M. Esperanza Dorado Pérez
The implementation of the General Data Protection Regulation (GDPR) marked a paradigm shift in public administration, moving from a formal and reactive compliance model to one based on proactive responsibility and risk management. In this context, the Regional Government of Andalusia has developed a corporate methodology for risk analysis and impact assessment that ensures homogeneous, verifiable, and sustainable compliance within an organisation characterised by significant structural, functional, and technological complexity. Using the Andalusian Government as a case study, this article examines the multilevel governance model that underpins this methodology, structured through a combination of strategic centralisation, operational decentralisation, and a strengthened role for the network of Data Protection Officers. It also analyses the methodology’s capacity to integrate regulatory, technological, and organisational dimensions, positioning it as a strategic tool that enhances traceability, documentation quality, and responsiveness to audits and inspections. Based on the experience gained since its implementation, the article identifies future lines of development aimed at reinforcing continuous improvement, developing technological support tools, incorporating specific risk factors for artificial intelligence processing, and advancing towards models of algorithmic governance and certification. The Andalusian experience emerges as a replicable good practice for other public administrations, contributing to the consolidation of an institutional culture grounded in transparency, accountability, and the effective protection of fundamental rights.