Joint controller agreement: Benefits and challenges of joint controllership

The Joint Controller Agreement (JCA) still seems complicated and cumbersome to many managers in practice. But wrongly so: with the careful design of the agreement, responsible companies can benefit from many advantages, achieve efficiency gains through forward-looking process design and operate a corresponding effective risk management.

Read more

The NIS 2 Directive: Key objectives and regulations

Last December, the European Council and the European Parliament adopted the Network and Information Security Directive (NIS 2 Directive), thus initiating a reform of the legal requirements for IT security in the European area. After coming into force on 2023-01-16, Germany and the other EU member states now have 21 months to transpose the regulations into national law and adapt existing regulations to the new laws.

Read more
Anonymisation and pseudonymisation

Anonymisation and pseudonymisation in practice

In this article, we look at how the supposed contradiction between data protection through pseudonymisation and the use of personal data in scientific practice can be dealt with. In addition, we take a look at the special challenges that actors in the health care sector face in this topic.

Read more

Cybersecurity and data protection: Challenges for companies

What should be done when a cyber attack occurs? What can cybersecurity look like in the company? Read more now!

Read more

Rights of the data subject under the GDPR: An overview

The General Data Protection Regulation (GDPR) has resulted in significant changes in the area of data subjects’ rights. What do companies have to consider?

Read more

New EDPB guidelines on the right of access: How companies can provide information in a legally compliant manner

In this article, we present these guidelines and provide companies with valuable practical advice on how to proceed with a request for information.

Read more

Designing and structuring an efficient DPMS

Implementing data security and data protection appropriately within your company is a complex task. Given the large number of data processing operations that are carried out every day at different points and the equally large number of legal rules that have to be observed, it is easy to lose track of exactly what is going […]

Read more

Transmission of health data: pitfalls in health apps & fitness trackers

Digitisation is permeating all areas of life. Also, especially within the health care sector, the eagerness to spur the digital transformation is immense – equally from state and private sides. Thus, the market is already well-filled with a variety of fitness trackers and health apps today. Even health insurances promote the use of their own […]

Read more

Handling enquiries from data subjects – what is really relevant?

The proper handling of enquiries from data subjects benefits any business. A well-versed approach can not only ensure compliance, but also optimise and accelerate the entire business process. For this reason, responding to data subject requests should be a firm component of a good data protection management system in the organisation. But how does one […]

Read more

The biggest GDPR myths: the consent – what is right and what is wrong?

GDPR myth busters – Part 1 The GDPR is effective since 25 May 2018. Before and after, there was a lot going on. Hardly any other topic has been talked about and published so much. Unfortunately, the numerous publications with the allegedly “best” references and recommendations have not resulted in an understanding amongst the “data […]

Read more