FAQs.

on the data protection officer and the data protection audit

FAQs2023-10-30T14:42:07+01:00
What qualifications must a data protection officer have?2023-03-22T15:09:02+01:00

A data protection officer must fulfill the following three main factors in accordance with the requirements of Art. 37 para. 5 GDPR:

  • professional qualification with regard to expertise in the field of data protection law
  • Specialist knowledge in the field of data protection practice
  • Ability to perform the tasks specified in Art. 39 GDPR (see above)
How is a data protection officer liable?2023-03-22T15:09:05+01:00

The external data protection officer is personally liable for all activities. Due to this high risk, we have developed an insurance concept that covers losses of up to EUR 40 million.

According to which standards is the data protection audit carried out?2023-03-22T15:09:59+01:00

We audit your company in accordance with the legal standards of the GDPR and the BDSG (new). From a practical perspective, we are guided by the legal requirements of the audit procedures of the state data protection authorities.

What are the benefits of structured AI compliance?May 6, 2026, 4:05:50 PM

Companies reduce regulatory risks, build trust with customers and business partners, and can use AI systems in a more secure, transparent, and sustainable manner.

What are the benefits of a data protection audit?2023-03-22T15:10:15+01:00

With a data protection audit, you can prove to customers and also during an official audit that you comply with and implement the legal provisions and requirements of the GDPR. Above all, you create trust with potential customers and cooperation partners who want proof of GDPR compliance.

What is the process for an ISO 27001 project?May 6, 2026, 3:51:35 p.m.

The project typically begins with a GAP analysis. This is followed by a risk analysis, the implementation of the ISMS, the preparation of the necessary documentation, and preparation for the certification audit.

What are the costs of a data protection audit?2023-03-22T15:10:37+01:00

The costs depend on the size of the company and the number of branches. We will be happy to provide you with a fixed price offer within 24 hours.

How long does it take to implement an ISMS in accordance with ISO 27001?May 6, 2026, 3:52:03 p.m.

The duration depends on the size and complexity of the organization. In many cases, a certifiable ISMS can be established within a few months.

Can ISO 27001 be combined with data protection and NIS2?May 6, 2026, 3:56:53 PM

Yes. ISO 27001 can be seamlessly integrated with GDPR data protection requirements as well as regulatory requirements such as NIS2 or DORA, creating synergies and more efficient processes.

Can AI compliance be combined with data protection and ISO 27001?May 6, 2026, 4:04:43 p.m.

Yes. AI compliance can be effectively integrated with data protection, information security, and governance frameworks—particularly in conjunction with the GDPR, ISO 27001, NIS2, or DORA.

Which companies need AI compliance?May 6, 2026, 4:00:46 p.m.

AI compliance is relevant for all companies that use or develop AI systems—particularly in the fields of HR, customer service, marketing, finance, healthcare, software, or automated decision-making processes.

What are the tasks of a data protection officer?2023-03-22T15:09:08+01:00

The specific tasks of the data protection officer result from the GDPR and primarily include

  • Monitoring the legal requirements of the GDPR
  • Overview of processing activities
  • Risk assessment for processing activities
  • Employee training
Which AI systems need to be tested?May 6, 2026, 4:03:25 PM

As a general rule, all AI solutions in use should be evaluated—particularly external AI tools, generative AI, HR systems, automated decision-making processes, and AI applications that process personal data.

What are the benefits of ISO 27001 certification?May 6, 2026, 3:50:37 p.m.

ISO 27001 certification strengthens information security, reduces risks, and builds trust among customers, partners, and regulatory authorities. At the same time, it helps streamline internal processes and ensure compliance with regulatory requirements.

Do you also provide support for AI governance and policies?May 6, 2026, 4:04:04 PM

Yes. We help companies establish legally compliant AI governance frameworks and develop internal AI policies, usage guidelines, and compliance processes.

What documents and guidelines are being developed?May 6, 2026, 3:56:09 p.m.

We assist with the development of all necessary policies and documentation, including security policies, risk analyses, asset management, access control frameworks, emergency plans, and ISMS documentation.

Which companies need ISO 27001?May 6, 2026, 3:54:32 p.m.

ISO 27001 is particularly well-suited for organizations with high standards for information security, data protection, and compliance—such as those in the IT, software, healthcare, finance, manufacturing, or critical infrastructure sectors.

What are the risks associated with the use of AI?May 6, 2026, 4:02:15 PM

The use of AI can entail risks related to data protection, liability, compliance, and reputation. Of particular concern are erroneous decisions, a lack of transparency, discriminatory outcomes, or insecure data processing.

Do you also offer employee training on AI?May 6, 2026, 4:05:21 PM

Yes. We offer practical training and awareness sessions for employees, managers, and compliance officers on the safe and legally compliant use of AI.

Do you also provide support for existing AI systems?May 6, 2026, 4:06:19 PM

Yes. AI solutions that are already in use can be reviewed, evaluated, and adapted to meet current regulatory requirements.

What are the costs associated with ISO 27001 consulting?May 6, 2026, 3:49:45 PM

The cost depends on the size of your company, the complexity of your IT infrastructure, and the scope of certification you require. We would be happy to provide you with a customized, fixed-price quote within 24 hours.

Who needs a data protection officer?2023-03-22T15:09:11+01:00

Certain companies are obliged to appoint a (external or company) data protection officer. The General Data Protection Regulation (GDPR) and the new BDSG stipulate the appointment of a company data protection officer if one of the following conditions is met:

a) As a rule, at least ten people are permanently involved in the automated processing of personal data in the company.

b) The core activity of the company is the performance of processing operations which, by virtue of their nature, their scope and/or their purposes, require extensive regular and systematic monitoring of data subjects (this includes, for example, hospitals and pharmacies).

What does an AI compliance project entail?May 6, 2026, 4:02:50 PM

The process begins with an analysis of the AI systems and processes in use. Risks are then assessed, necessary measures are defined, and governance, documentation, and compliance frameworks are established.

What does the EU AI Act cover?May 6, 2026, 4:01:34 p.m.

The EU AI Act establishes Europe-wide requirements for the safe and legally compliant use of artificial intelligence. Depending on their risk category, companies must meet specific transparency, documentation, and security requirements.

Do you also provide support for ISO 27001 certification?May 6, 2026, 3:55:35 PM

Yes. We support companies throughout the entire project—from the initial analysis through to the successful preparation for and support during the external certification audit.