What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
Building an integrated management system: From an ISO patchwork to a uniform compliance architecture
Anyone who maintains multiple ISO standards knows the problem: duplicate audits, contradictory procedures, redundant documents. An integrated management system based on a high level structure bundles requirements, reporting obligations and audit trails. This guide shows the structure, sequence and tools.
All agent roles in one software: When consolidation is worthwhile
Medium-sized companies manage six to twelve representative roles in parallel, usually in separate tools. Consolidated software reduces interface costs, closes audit gaps and makes the personal liability of management manageable. What needs to be taken into account.
§ 42 BDSG: Criminal liability for data misuse in German data protection law
Section 42 BDSG regulates criminal liability for intentional data misuse. This article explains the facts, the penalty range, the distinction from the GDPR fine and the organisational obligations of the management.
Doctor's practice hygiene plan 2022: What needs to be up to date since then
A hygiene plan is not a static document. Anyone who is still working with the 2022 version in 2026 risks complaints from the health department and KV. This article shows which RKI recommendations and legal bases have been updated since 2022.
Hygiene officers in nursing: What RKI and KRINKO require operationally
Care facilities must appoint hygiene officers according to clearly defined guidelines from the RKI and KRINKO. This article explains qualifications, tasks, documentation requirements and how CIVAC bundles the order, the hygiene plan and the audit evidence in one workspace.
KRINKO guidelines for hospital hygiene: obligations and implementation
Hospital hygiene is not a recommendation, but rather a requirement under the IfSG, state hygiene regulations and KRINKO specifications. This article shows how clinics document risk analyses, hygiene plans and reporting paths in a legally compliant manner.
Hygiene in care: worksheet, checklist and legally compliant instruction
A nursing hygiene worksheet is more than just a training slide. It is the central proof document for home supervision, MDK and the health department. This guide shows the structure, mandatory content and templates for practice.
Washing hands and hygiene: duties, methodology and evidence in the company
Washing your hands seems trivial, but it is anchored in the company's regulations: IfSG, LMHV, ArbStättV and the RKI-KRINKO recommendations prescribe procedures, means and evidence. The article shows obligations, methodology according to DIN EN 1499 and how hand hygiene can be documented in an audit-proof manner.
Hand hygiene in care: duties, indications, evidence
Hand hygiene is the single most effective measure against nosocomial infections. This guide organises the legal obligations according to Section 23 IfSG, the five WHO indications and the operational evidence that home supervision and MD examiners want to see.
Institute for Hygiene and Environmental Medicine: tasks, duties, practical role
Institutes for hygiene and environmental medicine provide analysis, inspection and advice. Anyone who has to fulfil operational hygiene obligations according to IfSG, BioStoffV and TrinkwV also needs an internal representative structure. This article explains tasks and interfaces.
Hygiene training online: legal framework, content and auditable evidence
Online hygiene training is recognised in many industries, but does not replace every instruction. The article explains Section 43 IfSG, annual follow-up instructions, minimum technical requirements and the trail of evidence with which hygiene officers and management satisfy supervisory authorities.
Metro hygiene: what wholesale, catering and HACCP really demand from each other
Anyone who buys food wholesale and processes it in the catering industry has a double hygiene chain. The article explains obligations according to LMHV, IfSG and HACCP, shows how hygiene officers keep a complete track of receipts from goods receipt to the guest and where CIVAC can provide relief.
Hygiene instructions according to § 43 IfSG: Obligation, deadline, proof
Anyone who handles food needs instruction in accordance with Section 43 of the Infection Protection Act. This article explains the scope, deadlines, content and how the hygiene officer keeps the evidence in a verifiable manner.
External Compliance Officer for B2B SaaS in Germany: Roles, Cost, Setup
B2B SaaS founders in Germany face overlapping duties under GDPR, NIS-2, HinSchG, and ISO/IEC 27001:2022. An external compliance officer covers the controls without an internal hire, leaving the engineering roadmap untouched.
EU AI Act: Obligations for High-Risk AI Systems in Practice
The EU AI Act introduces twelve cumulative obligations for providers of high-risk AI systems and four additional duties for deployers. This article translates Articles 8 to 27 into a working compliance routine: risk management, data governance, logging, human oversight, transparency, and conformity assessment.
Compliance guidelines for medium-sized companies: templates that withstand regulatory scrutiny
Downloaded Word templates are rarely sufficient for a supervisory audit. This article shows which elements a compliance policy needs in medium-sized companies, how the appointment certificate, proof of training and escalation path are neatly interlinked and how CIVAC provides templates in a version-specific manner.
Compliance audit in medium-sized companies: Checklist 2026 for management and representatives
This 2026 checklist shows medium-sized companies step by step which 14 subject areas a compliance audit covers, which documents must be available and how the platform documentation reduces the effort.
Building a tax compliance management system: Seven building blocks according to IDW PS 980
A tax compliance management system only protects against criminal proceedings if all seven basic elements according to IDW PS 980 are implemented and documented. The application decree for Section 153 AO expressly recognises the Tax CMS as an indication of intent.
Kerberos Compliance: Check authentication, prove risks, pass audit
Kerberos is the silent backbone of many Active Directory environments. Reviewers ask about key lengths, ticket lifetimes, and Kerberoasting protection. This article shows what evidence ISO 27001:2022 and NIS-2 expect from you and how you can file it in a structured manner.
Governance, Risk and Compliance: How GRC becomes an operational discipline
Governance, risk and compliance only works if the appointment certificate, risk register and audit evidence live in the same system. This article shows how GRC according to ISO 37301 and ISO 31000 is managed as an operational process, not as a slide carousel.
Compliance consulting 2026: When the workshop is enough and when a representative has to take over
Compliance consulting often promises strategy and delivers PowerPoint. This article explains which form of delivery fulfils which obligation, how you differentiate between consultants, platforms and agents and how you measure audit robustness.
Who needs a compliance officer in the company: duty, thresholds, risk
There is only an explicit obligation to appoint a compliance officer in a few industries. In fact, Section 130 OWiG forces every management to supervise. This article specifically explains who is responsible and when.
Outsourced DPO: When an External Data Protection Officer Outperforms an Internal Hire
An outsourced DPO covers GDPR Article 37 duties, breach reporting under Article 33, and evidence files for supervisory authorities. This guide explains scope, cost ranges, and how an external DPO integrates with German labour law and works alongside the information security officer.
GDPR Compliance Software for German Mid Market in 2026: A Practical Buyer Guide
GDPR enforcement against the German Mittelstand has intensified since the federal coordinated audit of 2025. This buyer guide shows what a modern compliance platform must deliver: records, breach pipelines, residency, officer workflows, and signed records of authority.