Magazine

Data Protection

Articles, videos, webinars, and checklists on GDPR, AI compliance, and NIS-2 – drawn from daily consulting practice, and implementable with reasonable effort.

Topic
Format
1-10 of 11 posts
  • What must companies consider when documents are lost in the mail?
    If a shipment containing personal data is lost, the risk to the individuals involved is significant. What companies need to consider now.
    Cindy Stefanet
    by Cindy Stefanet • 27.09.2026
  • Data protection when working from home
    Home office shifts data processing into the private sphere. What technical and organizational measures companies need to take for this.
    Cindy Stefanet
    by Cindy Stefanet • 27.09.2026
  • Handling access requests from rejected applicants
    Rejected applicants often ask about the reasons. When companies must provide information – and when they are not required to do so.
    Cindy Stefanet
    by Cindy Stefanet • 27.09.2026
  • When is consent under the GDPR valid?
    Consent is not a standard solution. When it becomes the legal basis after GDPR it has taken effect.
    Cindy Stefanet
    by Cindy Stefanet • 27.09.2026
  • Data Protection
    External service providers in social institutions: Why the DPA does not regulate everything
    An AVV alone is not always enough in social institutions. What matters when it comes to external service providers.
    Cindy Stefanet
    by Cindy Stefanet • 09.09.2026
  • Data Protection
    $400 million for child data: What companies can learn from the TikTok case
    The TikTok case shows how important the protection of children’s data is. What companies should consider when offering digital services.
    Jonas Buchholz
    by Jonas Buchholz • 09.09.2026
  • Data processing on behalf in practice: When is a contract required?
    Cloud providers, IT service providers, external software: When is contract processing involved and when is a contract required?
    Cindy Stefanet
    by Cindy Stefanet • 01.09.2026
  • Delayed GDPR access response: Does your company have to pay damages?
    Requests for information under Article 15 GDPR must be answered no later than one month after the request was made. What happens if the deadline is exceeded.
    Jonas Buchholz
    by Jonas Buchholz • 12.12.2025
  • GDPR Right of Information: Unreasonable effort is not an excuse!
    The right to information under Art. 15 GDPR applies even in cases of high expense. Why „unreasonable“ is not an excuse.
    Jonas Buchholz
    by Jonas Buchholz • 20.06.2025
  • Data protection vs. data security
    Data protection and data security are often confused, but they pursue different goals. The difference at a glance.
    Cindy Stefanet
    by Cindy Stefanet • 25.04.2025