What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.

Section 6 Para. 12 Sentence 3 GefStoffV: when an office or a fulfilment warehouse needs no hazardous substances register, and why that answer has to come from the risk assessment
The hazardous substances register under Section 6 Para. 12 GefStoffV has an exemption that most templates leave out: the duty lapses where only low-hazard activities are carried out on the premises. For a software company with cleaning agents in the kitchenette that is the real question, and for an online retailer with a warehouse as well. This article reads Sentence 3, the four criteria of Paragraph 13 and the documentation duty of Paragraph 8 in their wording and shows why the exemption holds only with a documented assessment.

Monitoring legal changes: from which day a change applies, why publication is not the key date, and who owns it inside the company
Legal monitoring is usually sold as a news feed. The source itself is free: the Federal Law Gazette is issued on recht.bund.de, and Section 5 VkBkmG requires a free notification service. What is missing is the translation of a publication into a key date and an owner. This article reads Article 82(2) of the Basic Law and Articles 288 and 297 TFEU in their wording and shows the three places where publication is not the day on which the duty begins.

Legal register: where the law requires a register of obligations, where it only requires supervision, and why a status column on its own proves nothing
A legal register is sold as a legal duty. A register of applicable legal obligations is expressly required only in Annex I point 3 of the EMAS Regulation, and there together with a statement of how compliance is evidenced. For every other company the need follows from Section 130 OWiG, which does not sanction the missing register but the omitted supervision. This article separates the two bases and shows which column most registers lack.

Sections 10 to 12 ChemBiozidDV: which biocidal products may not sit on an open shelf, who may hand them over, and what has to happen online before the contract is concluded
Sections 10 to 13 of the German Biocidal Products Implementing Ordinance have applied since 1 January 2025. They settle three things: which biocidal products a purchaser may not reach freely, who may hand them over at all, and what has to be completed in online and mail-order sales before the contract of sale is concluded. This article reads the three provisions in their operative wording, separates the two tiers of the self-service ban, and shows why the level of the fine is not in the ordinance but in Section 26 Para. 3 ChemG.

The accessibility check: thirty pages, four WCAG tags, no statement of conformity. And what § 14 BFSG requires regardless
The accessibility check in CIVAC discovers up to thirty pages of a website, renders them in a browser and tests them with axe-core against WCAG 2.1 at levels A and AA; a language model only phrases the remediation advice afterwards. This article describes the mechanism from the code and sets it beside § 14 of the German Accessibility Strengthening Act (BFSG): the information under Annex 3, the duty to meet the requirements “at all times”, and the notification of the market surveillance authority in case of non-conformity.

Art. 32(1)(d) GDPR: a process for regularly testing. Why one check is not a process, and what a mock audit covers
Art. 32(1)(d) GDPR requires “a process for regularly testing, assessing and evaluating the effectiveness” of technical and organisational measures. This article takes the three words process, regularly and effectiveness apart, sets Art. 24(1) sentence 2 and Art. 32(3) beside them, and describes what the mock audit in CIVAC contributes: criteria and evidence in, gaps with a corrective action out.

Art. 25 GDPR: data protection by design is a duty of the controller, and it applies at two moments
Art. 25(1) GDPR binds the controller “both at the time of the determination of the means for processing and at the time of the processing itself”. This article takes that two-moment structure literally, explains why a certification under paragraph 3 is only an element, and shows from Art. 39(1)(a) and (b) where the person sits who actually does this work.

§ 30(2) no. 5 BSIG: security in acquisition, development and maintenance. A scan is evidence of the measure, not fulfilment of the duty
§ 30(2) no. 5 and no. 6 of the German BSI Act describe exactly what an automated code and policy scanner does. This article quotes both numbers and shows, from § 30(1) sentence 3 and § 38(1) BSIG, why the scan report is evidence but the documented obligation and the supervising management are what the statute actually requires.

Art. 28(1) GDPR: “sufficient guarantees”. What the controller must check before deploying a SaaS application, and what point (h) allows afterwards
Art. 28(1) GDPR is not a contract clause but a selection duty: the controller “shall use only processors providing sufficient guarantees” to implement appropriate measures. This article separates that pre-contract check from the audit right under paragraph 3(h) afterwards, and shows from two audit templates in the CIVAC workspace what is actually asked.

§ 203(3) and (4) StGB: a medical practice's IT provider is itself criminally liable if it discloses a secret, and the practice is liable if it never bound the provider to secrecy
Since the recast of § 203 of the German Criminal Code, professionals bound by secrecy may disclose secrets to „sonstigen mitwirkenden Personen“ – other participating persons – „soweit dies für die Inanspruchnahme der Tätigkeit … erforderlich ist“, in so far as necessary to use their services. In return, subsection 4 sentence 1 makes the participating person itself an offender, and subsection 4 sentence 2 no. 1 punishes the professional who did not ensure that it „zur Geheimhaltung verpflichtet wurde“ – was bound to secrecy. What that means for software and cloud providers in healthcare, for law firms and for tax advisers, verbatim.

§ 83 MPDG: whoever informs professional circles about medical devices is a medical device adviser – with proven expertise, regular training paid for by the principal and a recording duty that reaches the PRRC
§ 83(1) of the German Medical Devices Implementation Act (MPDG) allows only a person with „die für die jeweiligen Medizinprodukte erforderliche Sachkenntnis und Erfahrung“ – the expertise and experience required for the specific devices – to inform professional circles as an occupation, „auch für die fernmündliche Information“, including by telephone. Subsection 3 obliges the principal to provide regular training, subsection 4 obliges the adviser to record reports of risks and forward them without delay to the manufacturer or its responsible person. § 94 MPDG backs the activity without expertise, the missing proof and the omitted recording or forwarding with a fine of up to thirty thousand euros.

