What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.

Software is an export: Art. 2 No. 2 lit. d of Regulation (EU) 2021/821 and the Cryptography Note
Whoever makes software available electronically to a user outside the EU is exporting. What the Dual-Use Regulation then requires, which notes decontrol, and which file has to exist even when the product is decontrolled.
Berlin Commissioner for Data Protection and Freedom of Information: What companies need to know in 2026
The Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI) is the supervisory authority for around 200,000 responsible persons in Berlin. This guide explains responsibility, reporting paths according to Art. 33 GDPR, current audit priorities and how you can keep evidence in an audit-proof manner.
DSB costs 2026: What a data protection officer really costs internally and externally
An internal DSB costs around 35,000 to 90,000 euros per year in full costs for medium-sized businesses, while an external DSB costs between 4,800 and 24,000 euros. This guide shows which items make the difference and when which model is worthwhile.
Data breach report to the supervisory authority: The 72-hour path according to Art. 33 GDPR
Art. 33 GDPR requires a data breach to be reported within 72 hours of becoming aware of it. This guide shows the path, the thresholds, the documentation and the connection to Art. 34 GDPR, cleanly and comprehensibly.
Order DSB for 20 or more employees: Obligation, deadline and appointment certificate
As soon as 20 people in the company are constantly engaged in automated processing of personal data, Section 38 BDSG applies. We show you how to document the order in a legally compliant manner, report it and fill it internally and externally.
Data protection officer costs 2026: What DSB really costs internally, externally and as a service
How much does a data protection officer cost in 2026? We break down internal full costs, external monthly flat rates and the officer-as-a-service model into comprehensible ranges, including cost drivers, risk items and fine logic in accordance with Art. 83 GDPR.

Patient-oriented complaints management: the hospital duty in § 135a (2) no. 2 SGB V
In a German hospital, patient-oriented complaints management is not a service topic but part of the statutory quality assurance duty. A subordinate clause in § 135a (2) no. 2 SGB V carries it.

Internal reporting office without a threshold: the nine categories in § 12 (3) HinSchG
For nine categories in the financial and insurance sector the duty to operate an internal reporting office applies regardless of headcount. Counting employees first is the wrong test order.

§ 36 HinSchG: the reversal of the burden of proof and what it means for personnel decisions after a report
Under § 36 (2) HinSchG a detriment suffered after a report is presumed to be a reprisal. The employer then carries the proof. What that means for transfers, appraisals and dismissals.

The effectiveness review under § 8 (5) LkSG: the annual clock and the event trigger
§ 8 (5) LkSG requires two reviews, not one: an annual clock and an event-driven review whenever the risk situation changes materially. Reviewing once a year does not satisfy it.
Data protection law in Germany: GDPR, BDSG and obligations 2026
The German data protection law consists of the GDPR and BDSG. This article explains the ordering requirement, 72-hour reporting according to Art. 33 GDPR, the risk of fines and how you can properly document the obligations in 2026.
ISB training: routes, providers, costs and realistic schedules
Anyone who takes on the ISB role needs solid qualifications. This article compares the most important training paths, providers, costs and examination formats and shows how you can secure the operational takeover of the role.
NIS2 Consulting: What to expect from a senior advisor in 2026
Germany's NIS-2 transposition is expected in 2026. Roughly 29,500 entities will need an information security officer, documented controls and a 24/72-hour reporting path. This article explains what mature NIS2 consulting looks like and how to choose the right delivery model.
LkSG with 1,000 employees or more: Catalog of duties 2024 and transition to CSDDD
Since January 1, 2024, the Supply Chain Due Diligence Act has also applied to companies with 1,000 or more employees. This article lists the eleven obligations according to Section 3 LkSG, the reporting deadlines and the transition to the EU Supply Chain Directive 2027.
Human rights officer: Obligation according to Section 4 Paragraph 3 LkSG and task profile
Since January 1, 2024, the LkSG obligation applies to all companies with 1,000 or more employees in Germany. Section 4 Paragraph 3 LkSG requires a person to monitor risk management. This article explains duties and orders.
Prevention measures LkSG in your own business area: practical list of obligations
According to Section 6, the LkSG requires preventive measures first in your own business area. This article shows which measures BAFA examines, how you document them and which structures CIVAC provides for this.
CSDDD Compliance Timeline: EU Due Diligence Obligations Until 2029
Directive (EU) 2024/1760 entered into force on 25 July 2024. Member States must transpose it by 26 July 2026. From 2027, the largest companies fall in scope, with full coverage by 2029. This guide maps every milestone, threshold, and officer role.
External environmental protection officer: appointment, duties, models
The external environmental protection officer relieves the burden on companies without their own specialist staff. We explain the ordering obligations according to BImSchG, KrWG and WHG as well as the CIVAC model with an SLA of 2 working days and audit-proof documentation in the workspace.
Supplier auditor: role, qualifications and obligation to provide documentation between ISO 9001, VDA 6.3 and LkSG
The supplier auditor decides whether procurement, quality and supply chain obligations come together. This guide explains qualifications, methodology, reporting line and the documentation requirement between ISO 9001:2015, VDA 6.3, IATF 16949 and LkSG.
HinSchG E: Set up and operate an internal reporting office
The search for hinschg e usually ends in the Whistleblower Protection Act. This guide explains the scope of application, the reporting point requirement for 50 or more employees, deadlines and how CIVAC operates the reporting point using a platform.
Real Estate Expert 2026: Roles, Duties, Order
A real estate expert provides market value reports that can be used in court, the tax office and the bank. Read about which qualifications will count in 2026, how the order process works and how reports can be translated into a verifiable workspace.
Quality management software for medium-sized companies in the DACH region
ISO 9001:2015 requires verifiable processes, measures and responsibilities. A QM software for DACH medium-sized companies must provide EU data residency, audit templates and a clear reporting line without slowing down the QMB in day-to-day business.
ISO 9001 QM manual template: sample structure, obligations and audit practice
ISO 9001:2015 no longer requires a classic QM manual, but in practice auditors still require a resilient structure. This template shows the structure, mandatory chapters and documentation.
Occupational medicine service providers in the DACH region: selection grid for appointing company doctors
Appointing a company doctor in accordance with Section 2 ASiG, ASchG or ArGV 3 requires more than a cheap all-inclusive offer. This article provides a selection grid with 14 criteria for DACH-wide tenders and shows how providers can really be compared.