Magazine
Data protection know-how
that works in everyday practice
Articles, videos, webinars, and checklists on GDPR, AI compliance, and NIS-2 – drawn from daily consulting practice, and implementable with reasonable effort.

Thematic areas
News
About the AI hype out
Real everyday situations instead of paragraphs – for management, data protection, IT, compliance and executives.
November 5, 2026 · 11 a.m. · online · free of charge
Next date: December 10, 2026
With Asmus Eggert and Jennifer Schülzky, mip Consult
Data Protection

In an emergency
A data breach doesn't announce itself
A lost laptop, an incorrectly addressed email with customer data, a successful phishing attack on a mailbox: As soon as your company becomes aware of a personal data breach, the time limit under Article 33 of the GDPR begins to run – 72 hours for notification to the supervisory authority, provided there is a risk to the affected individuals. What has been decided beforehand is decisive: Who reports internally to whom, who assesses the risk, who talks to the authority. If this is only clarified in an emergency, exactly those hours are lost that matter.
Information security
From the consulting practice
Data protection usually fails in day-to-day work
The requirements of the General Data Protection Regulation have been fixed since 2018. What is constantly changing is everything around it: new tools, new service providers, new responsibilities, colleagues who leave and come back. It is precisely here that the gaps arise. Not in the list of processing activities, but between the department that wants to try out a tool and the IT department that learns about it when it is already in use. Therefore, in our articles, we cover not only the procedures but also processes that still apply even when no one is thinking about data protection.

AI Consulting
AI Consulting
AI is usually in use long before anyone officially introduces it.
In most companies, AI deployment doesn’t start with a decision by the management; it starts with individual employees: a chatbot for the initial draft, a transcription service for the meeting, a translation tool for the contract. The crucial question is therefore not which model is the best, but which data leaves the company and on what legal basis it is done. We will sort out with you which applications are not critical, which need regulation, and which you should leave to others.

Frequently asked questions
Am I still allowed to ask for a salutation in the contact form?
Yes. The European Court of Justice did not ban the query, but the Obligatory If the greeting is not necessary for your purpose, please fill in the field voluntarily – or leave it blank. Those who want to address you personally can offer it as an optional feature, ideally with an open input field instead of a choice between two options.
What exactly did the European Court of Justice decide on January 9, 2025?
In case C-394/23, a French railway company forced customers to choose between „Mr.“ and „Mrs.“ when purchasing tickets online. The court clarified that for a transport contract, the address is not generally required. Such an obligatory requirement violates the principle of data minimization.
What does data minimization according to Article 5(1)(c) of the GDPR mean in practice?
They are only allowed to collect the data that is necessary for the specific purpose – not the data that is useful, practical, or historically relevant. The standard is the purpose, not the technical possibility. Data minimization does not begin with deletion, but already in the form itself.
Which mandatory fields should we check now?
Typical candidates include first names, titles, phone numbers, birth dates, postal addresses, and industry and company size. Check not only the contact form, but also registration and customer accounts, application forms, newsletter sign-ups, support portals, CRM, and internal capture forms. The rule of thumb is that the purpose of each required field must be clearly stated in a single sentence.
What happens if we keep the salutation as a mandatory field?
An unnecessary survey is processing without a valid basis. This can lead to regulatory measures and fines, and open the door for claims from those affected. What is most relevant in practice is the effort involved: the more unnecessary fields you create, the greater the obligations for providing information, deleting data, and documenting the data.
How do we implement this without degrading the customer experience?
In three steps: First, inventory all forms and document the purpose for each field. Second, for anything that does not meet the purpose test, either set it aside voluntarily or delete it. Third, incorporate the requirement into the standard process for new applications so that the same waste does not arise again. For outreach, the full name is usually sufficient.



















