Services
We offer comprehensive services. These include acting as your external data protection officer, data protection consulting, training for management and staff, and the integration of whistleblowing systems into your organisation. Which service you engage us for depends on whether you have a duty to meet, something to demonstrate or a project that calls for it.
As the external data protection officer you appoint, we take on the responsibility that comes with the role under Art.
ConsultingWe see our task as making a project possible and not shaping data protection into a brake on it.
TrainingWe teach data protection, from mandatory training for all staff to training tailored to a single department.
Whistleblowing systemsThe German Whistleblower Protection Act requires employers with, as a rule, 50 or more staff to operate an internal reporting channel, and it reverses the burden of proof for reprisals.
The shape the answer arrives in
The same service can be delivered as short advice, as a written assessment or as an audit. Which form fits depends on who the result has to be shown to.
Appointment as data protection officer
A standing responsibility with the tasks set out in Art. 39 GDPR, plus a procedure that applies as soon as something happens.
Advice during ongoing operations
An assessment, spoken or briefly in writing, where a decision is pending and no document needs to be produced.
Written assessment
The answer in writing, with a traceable path to it, suitable for management, a supervisory authority or a contractual partner.
Audit
The actual state is established, and the deviations are ordered by their weight.
Training
The knowledge moves into the organisation, and attendance is evidenced as the accountability principle requires.
Reporting channel operated by a third party
A function is taken over and kept out of internal reporting lines, sec. 14(1) HinSchG.
What are you looking for?
The questions from practice are ordered by field of law. Each of them also states the form in which we answer it.
Why the choice of legal basis decides the duties that follow, and why the effort afterwards lies in implementation rather than in the question of admissibility.
Artificial intelligenceWhy classification comes before every duty, how a business turns into a provider, and which duties a high-risk system adds for each of the two roles.
Information securityWhom NIS2, the Cyber Resilience Act and Art. 32 GDPR reach, why information security law is technology neutral, and what follows from that for implementation.