, but about quality.
Conclusion
Data protection in case management is not a purely technical discipline, but an expression of responsibility. Those who take it seriously create trust, stability, and long-term quality – for clients, employees, and society. Reflections from Comitas's practical experience show that data protection is not the keystone of digitalization, but its foundation.
We would be happy to show you the essential technical aspects for a secure and data protection-compliant solution in a non-binding demo and also support you with organizational adjustments.

