Enterprise GRC systems have long been considered the standard for governance, risk, and compliance in large organizations. In practice, however, a conflict is increasingly coming to light: particularly in the
How to turn a record of processing activities into a tool that provides your company with transparency, reduces risks and reveals optimization potential.
According to the ECJ, an initial request for information can also be „excessive“ within the meaning of Art. 12 (5) GDPR if the controller proves that the request is not
Data breaches are now one of the most common compliance incidents in organizations. Incidents have to be assessed, reporting obligations checked, measures documented and communication decisions made within a short space of time. We provide
Google will reclassify its role in the use of reCAPTCHA under data protection law and will no longer act as a controller but as a processor from April 2026. What this means
In Germany, the internal data protection officer enjoys far-reaching special protection against dismissal. Anyone who appoints an employee as data protection officer is therefore making a decision with long-term consequences. What this means for
A recent ruling by the Federal Court of Justice (BGH) provides clarity regarding non-material damages pursuant to Art. 82 GDPR in the event of a data leak at a former processor.
Is proctoring in the application process compliant with data protection regulations? Find out which GDPR requirements apply and how companies can use proctoring in a legally compliant manner.
In its judgment C‑654/23, the European Court of Justice (ECJ) provides clear guidelines on the interpretation of the term „direct marketing“ within the meaning of the ePrivacy Directive and on the relationship between the
A few companies are currently receiving letters from data protection supervisory authorities regarding the use of AI tools. The supervisory authorities apparently want to obtain an up-to-date overview of the use of artificial intelligence in companies.