Skip to content
Data protection as a service | HIIG

Data Protection as a Service


The EU General Data Protection Regulation (GDPR) requires website and blog owners to comply with legal requirements on data protection. In order to be able to achieve this at all, operators must have both comprehensive technical and legal knowledge: they must be able to understand the technology they operate with in order to identify risks to fundamental rights, andthey must be able to select, configure and operate the technology competently in order to prevent violations of data subjects’ fundamental rights.

In the past, knowledge uncertainties have led to small websites and blogs being shut down on a massive scale. This became known as “website dying”. The consequences are serious, not only for the website owners themselves. If websites are not set up in accordance with data protection regulations the fundamental rights of data subjects will be at risk, mainly due to a lack of competence on the part of data controller. 

The most obvious and yet promising approach to solving this problem is to involve the data processor, the hosting providers. They have the technical resources at hand, the infrastructure and the legal expertise necessary in order to comply with data protection laws. 

In this research project we are developing, together with several research partners, solutions that help website owners to overcome their knowledge uncertainties. By specifying GDPR provisions regarding the operation of websites, we create certification criteria that determine how hosting providers can help website owners to operate their website or blog in accordance with the GDPR. These hosting providers can, on the other hand, signal this help to their (potential) customers as a product feature and thus gain a competitive advantage over their competitors. 

Taking off from here, this basic research project will be extended to other areas relevant to data protection law beyond website hosting. In parallel, the economic implications of these mechanisms will be researched, with the project ultimately contributing to the standardisation in the data protection field und push the state of the art in technical and organisational protection measures.

StartJanuary 2019


Maximilian von Grafenstein, Prof. Dr.

Associated Researcher, Co-Head of Research Programme

Jörg Pohle, Dr.

Head of Research Program: Actors, Data and Infrastructures

Part of the research programme

Former employees

  • Kevin Klug
    Former Associated researcher: Governance of Data-Driven Innovation

Working paper

Grafenstein, M. v., Pallas, J., & Pohle, J. (2021). Datenschutz durch Technikgestaltung gem. Art. 25 Abs. 1 DS-GVO. HIIG Discussion Paper Series, 2021(5). DOI: 10.5281/zenodo.6325328 Publication details

Organisation of events

Datenschutz by Design in der (Vollzugs)Praxis – Workshop für Expert*innen
From 28.10.2021 to 28.10.2021. Humboldt Institut für Internet und Gesellschaft, Berlin, Germany. Co-Organised by: Alexander Dix (EAID), Frank Pallas (TU Berlin) (National) Further information

Maximilian von Grafenstein, Jörg Pohle