Information Security & Standards
Filter posts
Reset filter
Data protection violation
Data Protection in Practice
AI & Innovation
Social Media
Digital Services & Tools
Cyber Threats & Incidents
Information Security & Standards
GDPR & Legal
Data Protection Management
Data Protection Officer
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

ISMS for SMEs: Best Practices for Systematic Information Security
An Information Security Management System (ISMS) allows you to systematically protect your organization's internal and external information from unauthorized access. This overview summarizes the key facts about ISMS and best practices for its implementation.
Information Security & Standards
Data Protection in Practice

The best path to a robust ISMS: implementation steps
A robust Information Security Management System (ISMS) forms the backbone of an effective corporate security strategy. Learn how to implement such a system in your company to keep hackers at bay.
Information Security & Standards
Data Protection Management
Data Protection in Practice

Data Protection Risk Analysis: Structure, Process, and Practical Examples
The GDPR is based on a simple principle: the higher the risk to the individuals involved, the more extensive the protective measures must be. Risk analysis is therefore the foundation for almost all data protection decisions within a company—from selecting technical measures and reporting data breaches to determining whether a data protection impact assessment is required. This article explains how it works in practice.
Information Security & Standards
Data Protection Management
Data Protection in Practice

Data Protection vs. Data Security: Simply Explained
Data security and data protection are not synonyms, but two important tasks for companies. Learn how to clearly distinguish between both areas and implement them efficiently.
Information Security & Standards
Cyber Threats & Incidents
Data Protection in Practice

What is a data security officer?
Data security is of paramount importance in the digital age. This is especially true for companies that manage and process large volumes of data—such as that of customers, suppliers, business partners, and employees. Data security officer, IT security officer, data protection officer—at first glance, these terms seem almost identical and interchangeable. However, a closer look reveals distinct differences.
Data Protection Officer
Information Security & Standards

Technical and Organizational Measures (TOMs): A Guide to GDPR Compliance
The General Data Protection Regulation (GDPR) requires companies to implement technical and organizational measures (TOMs) to ensure the secure processing of personal data. TOMs are the foundation of any GDPR-compliant data processing. In this guide, you will learn which measures are mandatory, how the 14 control areas work, and how to document your TOMs in a legally compliant manner—including practical tips for remote work and data processing agreements.
Data Protection in Practice
Information Security & Standards
Data Protection Management

WeTransfer and Data Protection: Is Your Data Transfer GDPR Compliant?
WeTransfer is a popular online service for sending large file attachments – but what about data protection? Discussions surrounding access rights in the terms and conditions and data storage on US servers raise important questions for compliance officers. This article provides a GDPR compliance check and demonstrates how SwissTransfer performs as a data protection-compliant alternative.
Data Protection in Practice
GDPR & Legal
Information Security & Standards
Digital Services & Tools
Secure Search Engines Without Tracking: 7 Privacy-Friendly Alternatives to Google
Google continues to dominate the global search engine market with a share of around 92% – but awareness of data protection and compliance requirements has fundamentally changed. For compliance officers in medium-sized companies, the question increasingly arises: How can we ensure secure, GDPR-compliant search processes? This article introduces 7 data protection-compliant search engine alternatives.
Data Protection in Practice
GDPR & Legal
Information Security & Standards

reCAPTCHA & Data Privacy: Is it GDPR compliant?
After years of criticism from data protection authorities, Google is taking action: starting April 2, 2026, Google will process reCAPTCHA data under a data processing agreement (DPA). This article explains what this means for your company and the steps you need to take now.
GDPR & Legal
Information Security & Standards
Data Protection Management
Data Protection in Practice

Digital Sovereignty: The Foundation for NIS2 and GDPR Compliance for SMEs
NIS2 requires supply chain security, GDPR demands transparent data processing, and DORA targets ICT security in the financial sector. Those who don't fully control their IT systems and data will struggle to meet these regulations. Digital sovereignty is therefore no longer a nice-to-have, but a prerequisite for demonstrable compliance.
Information Security & Standards
Data Protection in Practice

Cyberattacks on Germany: Are we already in a cyberwar, and what does that mean for SMEs?
Hybrid attacks, political tensions, and sabotage demonstrate: Germany is in the midst of a permanent cyber conflict – and SMEs are part of the attack surface. Companies that are not resilient could inadvertently become entangled in geopolitical conflicts.
Cyber Threats & Incidents
Information Security & Standards

ChatGPT & Data Privacy: What are the implications of using the chatbot?
ChatGPT is sparking global curiosity about Artificial Intelligence. Around 500 million people interact with the chatbot weekly. But with the hype, concerns from data protection experts are also growing. How secure is ChatGPT regarding data protection, and do companies have to forgo the AI tool?
AI & Innovation
Information Security & Standards
Data Protection in Practice
GDPR & Legal

Identity Theft: Examples and Consequences of Data Theft
Have you ever been a victim of identity theft? In the digital age, it happens faster than ever before. With inadequately protected data, it is easy for hackers to collect information and use it for malicious purposes.
Cyber Threats & Incidents
Information Security & Standards
Data Protection in Practice
GDPR & Legal

