Answers, before you ask.

Answers to the questions clients most often ask us at the start.

Book a consultation

Data protection officer

Who needs a data protection officer?

Designation is mandatory if at least 20 persons are regularly engaged in the automated processing of personal data, or if the core activities involve large-scale monitoring or the processing of sensitive data.

What is a data protection officer liable for?

An external data protection officer is personally liable. That is why, together with ERGO and Nürnberger Versicherung, we have developed an insurance concept with cover of more than EUR 40 million.

What does a data protection officer do?

Monitoring GDPR requirements, maintaining the record of processing activities, risk assessment, staff training and communication with the supervisory authority.

How quickly can the appointment take place?

After the initial consultation and once we have been instructed, we notify the competent authority of the appointment. We discuss the specific timeline in the initial consultation.

ISO 27001

How does certification work?

Gap analysis, setting up the ISMS, internal audit, certification audit by an accredited body, followed by continuous improvement. We support you at every step.

How long does it take to get certified?

That depends on how mature your organisation is; in many cases it takes a few months. After the gap analysis, we can give you a reliable estimate of the timeframe.

Who needs ISO 27001?

In particular IT and software companies, service providers with corporate clients, healthcare, finance and critical infrastructure. The trigger is usually a requirement from a major client.

Can ISO 27001 be combined with the GDPR, NIS2 and DORA?

Yes. A well-structured ISMS also covers the requirements of the GDPR, NIS2 and DORA. We integrate the different frameworks into the same structure.

AI compliance

Which companies need AI compliance?

Every company that uses or offers AI systems. The EU AI Act has no size threshold. What matters is which systems are in use and which risk class they fall into.

Which AI systems need to be assessed?

In principle, all systems used in the company, including purchased tools and generative AI. The assessment clarifies the risk class, legal bases and documentation obligations.

What does the EU AI Act regulate?

The EU AI Act divides AI systems into risk classes and attaches obligations to them: from transparency and labelling obligations to extensive requirements for high-risk systems.

Training

Is data protection training mandatory?

Yes. The GDPR requires staff who work with personal data to be trained. The legal data academy ensures that these training requirements are met.

How is evidence for the authority produced?

The platform documents completed training automatically. In the event of an audit or an inspection by the authorities, the evidence is available.

Which topics does the academy cover?

Data protection under the GDPR, information security with awareness training and the compliant use of AI tools.

Working together and fees

What does working with you cost?

You receive an individual fixed-fee offer instead of open-ended hourly rates. The fee depends on the size and complexity of your company.

How long am I tied in?

Our engagement agreement is based purely on trust and can be terminated at any time. We retain clients through quality, not through minimum terms.

Your question was not answered?

Then it is one for the initial consultation. 20 minutes, no obligation.