The increasing interconnectedness of production systems and the use of IoT devices generates a considerable amount of employee or customer data - whether directly or indirectly. The EU General Data Protection Regulation (EU-GDPR), effective 25 May 2018, results in a massive increase in the rights of data subjects and documentation obligations arising from the processing of personal data [1]. Those who do not respect these rights and/or fail to comply with their obligations face painfully increased fines of up to EUR 10 million (in serious cases EUR 20 million) or 2 % (4 %) of the annual turnover.