Article 87 MDR: three deadlines for serious incidents, 15 days, 10 days, 2 days, and the rule to report anyway when in doubt
Article 87 of Regulation (EU) 2017/745 obliges every manufacturer, regardless of size, to report serious incidents: no later than 15 days after becoming aware, no later than ten days in the event of death or an unanticipated serious deterioration in health, no later than two days in the event of a serious public health threat. Paragraph 7 removes uncertainty as an excuse. The wording, with the Article 2 definitions.

Articles 3 and 7 Data Act: connected products placed on the market after 12 September 2026 must make data accessible by default – not below 50 employees, yes from 50
Article 3(1) of Regulation (EU) 2023/2854 requires connected products to be designed and manufactured so that product data are accessible to the user „standardmäßig … einfach, sicher, unentgeltlich“ – by default, easily, securely, free of charge. Under Article 50 this applies to products placed on the market after 12 September 2026. Article 7(1) exempts micro and small enterprises and gives medium-sized ones a year. What that means for manufacturers with 20, 60 and 300 employees.

Articles 25 and 29 Data Act: the clauses every SaaS contract has needed since 12 September 2025, and why switching charges fall to zero on 12 January 2027
Regulation (EU) 2023/2854 has applied since 12 September 2025 and has no size threshold for providers of data processing services. Article 25 prescribes the minimum content of the contract, including a notice period of at most two months, a transitional period of at most 30 days and a retrieval period of at least 30 days. Article 29 bans switching charges from 12 January 2027. The wording, and what Article 31 exempts.

§ 17 BFSG: whoever relies on disproportionate burden documents it, keeps it for five years, reassesses on every change and notifies without delay
The exemption in § 17 of the German Accessibility Act (BFSG) is not a free pass. Subsection 2 requires a documented assessment kept for five years, subsection 3 a repeat at least every five years and on every change to the service, subsection 5 immediate notification of the market surveillance authority. Only micro-enterprises are partly exempt, and those end at ten employees.

From 20 jobs upwards: the five per cent quota of § 154 SGB IX, the compensatory levy of § 160 and the notice due by 31 March
An employer with an annual monthly average of at least 20 jobs must fill five per cent of them with severely disabled people, pays a tiered compensatory levy for every unfilled mandatory position and reports the figures to the Federal Employment Agency by 31 March. The three provisions verbatim, with the counting rules of § 156 and the fine provisions of § 238.

Green, amber, red: what the confidence of a Compliance Agent answer means, where the sources come from and when the answer is withheld
Every answer of the Compliance Agent in CIVAC carries a confidence on three levels with a reason, a list of typed sources and an escalation field. This article describes what goes into an answer, how the three levels are defined in the instruction, when the model may not give a substantive answer, and why the escalation field is a note to the officer and not a handover to a law firm.

The Pflichten-Check: four profile fields, three levels, one statute per role, and what the indication does not decide
The Pflichten-Check in CIVAC matches the company profile against the role catalogue and returns one finding per role: mandatory, recommended or monitor, with the statute, the profile fact that triggers the duty, and a next step. This article describes which four fields go in, how a finding is structured, what the traffic light at the end means, and why the result is only as good as the profile.

The Abmahncheck: nine review areas, five severities, one statute per finding, and what the check expressly does not assess
The Abmahncheck in CIVAC reads a website or an uploaded document and returns findings that each carry one category out of nine, one severity out of five, the statute the finding points to, a short evidence quote and a recommendation. This article describes what the check reviews field by field, how a finding is structured, why the result is a risk indication and not a legal assessment, and where its limits lie.

Five core steps, one data model: how a project in CIVAC runs from scope to report, and where no model is involved
Every project in CIVAC, whether a DPIA, a supplier audit or incident handling, has the same five core steps: scope, documents, questions, risks, report. This article describes them as they stand in the data model: which fields each step carries, where a language model makes suggestions, where only people work, and why the report is marked as stale as soon as an answer changes.

Sections 6, 17, 45 ElektroG: registration before placing on the market, take-back from 400 square metres, fines up to EUR 100,000
The German Electrical and Electronic Equipment Act catches manufacturers, dealers, marketplaces and fulfilment service providers with three interlocking provisions: the registration duty in section 6, the take-back duty in section 17 and the fines catalogue in section 45. Which thresholds the wording sets and who is liable for which breach.

Section 393 SGB V: since 1 July 2025 only a C5 Type 2 attestation counts, with one 18-month exception
A German healthcare provider or health insurer processing social and health data in the cloud needs, under section 393(3) SGB V, a current C5 attestation of the data-processing entity. Subsection 4 fixes when Type 1 was enough, since when Type 2 is required and which 18 months apply to systems newly placed on the market.

Article 15(2) MDR: under 50 employees no in-house PRRC, but one "permanently and continuously"
The Medical Devices Regulation requires every manufacturer to have a person responsible for regulatory compliance. Micro and small enterprises need not employ that person, but must have one permanently and continuously at their disposal. Where the threshold sits and what the wording actually demands.

Article 5n of Regulation (EU) No 833/2014: which software and which services a company may no longer provide to a customer established in Russia
ERP, CRM, CAD, online-banking software, IT consultancy and, since 25 November 2025, AI model access and high-performance computing: Art. 5n prohibits providing them to customers established in Russia. The wording, the authorisation grounds, the German criminal provision.