What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
Processing directory template according to GDPR: What an auditable template really needs to contain
A processing directory template in accordance with Art. 30 GDPR can be found online in five minutes. Whether it is test-proof is not determined by the column head, but by how it is maintained. The article shows mandatory fields, typical gaps and the transition from the template to the maintained directory.
Using AI in the company in compliance with data protection regulations: obligations, processes, evidence
Generative AI has arrived in medium-sized businesses. GDPR, EU AI Act and the BDSG provide a clear framework. This article shows which test steps, evidence and roles you need before ChatGPT, Copilot or Claude runs productively.
External DPO: Order, obligations and costs within a verifiable framework
An external DPO relieves management and IT if the order is clearly documented and the tasks specified in Art. 39 GDPR are carried out. This article shows the scope of obligations, the cost framework and the difference between a filing cabinet and an audit-proof platform.
Personal data according to GDPR: definition, categories and operational consequences
Personal data is the trigger for every GDPR obligation. Anyone who clearly defines the term from Art. 4 No. 1 GDPR identifies risks earlier, documents processing in a verifiable manner and accelerates audits and reporting paths in accordance with Art. 33 GDPR.
Art. 6 GDPR: The six legal bases are clearly documented and audit-proof
Art. 6 GDPR lists six legal bases. In practice, however, it is not the letter but the documentation that determines whether processing lasts. The article shows how you can select, justify and anchor legal bases in a directory in an audit-proof manner.
External DPO vs. Internal DPO in Germany: When Outsourcing Wins
Internal DPOs cost more than companies expect, carry hidden conflicts of interest and rarely scale across 25 compliance roles. This article maps the trade-offs and shows when an external Data Protection Officer is the audit-defensible choice in Germany.
Escape route signage according to ASR A2.3: specifications, obligations and audit evidence
ASR A2.3 specifies the requirements of the Workplace Ordinance for escape routes and their marking. The article explains minimum widths, signage according to DIN EN ISO 7010, emergency lighting, escape route plans and the evidence trail for fire protection officers.
Money laundering officer duty: who has to order, what are the tasks, how much does a violation cost
The money laundering officer obligation is narrowly defined, but in practice it is relevant for many companies. The article shows when the obligation is triggered, what tasks the mandate includes, what orders BaFin can issue and how CIVAC relieves the burden with Workspace and Officer-as-a-Service.
What does a money laundering officer do according to Section 7 GwG? Tasks, liability, order
Anyone who appoints a money laundering officer in accordance with Section 7 of the GwG defines a key role in money laundering prevention. This article shows tasks, authorities, reporting channels and personal liability in corporations and medium-sized companies.
AGG obligation: What employers really have to implement
The General Equal Treatment Act (AGG) obliges every employer to set up a complaints office, train the workforce and post notices. The article describes the specific obligations, the documentation, the liability consequences and how an external AGG complaints office is set up via CIVAC.
AML Officer Services for Financial Institutions in Germany: External Appointment, Scope, Cost
Section 7 GwG requires obliged entities in the German financial sector to appoint a money laundering officer (Geldwaeschebeauftragter). External AML officer services keep the mandate audit-fest under BaFin supervision without expanding the internal headcount.
Company doctor: From what number of employees does the obligation to order apply?
The obligation to appoint a company doctor results from the ASiG and DGUV regulation 2 and is not rigidly tied to an employee threshold. This article explains standard and alternative support, calculation of operating times and the auditable documentation of the order.
Construction site regulations (BaustellV): Obligations, SiGeKo order and advance notice in practice
The Construction Site Ordinance has regulated coordination obligations on construction sites since 1998. This article explains advance notice, SiGe plan, SiGeKo order, building owner's obligations and the interface to construction management in practice in 2026.
HinSchG draft bill: history, current status, what the upcoming amendment means for internal reporting points
The draft bill for the Whistleblower Protection Act from 2022 has had a significant impact on today's legal situation. Anyone who knows the history of its origins understands the scope for interpretation and can set up their internal reporting office in such a way that it can survive a future amendment.
Have a market value report drawn up: plan the duration realistically
Depending on the property, it takes between three and twelve weeks from the order to the signed market value report. We break down the duration into five phases, name accelerators and show when a short report is sufficient and when only the full report is sufficient.
External ISO 9001 Quality Manager in Germany: When to Outsource the QMB Role
An external ISO 9001 quality manager in Germany must meet the same formal appointment requirements as an internal QMB. This article explains role, liability, audit chain and how CIVAC delivers an appointed quality manager with workspace access in 2 business days.
Order QMB externally: When an external quality management representative is the better choice
An external QMB provides ISO 9001 expertise, audit preparation and a documented QM system without a full-time position. The article clarifies responsibility, costs, selection criteria and the handover to permanent operation.
Occupational health care G 37 VDU work: duration, deadlines, documentation
Prevention according to DGUV G 37 (computer workstations) takes between 20 and 40 minutes of pure examination time. The intervals result from ArbMedVV. Who documents what and how long must evidence be kept? Answers for management and company doctors.
Company doctor in the company: duties, appointment and interaction with compliance
The Occupational Safety Act requires employers to appoint a company doctor in writing. This article explains the legal obligations, the operating times according to DGUV regulation 2, the collaboration with occupational safety specialists and the integration into a compliance platform.
Setting up a whistleblower hotline in medium-sized companies: duties, channels, reporting line
The obligation to have an internal reporting office under the HinSchG has also applied to companies with 50 to 249 employees since December 17, 2023. This article shows how medium-sized companies set up the whistleblower hotline in a legally secure manner, combine the complaints office and data protection and present evidence in the audit.
Set up an AGG complaint office: Section 13 AGG, appointment certificate and procedural model
Section 13 AGG obliges every employer to set up a complaints office for cases of discrimination. The article provides templates for ordering, procedures and documentation and shows how CIVAC operates the position as an internal function or as an external solution under Officer-as-a-Service.
Money laundering officer costs 2026: What internal, external and hybrid really costs
The costs of a money laundering officer range from 800 euros per month if appointed externally to 80,000 euros in total annual costs in the internal model. Which route is right depends on the obligor status, risk profile and volume. This guide classifies the cost types, ranges and obligations in 2026.
Introduce the KYC process: Duties, stages and roles according to the AMLA
A KYC process is more than just identification on onboarding. It includes risk analysis, due diligence requirements per risk class, continuous monitoring and suspicious activity reporting. This guide shows what obliged entities must set up structurally in accordance with Section 2 of the GwG.
Annual fire protection instruction: duties, content, evidence 2026
Annual fire safety training is mandatory, but rarely well documented. Anyone who knows the legal basis and keeps records cleanly avoids fines, insurance disputes and personal liability on the part of the management.