Data protection and GDPR compliance
External data protection officer & GDPR consulting
With our thorough grasp of data protection and IT, we make sure your company processes personal data the way the GDPR requires.

Data protection and GDPR compliance
With our thorough grasp of data protection and IT, we make sure your company processes personal data the way the GDPR requires.
Complying with the General Data Protection Regulation (GDPR) and handling personal data correctly is indispensable for companies of every size. Since the GDPR came in, however, what is demanded of companies has grown considerably stricter. Those legal changes leave many companies facing difficulties – not only in implementation, but in the time and cost it takes. That is exactly where we come in, and we would be glad to offer you thorough advice.
Our company offers comprehensive advisory services in data protection, particularly in implementing the GDPR and the national additions made by the German Federal Data Protection Act (BDSG). We help you navigate the complex requirements of the GDPR, either by supporting your internal data protection officer or by taking on the role ourselves as an external data protection officer for the greater Freiburg area.
Our focus is on developing data protection solutions tailored to you. Those include:
Our expertise makes sure your company not only keeps to the strict rules of the GDPR, but does so efficiently and affordably. Contact us for professional advice and support on data protection and GDPR compliance.
At a time when data protection matters more and more, it is tempting to look for quick, easy answers and reach for a template or a generator. Those tools promise something simple and cheap, but they carry considerable risk and can end up costing more than professional advice would have.
Every company is unique – in its processes, in its customers, and in how it processes data. Templates and generators usually offer only standardised text, not something cut to a particular company's needs and obligations. A privacy policy written with professional advice takes the individual aspects of your company into account and makes sure every relevant point is covered.
For non-specialists it is often hard to see when and how data processing happens in their own company. Professional data protection advisers bring the knowledge needed to identify and assess every flow of data through your business, and make sure your privacy policy describes all of them correctly.
The General Data Protection Regulation sets strict requirements for processing personal data. A template or an automated generator may not account for all of them, which leads to compliance problems. Professional advisers keep up with the legislation and make sure your privacy policy meets the requirements as they currently stand.
An inadequate privacy policy can have serious consequences, including substantial fines. Given how many proceedings over data protection breaches are now brought, relying on generic text is a risk. A policy written by specialists offers a far higher degree of certainty and compliance.
Using a template or a generator may look cheap at first, but the financial and legal consequences of non-compliance can be considerable. Investing in professional data protection advice is an investment in the security and the durability of your company.
There is no flat answer, because the cost depends on several things: the size of your company and the number of employees, the nature and sensitivity of the personal data processed (health or financial data, for instance), the number and complexity of your processing activities, and how much support you want. The usual arrangements are either a monthly flat fee for ongoing support or billing by actual effort. After a short conversation we will gladly put together a transparent quote for your company – get in touch, with no obligation.
Under § 38 BDSG, companies must appoint a data protection officer as soon as they permanently employ at least 20 people on the automated processing of personal data. The obligation can apply regardless of headcount – for example if your core activity consists of extensive, regular and systematic monitoring of individuals, or if you process special categories of personal data on a large scale (Art. 37 GDPR). Whether and in what form the duty applies to you is something we check as part of an individual consultation.
A data processing agreement is required by Art. 28 GDPR whenever an external service provider processes personal data on your behalf – cloud, hosting, newsletter or IT providers, for example. Among other things it sets out the subject matter and purpose of the processing, the processor's obligations, and the technical and organisational measures protecting the data. We review your existing agreements and draft legally sound ones for your company.
An external data protection officer brings specialised, current expertise without your having to train and permanently commit your own staff. You avoid internal conflicts of interest, gain a neutral outside view, and pay only for the support you actually need. For small and medium-sized companies in particular, that is often the more efficient answer in both cost and time.
Call us or write to us — we will come back to you.