Data retention
When personal telecommunications data is stored by public authorities—or on their behalf—without a specific cause, this is referred to as data retention. As a precursor to telecommunications surveillance, data retention is one of the most controversial areas of data protection law. Corresponding legal provisions have been struck down multiple times by both the Federal Constitutional Court and the European Court of Justice.
GDPR & Legal
Information Security & Standards
Cyber Threats & Incidents

Data Protection and the Trade Secret Act (GeschGehG)
For companies, knowledge is capital. These trade secrets have significant economic value and must not fall into the hands of unauthorized third parties. It is not just large corporations but also startups that possess sensitive trade secrets worthy of protection, which are subject to confidentiality requirements and can secure a competitive advantage. With the entry into force of the Trade Secret Act (GeschGehG), every company must demonstrate that it protects its know-how through measures that are both externally recognizable and appropriate.
Information Security & Standards
Data Protection in Practice
Cyber Threats & Incidents

Password Privacy: How Secure Are the Alternatives?
In an increasingly digitized world, passwords serve as the first line of defense for our personal data. But how secure are these traditional passwords really? Given the constant evolution of technology and the growing threat of cybercrime, it is essential to evaluate and understand various authentication methods.
Cyber Threats & Incidents
Data Protection Management
Data Protection in Practice
Information Security & Standards

Data protection as the foundation for IT security?
IT companies are facing major challenges: cyber threats are growing, yet they cannot afford to fall behind in the digitalization race. Here is how data protection helps balance IT security with progress.
Information Security & Standards
Data Protection Management
Data Protection in Practice

IT Security: The Scale of the Cyber Threat
The BSI status report provides regular updates on the state of IT security in Germany. The latest report presents alarming findings. We have summarized the 5 most important takeaways and show you how to protect your company.
Data Protection in Practice
Information Security & Standards

Privacy by Design & Privacy by Default
The GDPR mandates data protection through technology design via privacy by design. Furthermore, privacy by default is intended to ensure data-friendly settings from the outset. In practice, this does not always work as intended.
GDPR & Legal
Information Security & Standards
Data Protection Management

Data Privacy and Security in Google Drive – What You Need to Know
How secure is the data you store in Google Drive? And can that security be improved? We have put together information and tips on Google Drive and data privacy to ensure your data stays truly secure.
Digital Services & Tools
Information Security & Standards
GDPR & Legal
Data Protection in Practice

Password Managers & Data Privacy – What Does the GDPR Require?
The GDPR sets high standards for passwords. Password managers make it easy to keep track of numerous, complex passwords. Which password managers are recommended for businesses?
Cyber Threats & Incidents
Information Security & Standards
Data Protection in Practice

EU Digital Wallet: What you need to know now
The European Union is currently working on a digital identity wallet. This will allow EU citizens to identify themselves more easily online and store important documents, such as ID cards or driver's licenses, in a digital format. The digital wallet will also be relevant for businesses. However, data protection advocates see more than just benefits in this development.
Information Security & Standards
GDPR & Legal
Data Protection in Practice

Protecting Against Insider Data Theft: Strategies for Businesses
In today's digital era, external cyberattacks on companies are no longer unusual and are a well-known risk. Yet, despite all the justified fear of external threats, an increasingly underestimated risk is coming into focus: data theft from within the organization.
GDPR & Legal
Information Security & Standards
Data Protection in Practice
Cyber Threats & Incidents

Digitization vs. Data Privacy: The Electronic Health Card
The ongoing digitalization of the healthcare sector, particularly regarding the handling of patient data on the electronic health card (eGK), raises important questions about data privacy in medicine.
GDPR & Legal
Data Protection Management
Data Protection in Practice
Information Security & Standards

WhatsApp alternatives for business communication
Using WhatsApp for business? From a data protection perspective, it’s not a great idea, as app providers are also subject to the GDPR. We highlight the risks and introduce popular messenger alternatives like Threema and Signal.
Social Media
Information Security & Standards
Data Protection in Practice

HubSpot & GDPR: Is this CRM compliant?
The CRM tool HubSpot is a valuable asset for companies in customer acquisition and sales. However, storing large amounts of personal data also raises data protection concerns. Read on to learn about the applicable regulations.
GDPR & Legal
Digital Services & Tools
Data Protection in Practice
Information Security & Standards

Presearch: Is the decentralized search engine privacy-compliant?
Aufmerksame Besitzer eines neuen Android-Gerätes haben es vielleicht schon entdeckt: die Suchmaschine Presearch als Alternative zu Google. Auch wenn die Bekanntheit und ihr Marktanteil noch sehr gering sind, ist das Auftauchen von Presearch auf dem Smartphone Grund genug, dass wir uns diese Suchmaschine hinsichtlich Datenschutz genauer anschauen.
GDPR & Legal
Data Protection in Practice
Information Security & Standards

