Magazine

Data protection know-how
that works in everyday practice

Articles, videos, webinars, and checklists on GDPR, AI compliance, and NIS-2 – drawn from daily consulting practice, and implementable with reasonable effort.

News

  • Data Protection
    $400 million for child data: What companies can learn from the TikTok case
    The TikTok case shows how important the protection of children’s data is. What companies should consider when offering digital services.
    Jonas Buchholz
    by Jonas Buchholz • 09.09.2026
  • Delayed GDPR access response: Does your company have to pay damages?
    Requests for information under Article 15 GDPR must be answered no later than one month after the request was made. What happens if the deadline is exceeded.
    Jonas Buchholz
    by Jonas Buchholz • 12.12.2025
  • Incorrect SCHUFA entry: When is you entitled to damages under the GDPR?
    Incorrect or premature reports to SCHUFA can have significant data protection consequences for companies.
    Jonas Buchholz
    by Jonas Buchholz • 27.09.2025

What are current problems in practice?

45 minutes 7 real cases 0 Paragraph Tables
Live webinar

About the AI hype out

Real everyday situations instead of paragraphs – for management, data protection, IT, compliance and executives.

November 5, 2026 · 11 a.m. · online · free of charge
Next date: December 10, 2026
With Asmus Eggert and Jennifer Schülzky, mip Consult

This field is for validation purposes and should be left unchanged.
You will receive the access data and a reminder by email. We will only use your address for this webinar. More in the Data protection information.

Data Protection

  • Data protection when working from home
    Home office shifts data processing into the private sphere. What technical and organizational measures companies need to take for this.
    Cindy Stefanet
    by Cindy Stefanet • 27.09.2026
  • Handling access requests from rejected applicants
    Rejected applicants often ask about the reasons. When companies must provide information – and when they are not required to do so.
    Cindy Stefanet
    by Cindy Stefanet • 27.09.2026
  • What must companies consider when documents are lost in the mail?
    If a shipment containing personal data is lost, the risk to the individuals involved is significant. What companies need to consider now.
    Cindy Stefanet
    by Cindy Stefanet • 27.09.2026
Warning symbol for a reported data privacy breach

In an emergency

A data breach doesn't announce itself

A lost laptop, an incorrectly addressed email with customer data, a successful phishing attack on a mailbox: As soon as your company becomes aware of a personal data breach, the time limit under Article 33 of the GDPR begins to run – 72 hours for notification to the supervisory authority, provided there is a risk to the affected individuals. What has been decided beforehand is decisive: Who reports internally to whom, who assesses the risk, who talks to the authority. If this is only clarified in an emergency, exactly those hours are lost that matter.

Information security

  • Why standard passwords can give attackers direct access to your systems
    A single weak password can be enough. Why factory-preset access data are particularly critical.
    Jonas Buchholz
    by Jonas Buchholz • 27.09.2026
  • Why TLS 1.0 and TLS 1.1 are a security risk today
    TLS protects data transmission between the browser and the web server. Why 1.0 and 1.1 are risky.
    Jonas Buchholz
    by Jonas Buchholz • 27.09.2026
  • Why outdated software is a preventable gateway for attacks
    Outdated software is a significant and avoidable security risk. What you can do.
    Jonas Buchholz
    by Jonas Buchholz • 27.09.2026
  • Information security
    Recognizing known vulnerabilities in time – this is how companies prepare for it
    Known vulnerabilities become a risk if security information is not implemented.
    Jonas Buchholz
    by Jonas Buchholz • 02.09.2026

From the consulting practice

Data protection usually fails in day-to-day work

The requirements of the General Data Protection Regulation have been fixed since 2018. What is constantly changing is everything around it: new tools, new service providers, new responsibilities, colleagues who leave and come back. It is precisely here that the gaps arise. Not in the list of processing activities, but between the department that wants to try out a tool and the IT department that learns about it when it is already in use. Therefore, in our articles, we cover not only the procedures but also processes that still apply even when no one is thinking about data protection.

AI Consulting

  • AI compliance
    Who actually bears responsibility when the AI responds?
    Generative AI generates its own answers, rather than simply referencing sources. Who is responsible for this?
    Jennifer Schülzky
    by Jennifer Schülzky • 27.09.2026
  • AI changes images – but does it need to be labeled?
    AI image processing raises data protection issues – and the question of whether edited images need to be labeled.
    Jennifer Schülzky
    by Jennifer Schülzky • 27.09.2026
  • Artificial Intelligence and Cyber Risks
    AI fundamentally changes the threat landscape in cybersecurity – for example through automated phishing campaigns.
    Jennifer Schülzky
    by Jennifer Schülzky • 27.09.2026
  • AI deployment in the company – Who keeps track?
    More and more companies are using AI. This requires clear responsibilities and transparent processes.
    Jennifer Schülzky
    by Jennifer Schülzky • 27.09.2026

AI Consulting

AI is usually in use long before anyone officially introduces it.

In most companies, AI deployment doesn’t start with a decision by the management; it starts with individual employees: a chatbot for the initial draft, a transcription service for the meeting, a translation tool for the contract. The crucial question is therefore not which model is the best, but which data leaves the company and on what legal basis it is done. We will sort out with you which applications are not critical, which need regulation, and which you should leave to others.

Software development


All articles at a glance.

Frequently asked questions

Am I still allowed to ask for a salutation in the contact form?


What exactly did the European Court of Justice decide on January 9, 2025?


What does data minimization according to Article 5(1)(c) of the GDPR mean in practice?

Which mandatory fields should we check now?


What happens if we keep the salutation as a mandatory field?


How do we implement this without degrading the customer experience?