77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
News & Insights

What officers need to know.

Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.

Latest
Software is an export: Art. 2 No. 2 lit. d of Regulation (EU) 2021/821 and the Cryptography Note
Governance & Compliance15 September 202611 min read

Software is an export: Art. 2 No. 2 lit. d of Regulation (EU) 2021/821 and the Cryptography Note

Whoever makes software available electronically to a user outside the EU is exporting. What the Dual-Use Regulation then requires, which notes decontrol, and which file has to exist even when the product is decontrolled.

Read more
Berlin Commissioner for Data Protection and Freedom of Information: What companies need to know in 2026
Data Protection & Privacy9 September 202612 min read

Berlin Commissioner for Data Protection and Freedom of Information: What companies need to know in 2026

The Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) is the supervisory authority for around 200,000 responsible persons in Berlin. This guide explains responsibility, reporting paths according to Art. 33 GDPR, current audit priorities and how you can keep evidence in an audit-proof manner.

Read more
DSB costs 2026: What a data protection officer really costs internally and externally
Data Protection & Privacy9 September 202613 min read

DSB costs 2026: What a data protection officer really costs internally and externally

An internal DSB costs around 35,000 to 90,000 euros per year in full costs for medium-sized businesses, while an external DSB costs between 4,800 and 24,000 euros. This guide shows which items make the difference and when which model is worthwhile.

Read more
Data breach report to the supervisory authority: The 72-hour path according to Art. 33 GDPR
Data Protection & Privacy9 September 202613 min read

Data breach report to the supervisory authority: The 72-hour path according to Art. 33 GDPR

Art. 33 GDPR requires a data breach to be reported within 72 hours of becoming aware of it. This guide shows the path, the thresholds, the documentation and the connection to Art. 34 GDPR, cleanly and comprehensibly.

Read more
Order DSB for 20 or more employees: Obligation, deadline and appointment certificate
Data Protection & Privacy9 September 202612 min read

Order DSB for 20 or more employees: Obligation, deadline and appointment certificate

As soon as 20 people in the company are constantly engaged in automated processing of personal data, Section 38 BDSG applies. We show you how to document the order in a legally compliant manner, report it and fill it internally and externally.

Read more
Data protection officer costs 2026: What DSB really costs internally, externally and as a service
Data Protection & Privacy9 September 202613 min read

Data protection officer costs 2026: What DSB really costs internally, externally and as a service

How much does a data protection officer cost in 2026? We break down internal full costs, external monthly flat rates and the officer-as-a-service model into comprehensible ranges, including cost drivers, risk items and fine logic in accordance with Art. 83 GDPR.

Read more
Patient-oriented complaints management: the hospital duty in § 135a (2) no. 2 SGB V
Health & Hygiene8 September 20269 min read

Patient-oriented complaints management: the hospital duty in § 135a (2) no. 2 SGB V

In a German hospital, patient-oriented complaints management is not a service topic but part of the statutory quality assurance duty. A subordinate clause in § 135a (2) no. 2 SGB V carries it.

Read more
Internal reporting office without a threshold: the nine categories in § 12 (3) HinSchG
Whistleblower Protection8 September 20269 min read

Internal reporting office without a threshold: the nine categories in § 12 (3) HinSchG

For nine categories in the financial and insurance sector the duty to operate an internal reporting office applies regardless of headcount. Counting employees first is the wrong test order.

Read more
§ 36 HinSchG: the reversal of the burden of proof and what it means for personnel decisions after a report
Whistleblower Protection8 September 202610 min read

§ 36 HinSchG: the reversal of the burden of proof and what it means for personnel decisions after a report

Under § 36 (2) HinSchG a detriment suffered after a report is presumed to be a reprisal. The employer then carries the proof. What that means for transfers, appraisals and dismissals.

Read more
The effectiveness review under § 8 (5) LkSG: the annual clock and the event trigger
Supply Chain8 September 20269 min read

The effectiveness review under § 8 (5) LkSG: the annual clock and the event trigger

§ 8 (5) LkSG requires two reviews, not one: an annual clock and an event-driven review whenever the risk situation changes materially. Reviewing once a year does not satisfy it.

Read more
Data protection law in Germany: GDPR, BDSG and obligations 2026
Data Protection & Privacy8 September 202613 min read

Data protection law in Germany: GDPR, BDSG and obligations 2026

The German data protection law consists of the GDPR and BDSG. This article explains the ordering requirement, 72-hour reporting according to Art. 33 GDPR, the risk of fines and how you can properly document the obligations in 2026.

Read more
ISB training: routes, providers, costs and realistic schedules
IT Security & NIS-28 September 202613 min read

ISB training: routes, providers, costs and realistic schedules

Anyone who takes on the ISB role needs solid qualifications. This article compares the most important training paths, providers, costs and examination formats and shows how you can secure the operational takeover of the role.

