Back to projects
Data Privacy · Governance · Digital EthicsIndividual academic work

GDPR Data Governance Review for Maquillados Martínez

Data privacy and ethics case applied to CRM, cookies, and automated profiling.

Type

Individual academic work

Area

Data Privacy · Governance · Digital Ethics

Tools

GDPR framework · AEPD criteria

Techniques

GDPR analysis · Consent audit · Legal basis mapping · Cookie consent · Profiling risk

Output

GDPR risk diagnosis and recommendations

Value

Individual academic work where I evaluated data processing, consent, cookies, and automated profiling under GDPR to extract governance risks and recommendations.

25/05/2018

key GDPR application date analysed

Art. 6

legal bases evaluated

Art. 9

special categories of data

Art. 22

automated profiling reviewed

01 / Fast scan

Case in 60 seconds

A quick scan of the case: what was happening, what needed to be solved, what I did, and what value is demonstrated.

Situation

S

Marketing, CRM, and analytics work with personal data. Decision-making must balance commercial activation with compliance, transparency, and processing limits.

Task

T

Individual academic work where I evaluated data processing, consent, cookies, and automated profiling under GDPR to extract governance risks and recommendations.

Action

A
  1. 01Identify processing activities and purposes.
  2. 02Evaluate legal basis and consent.
  3. 03Detect risks in cookies and profiling.
  4. 04Translate risks into governance recommendations.

Result

R
  • Tacit consent, inactivity, or pre-ticked boxes would not be sufficient under GDPR.
  • Scrolling cannot be considered valid cookie consent under AEPD guidance.
  • Philosophical beliefs are special-category data and increase automated-profiling risk.
  • Useful for CRM/BI and marketing analytics because it adds privacy judgement before activating data.
  • Reduces operational and reputational risk in campaigns and personalisation.
  • 25/05/2018 · key GDPR application date analysed

02 / Context

Problem

This section explains the business or analytical challenge before going into technical detail.

02.1

Executive summary

Short but useful case to show governance judgement: not every actionable data point should be used without assessing legal basis, consent, minimisation, and profiling risk.

02.2

My role

Individual academic work. I analysed the case through GDPR, consent criteria, legal basis, cookies, and profiling.

03 / Method

Approach

Methods, tools, and workflow. This shows how I structured the analysis.

03.1

Data & methods

  • Evaluation of consent prior to 25 May 2018 and the company's burden of proof.
  • Legal-basis mapping for employee data: legal obligation, contract, legitimate interest, and special categories.
  • Review of principles: purpose limitation, minimisation, accuracy, and storage limitation.
  • Analysis of cookies and automated profiling involving special categories of data.

03.2

Process

  1. 01Identify processing activities and purposes.
  2. 02Evaluate legal basis and consent.
  3. 03Detect risks in cookies and profiling.
  4. 04Translate risks into governance recommendations.

04 / Decision

Evidence and impact

Outputs, findings, and implications translated into decisions or professional value.

04.1

Key findings

  • Tacit consent, inactivity, or pre-ticked boxes would not be sufficient under GDPR.
  • Scrolling cannot be considered valid cookie consent under AEPD guidance.
  • Philosophical beliefs are special-category data and increase automated-profiling risk.
  • The historical database must be reviewed through purpose, minimisation, accuracy, and retention.

04.2

Business implications

  • Useful for CRM/BI and marketing analytics because it adds privacy judgement before activating data.
  • Reduces operational and reputational risk in campaigns and personalisation.

05 / Close

Professional close

Limitations, next steps, and available assets. This keeps the case honest and actionable.

05.1

Limitations

  • Individual academic work on a legal/business case.
  • Does not replace professional legal advice.

05.2

What I would do next

  • Turn findings into a CRM/cookie checklist.
  • Design a measurable consent-management workflow.

05.3

Assets

View summaryComing soonSummary can be expanded if needed.

Keep reading

Related projects

Cases connected by area, method, or decision type. Use them to follow an analytical thread without returning to the full list.

Next project

Sales BI Dashboard Structure & KPI Evaluation