Advisory for the Mittelstand and critical infrastructure NIS2 is in force: registration and reporting duties apply DE
Data protection & GDPR

Data protection that builds trust

The GDPR is no paper tiger – it's the basis for customers trusting you with their data and for partners working with you. With a legal foundation I get your data-protection processes in order: clear, audit-proof and without unnecessary bureaucracy.

Why data protection

More than a duty – a proof of trust

Many companies treat data protection as a nuisance. Yet it's increasingly a business factor: large customers demand solid data-protection evidence before any contract, and a breach costs not only fines but, above all, trust. Those who have data protection set up cleanly sell more easily and sleep more soundly.

My approach is the same as with NIS2: no mountain of paper that helps no one, but lean, lived processes that cover exactly what the GDPR requires – no more and no less.

Services

What I take on for your data protection

Record of processing activities

A record that's accurate and stays current – the basis for everything else and the first thing a supervisory authority asks for.

  • Complete inventory of your processing operations
  • Lawful basis and purposes documented per process
  • Kept current as workflows change

Technical & organisational measures

TOMs with system instead of boilerplate – matched to your actual risks and meshed with your information security.

  • Risk-based measures, not copy-paste templates
  • Aligned with your ISO 27001 / NIS2 controls
  • Demonstrable and ready for audits

Contracts & data processing

Data processing agreements, privacy notices and consents that hold up legally – with the lawyer's eye for wording and liability.

  • Data processing agreements with your providers
  • Privacy notices and consent texts that stand up
  • Liability and wording reviewed by a lawyer

Authority communication & breaches

In a crisis – such as a data breach – I handle the notification and communication with the supervisory authority confidently and on time.

  • Breach assessment within the 72-hour window
  • Notifications drafted and filed correctly
  • Confident dialogue with the supervisory authority
Interplay

Data protection and information security belong together

Data protection (GDPR) and information security (NIS2, ISO 27001) overlap heavily: both revolve around protecting data and systems. Treating them separately means doing a lot twice and missing gaps. I bring them under one roof – a management system that covers data protection and security together. That saves effort and makes your evidence consistent.

More on NIS2 & information security

FAQ

Answered briefly

Do we need an external data protection officer?

That depends on your size and your processing. I check whether you're obliged to appoint one and either support that role or guide your internal officer.

We already have data-protection templates – is that enough?

Templates are a start, but they rarely fit your reality. What matters is that the record, measures and contracts match your actual workflows – otherwise they fail at the first audit or customer enquiry.

How does this relate to NIS2?

Very closely. The technical measures from NIS2 and the GDPR's TOMs overlap heavily. Setting both up together meets two duties with one system.

Data protection that opens doors

Let's clarify, with no obligation, where your data protection stands and which steps deliver the most value.

Book an intro call