What we do for you
Our Services
Our core expertise lies at the intersection of law and technology. We advise you on data protection, information security and AI compliance, guiding you from strategic planning through to operational implementation.
Services Overview
Three focus areas. One point of contact.
All services from a single source, from strategic advisory through to operational implementation.
Data Protection & GDPR
As an external Data Protection Officer or through project-based advisory, we support you in the legally sound implementation of the GDPR and the German Federal Data Protection Act (BDSG).
Information Security & ISMS
Legal support in building, certifying and operating your ISMS in accordance with ISO/IEC 27001 and BSI IT-Grundschutz.
AI Compliance
Systematic identification, assessment and management of AI risks under the EU AI Act and ISO 42001.
Services in Detail
Our Focus Areas
Data Protection & GDPR Compliance
The GDPR confronts companies with complex requirements. As an experienced data protection advisor, we ensure legally sound processes and IT systems. I am also glad to personally take on the role of Data Protection Officer. In particular, we support you with:
- creating and maintaining your Record of Processing Activities (ROPA)
- conducting Data Protection Impact Assessments (DPIA)
- drafting and reviewing Data Processing Agreements (DPA)
- reviewing and adapting your technical and organisational measures (TOMs)
- training and employee awareness
Information Security Management (ISMS)
Whether driven by your own interests or required by your clients: an effective ISMS, for example one based on ISO/IEC 27001, protects the availability, confidentiality and integrity of your information. We support you from the gap analysis through to successful certification and beyond.
- Gap analysis and risk assessment
- Building and documenting the ISMS
- Preparing for and supporting certification audits
- Ongoing support and continuous improvement
AI Compliance & Governance
We develop tailored compliance frameworks and governance structures that make legal and technical risks systematically manageable, from analysis through to implementation.
- Building a compliance framework in accordance with ISO/IEC 42001
- Allocating responsibility (provider or deployer)
- Support in creating and maintaining your AI register
- Conducting risk assessments
- Building AI literacy
- Drafting policies and work instructions
- Preparing for regulatory audits and inspections