Read more
NIS2 Consulting: What to expect from a senior advisor in 2026
IT Security & NIS-28 September 202613 min read

NIS2 Consulting: What to expect from a senior advisor in 2026

Germany's NIS-2 transposition is expected in 2026. Roughly 29,500 entities will need an information security officer, documented controls and a 24/72-hour reporting path. This article explains what mature NIS2 consulting looks like and how to choose the right delivery model.

Read more
LkSG with 1,000 employees or more: Catalog of duties 2024 and transition to CSDDD
Supply Chain8 September 202613 min read

LkSG with 1,000 employees or more: Catalog of duties 2024 and transition to CSDDD

Since January 1, 2024, the Supply Chain Due Diligence Act has also applied to companies with 1,000 or more employees. This article lists the eleven obligations according to Section 3 LkSG, the reporting deadlines and the transition to the EU Supply Chain Directive 2027.

Read more
Human rights officer: Obligation according to Section 4 Paragraph 3 LkSG and task profile
Supply Chain8 September 202613 min read

Human rights officer: Obligation according to Section 4 Paragraph 3 LkSG and task profile

Since January 1, 2024, the LkSG obligation applies to all companies with 1,000 or more employees in Germany. Section 4 Paragraph 3 LkSG requires a person to monitor risk management. This article explains duties and orders.

Read more
Prevention measures LkSG in your own business area: practical list of obligations
Supply Chain7 September 202612 min read

Prevention measures LkSG in your own business area: practical list of obligations

According to Section 6, the LkSG requires preventive measures first in your own business area. This article shows which measures BAFA examines, how you document them and which structures CIVAC provides for this.

Read more
CSDDD Compliance Timeline: EU Due Diligence Obligations Until 2029
Supply Chain7 September 202613 min read

CSDDD Compliance Timeline: EU Due Diligence Obligations Until 2029

Directive (EU) 2024/1760 entered into force on 25 July 2024. Member States must transpose it by 26 July 2026. From 2027, the largest companies fall in scope, with full coverage by 2029. This guide maps every milestone, threshold, and officer role.

Read more
External environmental protection officer: appointment, duties, models
Environmental Protection7 September 202612 min read

External environmental protection officer: appointment, duties, models

The external environmental protection officer relieves the burden on companies without their own specialist staff. We explain the ordering obligations according to BImSchG, KrWG and WHG as well as the CIVAC model with an SLA of 2 working days and audit-proof documentation in the workspace.

Read more
Supplier auditor: role, qualifications and obligation to provide documentation between ISO 9001, VDA 6.3 and LkSG
Audits & Suppliers7 September 202613 min read

Supplier auditor: role, qualifications and obligation to provide documentation between ISO 9001, VDA 6.3 and LkSG

The supplier auditor decides whether procurement, quality and supply chain obligations come together. This guide explains qualifications, methodology, reporting line and the documentation requirement between ISO 9001:2015, VDA 6.3, IATF 16949 and LkSG.

Read more
HinSchG E: Set up and operate an internal reporting office
Whistleblower Protection7 September 202612 min read

HinSchG E: Set up and operate an internal reporting office

The search for hinschg e usually ends in the Whistleblower Protection Act. This guide explains the scope of application, the reporting point requirement for 50 or more employees, deadlines and how CIVAC operates the reporting point using a platform.

Read more
Real Estate Expert 2026: Roles, Duties, Order
Expert Assessors6 September 202612 min read

Real Estate Expert 2026: Roles, Duties, Order

A real estate expert provides market value reports that can be used in court, the tax office and the bank. Read about which qualifications will count in 2026, how the order process works and how reports can be translated into a verifiable workspace.

Read more
Quality management software for medium-sized companies in the DACH region
Quality Management6 September 202612 min read

Quality management software for medium-sized companies in the DACH region

ISO 9001:2015 requires verifiable processes, measures and responsibilities. A QM software for DACH medium-sized companies must provide EU data residency, audit templates and a clear reporting line without slowing down the QMB in day-to-day business.

Read more
ISO 9001 QM manual template: sample structure, obligations and audit practice
Quality Management6 September 202612 min read

ISO 9001 QM manual template: sample structure, obligations and audit practice

ISO 9001:2015 no longer requires a classic QM manual, but in practice auditors still require a resilient structure. This template shows the structure, mandatory chapters and documentation.

Read more
Occupational medicine service providers in the DACH region: selection grid for appointing company doctors
Occupational Medicine6 September 202612 min read

Occupational medicine service providers in the DACH region: selection grid for appointing company doctors

Appointing a company doctor in accordance with Section 2 ASiG, ASchG or ArGV 3 requires more than a cheap all-inclusive offer. This article provides a selection grid with 14 criteria for DACH-wide tenders and shows how providers can really be compared.

Read more