News & Insights
We are your first port of call for the latest news, analysis and background information on data protection, data strategy and IT security. We keep you informed with editorially prepared news and interesting facts. Subscribe directly to our newsletter and never miss a thing again.
27.08.2026
How to create a GDPR erasure concept: templates, deadlines and practical erasure rules
The GDPR clearly stipulates that personal data may not be stored indefinitely. A structured erasure concept helps implement legal requirements, minimise risks and maintain an overview. Find out how an effective concept is structured, which deadlines apply and what matters in practice.
Read more … How to create a GDPR erasure concept: templates, deadlines and practical erasure rules
19.08.2026
Share Deal in a consulting firm: data valuation, information security and ISO 27001
In consulting firms, a large share of enterprise value lies in methodologies, project experience, client knowledge and reusable information assets. These intangible assets are often stored in cloud platforms, knowledge bases, project tools and AI applications. Whether this becomes scalable know-how or a costly legacy burden depends on integrated data due diligence covering data protection, information security, ISO 27001, rights review and data governance.
Read more … Share Deal in a consulting firm: data valuation, information security and ISO 27001
11.08.2026
Creating an IT security concept in 7 steps
05.08.2026
The 10 most important questions about data strategy
Data are, or should be, the most important foundation for business decisions in every company. Whether in marketing, finance, product development or HR, solid figures and facts lead to better outcomes. To achieve this, however, data must also be structured and accessible. That is only possible with a well-designed data strategy. We have summarised the 10 most important questions on this topic for you.
Read more … The 10 most important questions about data strategy
28.07.2026
The 4 most common reasons why ISO 27001 certifications fail
ISO 27001 certification rarely fails at the external audit stage; it fails at an earlier stage. ISO projects are often only worked on when there are no other urgent tasks in the company. If you want to ensure the success of your ISO 27001 project, there are a few decisive factors that have proven themselves time and again in practice.
Read more … The 4 most common reasons why ISO 27001 certifications fail
21.07.2026
Microsoft 365 & data protection: identify risks, implement measures and work in compliance with the GDPR
Whether Microsoft 365 can be used in compliance with data protection law cannot be answered with a blanket yes or no. What matters is the specific way in which it is used in the respective company. The situation has improved since 2022, but parts of the criticism previously raised by supervisory authorities remain. We explain the actual risks, the current position of the authorities and the measures that matter now.
16.07.2026
NIS2 Tools for SMEs: why tools help, but cannot buy compliance
No tool automatically makes a company NIS2-compliant. Tools only accelerate implementation if risks, responsibilities and processes have been clarified first. We show which tool categories you really need, what a pragmatic basic stack looks like and which questions you should answer before making any purchase.
Read more … NIS2 Tools for SMEs: why tools help, but cannot buy compliance
03.07.2026
Data protection & IT security in M&A: review framework for data value, risks and deal implications
Data increases enterprise value only if it is economically usable, legally exploitable and technically protected. Missing legal bases, weak IT security or unclear data quality can turn what appears to be a value driver into a concrete deal risk. We explain how private equity investors and deal teams can systematically assess data value, data protection and IT security in due diligence and translate the findings into concrete deal mechanics.
25.06.2026
Deploying AI agents lawfully: fom hallucination risks to privacy by design
AI agents can perform tasks independently, make decisions and interact with IT systems — and that is precisely what makes them challenging from a compliance perspective. Deleted databases, legally binding chatbot statements and autonomous smear campaigns show that the risks are no longer theoretical. We explain which legal requirements apply and how companies can use AI agents in a legally compliant manner.
Read more … Deploying AI agents lawfully: fom hallucination risks to privacy by design
04.06.2026
Cookie banners in 2026: what must they be capable Of and Is reform on the horizon?
Cookie banners are intended to safeguard data protection, yet many users now click “Accept” out of sheer frustration. At the same time, pressure for reform is growing at EU level. What does this mean for companies? And what requirements actually apply today? An overview of the legal framework, practical challenges, and available courses of action.
Read more … Cookie banners in 2026: what must they be capable Of and Is reform on the horizon?