77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
News & Insights

What officers need to know.

Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.

Featured
Bright office kitchenette with sink and toaster, beside a white shelf holding five unlabelled spray bottles and a grey bucket
Occupational Safety23 September 20267 min read

Section 6 Para. 12 Sentence 3 GefStoffV: when an office or a fulfilment warehouse needs no hazardous substances register, and why that answer has to come from the risk assessment

The hazardous substances register under Section 6 Para. 12 GefStoffV has an exemption that most templates leave out: the duty lapses where only low-hazard activities are carried out on the premises. For a software company with cleaning agents in the kitchenette that is the real question, and for an online retailer with a warehouse as well. This article reads Sentence 3, the four criteria of Paragraph 13 and the documentation duty of Paragraph 8 in their wording and shows why the exemption holds only with a documented assessment.

Read more
Latest
Blank spiral-bound desk calendar next to a stack of white paper and a black coffee cup on a wooden desk by a window
Governance & Compliance23 September 20268 min read

Monitoring legal changes: from which day a change applies, why publication is not the key date, and who owns it inside the company

Legal monitoring is usually sold as a news feed. The source itself is free: the Federal Law Gazette is issued on recht.bund.de, and Section 5 VkBkmG requires a free notification service. What is missing is the translation of a publication into a key date and an owner. This article reads Article 82(2) of the Basic Law and Articles 288 and 297 TFEU in their wording and shows the three places where publication is not the day on which the duty begins.

Read more
Open grey ring binder with blank divider sheets on a light wooden desk, beside a fountain pen and a coffee mug
Governance & Compliance23 September 20268 min read

Legal register: where the law requires a register of obligations, where it only requires supervision, and why a status column on its own proves nothing

A legal register is sold as a legal duty. A register of applicable legal obligations is expressly required only in Annex I point 3 of the EMAS Regulation, and there together with a statement of how compliance is evidenced. For every other company the need follows from Section 130 OWiG, which does not sanction the missing register but the omitted supervision. This article separates the two bases and shows which column most registers lack.

Read more
Locked glass-fronted chemical storage cabinet holding unlabelled canisters in a bright storeroom
Produktsicherheit22 September 20269 min read

Sections 10 to 12 ChemBiozidDV: which biocidal products may not sit on an open shelf, who may hand them over, and what has to happen online before the contract is concluded

Sections 10 to 13 of the German Biocidal Products Implementing Ordinance have applied since 1 January 2025. They settle three things: which biocidal products a purchaser may not reach freely, who may hand them over at all, and what has to be completed in online and mail-order sales before the contract of sale is concluded. This article reads the three provisions in their operative wording, separates the two tiers of the self-service ban, and shows why the level of the fine is not in the ordinance but in Section 26 Para. 3 ChemG.

Read more
The accessibility check: thirty pages, four WCAG tags, no statement of conformity. And what § 14 BFSG requires regardless
Platform & Strategy21 September 202610 min read

The accessibility check: thirty pages, four WCAG tags, no statement of conformity. And what § 14 BFSG requires regardless

The accessibility check in CIVAC discovers up to thirty pages of a website, renders them in a browser and tests them with axe-core against WCAG 2.1 at levels A and AA; a language model only phrases the remediation advice afterwards. This article describes the mechanism from the code and sets it beside § 14 of the German Accessibility Strengthening Act (BFSG): the information under Annex 3, the duty to meet the requirements “at all times”, and the notification of the market surveillance authority in case of non-conformity.

Read more
Art. 32(1)(d) GDPR: a process for regularly testing. Why one check is not a process, and what a mock audit covers
Data Protection & Privacy21 September 20268 min read

Art. 32(1)(d) GDPR: a process for regularly testing. Why one check is not a process, and what a mock audit covers

Art. 32(1)(d) GDPR requires “a process for regularly testing, assessing and evaluating the effectiveness” of technical and organisational measures. This article takes the three words process, regularly and effectiveness apart, sets Art. 24(1) sentence 2 and Art. 32(3) beside them, and describes what the mock audit in CIVAC contributes: criteria and evidence in, gaps with a corrective action out.

Read more
Art. 25 GDPR: data protection by design is a duty of the controller, and it applies at two moments
Data Protection & Privacy21 September 20269 min read

Art. 25 GDPR: data protection by design is a duty of the controller, and it applies at two moments

Art. 25(1) GDPR binds the controller “both at the time of the determination of the means for processing and at the time of the processing itself”. This article takes that two-moment structure literally, explains why a certification under paragraph 3 is only an element, and shows from Art. 39(1)(a) and (b) where the person sits who actually does this work.

Read more
§ 30(2) no. 5 BSIG: security in acquisition, development and maintenance. A scan is evidence of the measure, not fulfilment of the duty
IT Security & NIS-221 September 20269 min read

§ 30(2) no. 5 BSIG: security in acquisition, development and maintenance. A scan is evidence of the measure, not fulfilment of the duty

§ 30(2) no. 5 and no. 6 of the German BSI Act describe exactly what an automated code and policy scanner does. This article quotes both numbers and shows, from § 30(1) sentence 3 and § 38(1) BSIG, why the scan report is evidence but the documented obligation and the supervising management are what the statute actually requires.

