Data Protection Management
Filter posts
Reset filter
Data protection violation
Data Protection in Practice
AI & Innovation
Social Media
Digital Services & Tools
Cyber Threats & Incidents
Information Security & Standards
GDPR & Legal
Data Protection Management
Data Protection Officer
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Schrems III is coming: What a US ruling means for data transfers by European companies
Does your company use Microsoft 365, Google Workspace, Salesforce, or AWS? If so, you are transferring personal data to the United States. Transatlantic data transfers were previously legally secure, but a US Supreme Court ruling in June 2026 has shaken this foundation. Almost every organization in Europe is affected.
Data Protection Management
Digital Services & Tools

The best path to a robust ISMS: implementation steps
A robust Information Security Management System (ISMS) forms the backbone of an effective corporate security strategy. Learn how to implement such a system in your company to keep hackers at bay.
Information Security & Standards
Data Protection Management
Data Protection in Practice

The Data Protection Audit: Definition, Process, and Questionnaire
A GDPR data protection audit offers small and medium-sized enterprises (SMEs) the opportunity to voluntarily have their data protection compliance reviewed and to demonstrate it externally through a certificate. Find out what to expect during preparation and the audit process.
GDPR & Legal
Data Protection Management

Data Protection Risk Analysis: Structure, Process, and Practical Examples
The GDPR is based on a simple principle: the higher the risk to the individuals involved, the more extensive the protective measures must be. Risk analysis is therefore the foundation for almost all data protection decisions within a company—from selecting technical measures and reporting data breaches to determining whether a data protection impact assessment is required. This article explains how it works in practice.
Information Security & Standards
Data Protection Management
Data Protection in Practice

Terms and Conditions, Privacy Policy, and Terms of Use on your website: Separate or together?
If you are searching for "terms and conditions privacy policy," you are usually looking for two things: legal clarity and a practical solution. In practice, the rule is almost always the same: terms and conditions, privacy policies, and terms of use are distinct legal instruments—each with different requirements regarding content, presentation, and implementation.
GDPR & Legal
Data Protection in Practice
Data Protection Management

Technical and Organizational Measures (TOMs): A Guide to GDPR Compliance
The General Data Protection Regulation (GDPR) requires companies to implement technical and organizational measures (TOMs) to ensure the secure processing of personal data. TOMs are the foundation of any GDPR-compliant data processing. In this guide, you will learn which measures are mandatory, how the 14 control areas work, and how to document your TOMs in a legally compliant manner—including practical tips for remote work and data processing agreements.
Data Protection in Practice
Information Security & Standards
Data Protection Management

reCAPTCHA & Data Privacy: Is it GDPR compliant?
After years of criticism from data protection authorities, Google is taking action: starting April 2, 2026, Google will process reCAPTCHA data under a data processing agreement (DPA). This article explains what this means for your company and the steps you need to take now.
GDPR & Legal
Information Security & Standards
Data Protection Management
Data Protection in Practice

Data protection in accounting: Securing financial data in compliance with GDPR
Anyone responsible for accounting within a company handles sensitive financial data on a daily basis. This makes data protection in accounting indispensable for any business. Learn how to keep your financial data GDPR-compliant, even as you increasingly digitize your accounting processes.
Data Protection Management
Data Protection in Practice

TIA – The Transfer Impact Assessment
Do you need to enter into SCCs because you transfer personal data to a non-European processor? In addition to SCCs, a TIA is now required for this. But what exactly is a Transfer Impact Assessment and how is it prepared? We explain.
GDPR & Legal
Data Protection Management
Data Protection in Practice

Pseudonymization vs. Anonymization: What is the difference?
Pseudonymization and anonymization can simplify data protection compliance for companies. Yet, these two terms often still leave many questions unanswered. We’re here to clear things up.
Data Protection Management
GDPR & Legal

Record of Processing Activities (ROPA) under GDPR
Create your record of processing activities in a legally compliant and digital format.
GDPR & Legal
Data Protection Management
Data Protection in Practice

Data processing
A wide range of data protection regulations is linked to the term "processing of personal data." Companies should therefore familiarize themselves with the concept of data processing and the underlying legal provisions in order to accurately fulfill their own data protection obligations and responsibilities.
GDPR & Legal
Data Protection Management

Password Privacy: How Secure Are the Alternatives?
In an increasingly digitized world, passwords serve as the first line of defense for our personal data. But how secure are these traditional passwords really? Given the constant evolution of technology and the growing threat of cybercrime, it is essential to evaluate and understand various authentication methods.
Cyber Threats & Incidents
Data Protection Management
Data Protection in Practice
Information Security & Standards

Data protection as the foundation for IT security?
IT companies are facing major challenges: cyber threats are growing, yet they cannot afford to fall behind in the digitalization race. Here is how data protection helps balance IT security with progress.
Information Security & Standards
Data Protection Management
Data Protection in Practice

Privacy by Design & Privacy by Default
The GDPR mandates data protection through technology design via privacy by design. Furthermore, privacy by default is intended to ensure data-friendly settings from the outset. In practice, this does not always work as intended.
GDPR & Legal
Information Security & Standards
Data Protection Management

