Core expertise
Further services
Podcast
Datenschutz-Puls: what matters in data protection law, every two weeks.
Focus industries
Further industries
Industries
Your industry is not listed? We advise across all sectors.
About us
Information
Podcast
Datenschutz-Puls: what matters in data protection law, every two weeks.
Designation is mandatory if at least 20 persons are regularly engaged in the automated processing of personal data, or if the core activities involve large-scale monitoring or the processing of sensitive data.
An external data protection officer is personally liable. That is why, together with ERGO and Nürnberger Versicherung, we have developed an insurance concept with cover of more than EUR 40 million.
Monitoring GDPR requirements, maintaining the record of processing activities, risk assessment, staff training and communication with the supervisory authority.
After the initial consultation and once we have been instructed, we notify the competent authority of the appointment. We discuss the specific timeline in the initial consultation.
Gap analysis, setting up the ISMS, internal audit, certification audit by an accredited body, followed by continuous improvement. We support you at every step.
That depends on how mature your organisation is; in many cases it takes a few months. After the gap analysis, we can give you a reliable estimate of the timeframe.
In particular IT and software companies, service providers with corporate clients, healthcare, finance and critical infrastructure. The trigger is usually a requirement from a major client.
Yes. A well-structured ISMS also covers the requirements of the GDPR, NIS2 and DORA. We integrate the different frameworks into the same structure.
Every company that uses or offers AI systems. The EU AI Act has no size threshold. What matters is which systems are in use and which risk class they fall into.
In principle, all systems used in the company, including purchased tools and generative AI. The assessment clarifies the risk class, legal bases and documentation obligations.
The EU AI Act divides AI systems into risk classes and attaches obligations to them: from transparency and labelling obligations to extensive requirements for high-risk systems.
Yes. The GDPR requires staff who work with personal data to be trained. The legal data academy ensures that these training requirements are met.
The platform documents completed training automatically. In the event of an audit or an inspection by the authorities, the evidence is available.
Data protection under the GDPR, information security with awareness training and the compliant use of AI tools.
You receive an individual fixed-fee offer instead of open-ended hourly rates. The fee depends on the size and complexity of your company.
Our engagement agreement is based purely on trust and can be terminated at any time. We retain clients through quality, not through minimum terms.
We do not use tracking or marketing cookies. Only your choice is stored. External media such as the Apple Podcasts player are loaded only with your consent, in which case your IP address is transmitted to Apple. You can change your choice at any time via "Cookie settings" in the footer.