Data protection records are only audit-ready if the processing, risk, approval, version, and measures remain traceably linked. Why email, Teams, and drives are often insufficient for this purpose.
Many companies maintain their record of processing activities (RPA) in Excel. This works fine on a day-to-day basis—until the RPA is audited. We explain why Article 30 of the GDPR
Modern transcription systems not only convert speech into text, but also attempt to identify individual speakers. As a result, they are not only directly subject to the requirements of the
A record of processing activities (VVT/RoPA) can become a tangible economic factor - if it is used correctly. How a legal regulatory obligation can be turned into a measurable return on investment.
The European Court of Justice has dismissed the action against the adequacy decision between the EU and the US, thus confirming the validity of the EU-US Data Privacy Framework
The Cologne Administrative Court has allowed the Federal Press Office to continue operating the Facebook fan page for the German government. The subject of the proceedings was in particular the question of whether the operation of a
When should a threshold value analysis be carried out, how does it work and how can it be reliably assessed whether there is an "expected high risk"? This article provides practical answers
Will Schufa's long retention periods soon be history? The Cologne Higher Regional Court considers it a violation of the GDPR if a credit agency makes negative entries after liabilities have been settled.
As controllers within the meaning of Art. 4 No. 7 GDPR, associations are obliged to fulfill all data protection requirements and to demonstrate compliance with them. The implementation represents
The French data protection authority CNIL has developed a practical guide for carrying out Transfer Impact Assessments (TIA). This procedure enables companies to assess the level of data protection in the recipient country.