How to turn a record of processing activities into a tool that provides your company with transparency, reduces risks and reveals optimization potential.
According to the ECJ, an initial request for information can also be „excessive“ within the meaning of Art. 12 (5) GDPR if the controller proves that the request is not
Data breaches are now one of the most common compliance incidents in organizations. Incidents have to be assessed, reporting obligations checked, measures documented and communication decisions made within a short space of time. We provide
Google will reclassify its role in the use of reCAPTCHA under data protection law and will no longer act as a controller but as a processor from April 2026. What this means
Good audit preparation requires clear responsibilities, structured evidence and transparent processes. Find out how auditors think, what weaknesses frequently occur in data protection audits and how you can
The European Data Protection Board's coordinated enforcement action 2026 focuses on the transparency and information obligations under Articles 12, 13, and 14 of the GDPR. What this means in concrete terms for
Is proctoring in the application process compliant with data protection regulations? Find out which GDPR requirements apply and how companies can use proctoring in a legally compliant manner.
Cookie banners have long been part of everyday life, but their legal admissibility remains controversial. The question of whether so-called "pay or okay" models are compatible with the GDPR is particularly controversial.
The data protection assessment of health data in the employment relationship is one of the most sensitive aspects of compliance practice. A current occasion for in-depth discussion is the publication of the