Read more
Art. 28(1) GDPR: “sufficient guarantees”. What the controller must check before deploying a SaaS application, and what point (h) allows afterwards
Data Protection & Privacy21 September 20267 min read

Art. 28(1) GDPR: “sufficient guarantees”. What the controller must check before deploying a SaaS application, and what point (h) allows afterwards

Art. 28(1) GDPR is not a contract clause but a selection duty: the controller “shall use only processors providing sufficient guarantees” to implement appropriate measures. This article separates that pre-contract check from the audit right under paragraph 3(h) afterwards, and shows from two audit templates in the CIVAC workspace what is actually asked.

Read more
Empty reception area of a medical practice with a closed filing cabinet, a switched-off monitor and a houseplant in morning light
Datenschutz & Privacy17 September 20269 min read

§ 203(3) and (4) StGB: a medical practice's IT provider is itself criminally liable if it discloses a secret, and the practice is liable if it never bound the provider to secrecy

Since the recast of § 203 of the German Criminal Code, professionals bound by secrecy may disclose secrets to „sonstigen mitwirkenden Personen“ – other participating persons – „soweit dies für die Inanspruchnahme der Tätigkeit … erforderlich ist“, in so far as necessary to use their services. In return, subsection 4 sentence 1 makes the participating person itself an offender, and subsection 4 sentence 2 no. 1 punishes the professional who did not ensure that it „zur Geheimhaltung verpflichtet wurde“ – was bound to secrecy. What that means for software and cloud providers in healthcare, for law firms and for tax advisers, verbatim.

Read more
Open equipment case with a handheld medical device in foam inlay on a wooden table in a bright clinic room
Healthcare17 September 20268 min read

§ 83 MPDG: whoever informs professional circles about medical devices is a medical device adviser – with proven expertise, regular training paid for by the principal and a recording duty that reaches the PRRC

§ 83(1) of the German Medical Devices Implementation Act (MPDG) allows only a person with „die für die jeweiligen Medizinprodukte erforderliche Sachkenntnis und Erfahrung“ – the expertise and experience required for the specific devices – to inform professional circles as an occupation, „auch für die fernmündliche Information“, including by telephone. Subsection 3 obliges the principal to provide regular training, subsection 4 obliges the adviser to record reports of risks and forward them without delay to the manufacturer or its responsible person. § 94 MPDG backs the activity without expertise, the missing proof and the omitted recording or forwarding with a fine of up to thirty thousand euros.

Read more
Infusion pump on a drip stand in an empty, bright hospital corridor with a window in the background
Product Safety17 September 20269 min read

Article 87 MDR: three deadlines for serious incidents, 15 days, 10 days, 2 days, and the rule to report anyway when in doubt

Article 87 of Regulation (EU) 2017/745 obliges every manufacturer, regardless of size, to report serious incidents: no later than 15 days after becoming aware, no later than ten days in the event of death or an unanticipated serious deterioration in health, no later than two days in the event of a serious public health threat. Paragraph 7 removes uncertainty as an excuse. The wording, with the Article 2 definitions.

Read more
Connected production machine in a bright factory hall, a sensor with data cable in sharp focus in the foreground
Product Safety17 September 20269 min read

Articles 3 and 7 Data Act: connected products placed on the market after 12 September 2026 must make data accessible by default – not below 50 employees, yes from 50

Article 3(1) of Regulation (EU) 2023/2854 requires connected products to be designed and manufactured so that product data are accessible to the user „standardmäßig … einfach, sicher, unentgeltlich“ – by default, easily, securely, free of charge. Under Article 50 this applies to products placed on the market after 12 September 2026. Article 7(1) exempts micro and small enterprises and gives medium-sized ones a year. What that means for manufacturers with 20, 60 and 300 employees.

Read more
Aisle in a data centre with open racks and neatly bundled coloured cabling in cool light
Governance & Compliance17 September 202610 min read

Articles 25 and 29 Data Act: the clauses every SaaS contract has needed since 12 September 2025, and why switching charges fall to zero on 12 January 2027

Regulation (EU) 2023/2854 has applied since 12 September 2025 and has no size threshold for providers of data processing services. Article 25 prescribes the minimum content of the contract, including a notice period of at most two months, a transitional period of at most 30 days and a retrieval period of at least 30 days. Article 29 bans switching charges from 12 January 2027. The wording, and what Article 31 exempts.

Read more
Accessible entrance of an office building with tactile paving, a low ramp and a handrail in morning light
Product Safety17 September 20269 min read

§ 17 BFSG: whoever relies on disproportionate burden documents it, keeps it for five years, reassesses on every change and notifies without delay

The exemption in § 17 of the German Accessibility Act (BFSG) is not a free pass. Subsection 2 requires a documented assessment kept for five years, subsection 3 a repeat at least every five years and on every change to the service, subsection 5 immediate notification of the market surveillance authority. Only micro-enterprises are partly exempt, and those end at ten employees.