Fingerprint Devices & Data Privacy – How secure are fingerprint scanners?
Fingerprint devices are used in both private and professional settings, for example, to secure hardware. But what about data protection when it comes to these fingerprint scanners? And what other security concerns should be considered?
Information Security & Standards
Data Protection in Practice
GDPR & Legal

Fax & Data Protection: What are the data protection implications when transmitting information via fax?
They really do still exist—clattering fax machines that are by no means confined to dusty offices. But what about the issue of data protection and faxing? Do they actually go together?
Data Protection Management
Information Security & Standards

Electronic Patient Records & Data Privacy: How secure is the ePA?
The electronic patient record, or ePA for short, is a divisive topic: will it give the German healthcare system a much-needed digital boost, or does it primarily pose a data privacy risk? We provide an overview of the digital patient record and data protection.
GDPR & Legal
Data Protection in Practice
Information Security & Standards

Mobile Device Management (MDM) & Data Privacy with Lendis
Mobile Device Management (MDM) solutions help companies easily implement various GDPR requirements. Our partner Lendis explains what you need to know.
Data Protection in Practice
Data Protection Management
Information Security & Standards

Remote Support & Data Privacy
IT maintenance is often carried out via remote access. Companies, in particular, must strictly adhere to data protection regulations in the process. What does the GDPR stipulate regarding remote maintenance?
Data Protection Management
Data Protection in Practice
Information Security & Standards

VPN: The pros and cons of using a VPN for data privacy
Virtual Private Networks (VPNs) enhance security and privacy online, both at work and in your personal life. But what exactly does that mean, and which aspects of data protection are involved? We’ll break it down for you.
Information Security & Standards
Data Protection in Practice

Telegram and data privacy: The risks users face
Telegram has long been considered a secure alternative to WhatsApp and similar apps because it does not require a phone number. However, this enthusiasm waned as more radical groups began using the platform for bot services and planning criminal activities. Criticism regarding data privacy has also grown louder; learn more about Telegram's data privacy practices here.
Information Security & Standards
GDPR & Legal
Data Protection in Practice

E-Prescriptions & Data Privacy: Is the electronic prescription GDPR-compliant?
As of January 1, 2022, electronic prescriptions are mandatory in all medical practices. However, e-prescriptions have also raised concerns regarding the sensitive data stored within them. Read on to learn how e-prescriptions align with data protection standards.
GDPR & Legal
Data Protection in Practice
Data Protection Management
Information Security & Standards

Doctolib, Jameda, and similar platforms: What is the status of data protection in appointment booking portals?
Medical appointment booking portals promise users a simple and straightforward way to schedule and manage doctor visits. Recently, the booking platform Doctolib has come under scrutiny by the Berlin Commissioner for Data Protection. This raises the question: is sensitive data being adequately protected, and what should we as consumers keep in mind when booking appointments online?
Data Protection in Practice
Information Security & Standards
GDPR & Legal

LinkedIn & Data Privacy: How secure is user data?
Online networks like LinkedIn make it easier to build and maintain professional connections. However, the information users are required to provide is usually personal data and should be protected accordingly.
Social Media
Data Protection in Practice
Information Security & Standards
GDPR & Legal

Data protection in online shops: Beware of fake online stores!
It’s not just during the pre-Christmas rush that online shopping surges. However, shopping online can become problematic if consumers end up on shady websites. Here is what you should look out for when shopping online and how to spot dangerous fake shops.
GDPR & Legal
Data Protection in Practice
Information Security & Standards

Zoombombing: Harmless or dangerous?
Due to the COVID-19 pandemic, the video conferencing tool Zoom gained more than 150 million new users almost overnight. Internet trolls looking to exploit the situation were quick to act, leading to the rise of what is known as "Zoombombing."
Information Security & Standards
Cyber Threats & Incidents
Data Protection in Practice
GDPR & Legal

YouTube & Data Privacy: Is the Video Platform GDPR Compliant?
Videos are one of the most important means of communication today, and YouTube is one of the largest video platforms in existence. But how does YouTube handle data privacy and GDPR compliance?
GDPR & Legal
Information Security & Standards
Data Protection in Practice

Signal & Privacy
Is Signal a secure messenger? As an alternative to the market leader WhatsApp, Signal is becoming increasingly popular. But how does Signal stack up when it comes to data privacy, GDPR, and related issues?
Data Protection in Practice
GDPR & Legal
Information Security & Standards
Social Media

Give us your data and you'll look old. FaceApp at its best.
What will I look like when I’m old? Should I get preventative fillers for any potential wrinkles? To answer these questions, FaceApp helps with digital aging. However, what the app does with the data provided and the state of FaceApp’s data privacy is alarming.
AI & Innovation
Information Security & Standards
Data Protection in Practice
GDPR & Legal

Screensharing and Data Privacy: Top Tips
To ensure that data protection remains a priority during digital work—even in times of COVID-19 and widespread remote work—we have compiled the best data privacy tips for screensharing.
GDPR & Legal
Data Protection in Practice
Information Security & Standards
Topics