Data exchange: What the Data Act regulates
To improve processes, supply chains, or carbon footprints, companies need to collect data—but it only becomes truly efficient when that data is shared. What are the benefits and the hurdles? And what roles do platforms, the Data Act, and data protection officers play in this process?
Data Protection Management
GDPR & Legal
Data Protection in Practice

The story behind Google Consent Mode V2
Website operators must obtain user consent for storing and processing data when using Google Ads or Google Analytics. Since March 2024, the use of Google Consent Mode has been mandatory for them. We provide information on what this means for you in practice.
Digital Services & Tools
Data Protection Management
GDPR & Legal
Data Protection in Practice

Digitization vs. Data Privacy: The Electronic Health Card
The ongoing digitalization of the healthcare sector, particularly regarding the handling of patient data on the electronic health card (eGK), raises important questions about data privacy in medicine.
GDPR & Legal
Data Protection Management
Data Protection in Practice
Information Security & Standards
Meta Pixel & GDPR: Is tracking via Meta Pixel compliant with data protection regulations?
Whether you are already using the Meta Pixel or are just planning to implement it, here you will find everything you need to know about the data protection requirements and how to use the Meta Pixel in a way that is as GDPR-compliant as possible.
GDPR & Legal
Data Protection Management
Data Protection in Practice
Social Media
Digital Services & Tools

Privacy Policy for Apps: What App Providers Need to Know
It is not just website and online shop operators who need to address data protection; app providers are also subject to the European Union's data privacy regulations. The GDPR imposes numerous obligations on business owners, including app operators, to protect the personal data of their users.
GDPR & Legal
Data Protection in Practice
Data Protection Management

Fax & Data Protection: What are the data protection implications when transmitting information via fax?
They really do still exist—clattering fax machines that are by no means confined to dusty offices. But what about the issue of data protection and faxing? Do they actually go together?
Data Protection Management
Information Security & Standards

Legal Notice (Impressum) under the TMG: What Website Operators Need to Know
The German Telemedia Act (TMG) specifies the information companies must provide when conducting business publicly. This includes a legal notice (Impressum). Find out here who is required to provide a legal notice and how you can reliably fulfill these obligations.
Data Protection Management
Data Protection in Practice

Contact forms on websites: Data privacy & GDPR
Data protection often ends where online contact forms begin. The principle of data minimization, in particular, is frequently nowhere to be found. For website operators, this can quickly become expensive, as it carries the risk of significant fines.
GDPR & Legal
Data Protection Management
Data Protection in Practice

Monitoring of Data Processors
Many companies rely on one or even several data processors in their day-to-day operations. These processors should be audited regularly to ensure that an adequate level of data protection is maintained. We outline the key points that must be considered when auditing your data processors.
GDPR & Legal
Data Protection Management
Data Protection in Practice

Mobile Device Management (MDM) & Data Privacy with Lendis
Mobile Device Management (MDM) solutions help companies easily implement various GDPR requirements. Our partner Lendis explains what you need to know.
Data Protection in Practice
Data Protection Management
Information Security & Standards

Remote Support & Data Privacy
IT maintenance is often carried out via remote access. Companies, in particular, must strictly adhere to data protection regulations in the process. What does the GDPR stipulate regarding remote maintenance?
Data Protection Management
Data Protection in Practice
Information Security & Standards

E-Prescriptions & Data Privacy: Is the electronic prescription GDPR-compliant?
As of January 1, 2022, electronic prescriptions are mandatory in all medical practices. However, e-prescriptions have also raised concerns regarding the sensitive data stored within them. Read on to learn how e-prescriptions align with data protection standards.
GDPR & Legal
Data Protection in Practice
Data Protection Management
Information Security & Standards

Tricky topic: staff scheduling and data privacy? This trick keeps posting your shift plans compliant
Data protection and staff scheduling can be a tricky combination: as a general rule, duty rosters containing full names may no longer be posted in the workplace. However, there are simple ways to ensure that schedules remain accessible to all employees.
GDPR & Legal
Data Protection Management
Data Protection in Practice
Cookieless Tracking: GDPR-Compliant Tracking Alternatives
Third-party cookies, which are set when visiting almost any website, are set to be phased out. This poses a problem for many advertisers, as cookie-based tracking is a massive market. So, what is the alternative? And is it more compliant with data protection regulations?
GDPR & Legal
Data Protection Management
Data Protection in Practice
Digital Services & Tools

Freelancers and Data Protection
Determining the data protection status of freelancers can often be tricky. We will show you how to clarify exactly what data protection requirements apply to "your" freelancers.
GDPR & Legal
Data Protection Management
Data Protection in Practice

Digital voting tools: Compliant and on schedule
When many team members work remotely, scheduling via a polling tool is often the easiest approach. Here is what you should definitely keep in mind when using these tools within your company.
GDPR & Legal
Data Protection in Practice
Data Protection Management
Topics