Read more
Height-adjustable workstation with clear space for a wheelchair in an empty, bright open-plan office
Personnel17 September 202610 min read

From 20 jobs upwards: the five per cent quota of § 154 SGB IX, the compensatory levy of § 160 and the notice due by 31 March

An employer with an annual monthly average of at least 20 jobs must fill five per cent of them with severely disabled people, pays a tiered compensatory levy for every unfilled mandatory position and reports the figures to the Federal Employment Agency by 31 March. The three provisions verbatim, with the counting rules of § 156 and the fine provisions of § 238.

Read more
Green, amber, red: what the confidence of a Compliance Agent answer means, where the sources come from and when the answer is withheld
Platform & Strategy16 September 20269 min read

Green, amber, red: what the confidence of a Compliance Agent answer means, where the sources come from and when the answer is withheld

Every answer of the Compliance Agent in CIVAC carries a confidence on three levels with a reason, a list of typed sources and an escalation field. This article describes what goes into an answer, how the three levels are defined in the instruction, when the model may not give a substantive answer, and why the escalation field is a note to the officer and not a handover to a law firm.

Read more
The Pflichten-Check: four profile fields, three levels, one statute per role, and what the indication does not decide
Platform & Strategy16 September 20268 min read

The Pflichten-Check: four profile fields, three levels, one statute per role, and what the indication does not decide

The Pflichten-Check in CIVAC matches the company profile against the role catalogue and returns one finding per role: mandatory, recommended or monitor, with the statute, the profile fact that triggers the duty, and a next step. This article describes which four fields go in, how a finding is structured, what the traffic light at the end means, and why the result is only as good as the profile.

Read more
The Abmahncheck: nine review areas, five severities, one statute per finding, and what the check expressly does not assess
Platform & Strategy16 September 20269 min read

The Abmahncheck: nine review areas, five severities, one statute per finding, and what the check expressly does not assess

The Abmahncheck in CIVAC reads a website or an uploaded document and returns findings that each carry one category out of nine, one severity out of five, the statute the finding points to, a short evidence quote and a recommendation. This article describes what the check reviews field by field, how a finding is structured, why the result is a risk indication and not a legal assessment, and where its limits lie.

Read more
Five core steps, one data model: how a project in CIVAC runs from scope to report, and where no model is involved
Platform & Strategy16 September 20269 min read

Five core steps, one data model: how a project in CIVAC runs from scope to report, and where no model is involved

Every project in CIVAC, whether a DPIA, a supplier audit or incident handling, has the same five core steps: scope, documents, questions, risks, report. This article describes them as they stand in the data model: which fields each step carries, where a language model makes suggestions, where only people work, and why the report is marked as stale as soon as an answer changes.

Read more
Sections 6, 17, 45 ElektroG: registration before placing on the market, take-back from 400 square metres, fines up to EUR 100,000
Environmental Protection15 September 202611 min read

Sections 6, 17, 45 ElektroG: registration before placing on the market, take-back from 400 square metres, fines up to EUR 100,000

The German Electrical and Electronic Equipment Act catches manufacturers, dealers, marketplaces and fulfilment service providers with three interlocking provisions: the registration duty in section 6, the take-back duty in section 17 and the fines catalogue in section 45. Which thresholds the wording sets and who is liable for which breach.

Read more
Section 393 SGB V: since 1 July 2025 only a C5 Type 2 attestation counts, with one 18-month exception
IT Security & NIS-215 September 202610 min read

Section 393 SGB V: since 1 July 2025 only a C5 Type 2 attestation counts, with one 18-month exception

A German healthcare provider or health insurer processing social and health data in the cloud needs, under section 393(3) SGB V, a current C5 attestation of the data-processing entity. Subsection 4 fixes when Type 1 was enough, since when Type 2 is required and which 18 months apply to systems newly placed on the market.

Read more
Article 15(2) MDR: under 50 employees no in-house PRRC, but one "permanently and continuously"
Product Safety15 September 202610 min read

Article 15(2) MDR: under 50 employees no in-house PRRC, but one "permanently and continuously"

The Medical Devices Regulation requires every manufacturer to have a person responsible for regulatory compliance. Micro and small enterprises need not employ that person, but must have one permanently and continuously at their disposal. Where the threshold sits and what the wording actually demands.

Read more
Article 5n of Regulation (EU) No 833/2014: which software and which services a company may no longer provide to a customer established in Russia
Governance & Compliance15 September 202611 min read

Article 5n of Regulation (EU) No 833/2014: which software and which services a company may no longer provide to a customer established in Russia

ERP, CRM, CAD, online-banking software, IT consultancy and, since 25 November 2025, AI model access and high-performance computing: Art. 5n prohibits providing them to customers established in Russia. The wording, the authorisation grounds, the German criminal provision.

Read more