Legal & Regulatory Framework
Legal Requirements: Data Protection, IT Security & AI Compliance
protection, IT security, and the use of artificial intelligence are no longer optional considerations but areas of corporate responsibility governed by law. Companies are required to assess risks, document processes, and implement appropriate safeguards. Non-compliance can result not only in substantial fines but also in significant financial and reputational damage.
GDPR – General Data Protection Regulation
The GDPR governs the processing of personal data within the European Union. Companies are required to process personal data lawfully, transparently, and securely. This includes, among other requirements, transparency and information obligations, technical safeguards, documentation, as well as procedures for handling data breaches and data subject rights.
BDSG – German Federal Data Protection Act
The German Federal Data Protection Act (BDSG) supplements the GDPR with specific national provisions applicable in Germany. Particularly relevant are the requirements relating to employee data protection and the appointment of a Data Protection Officer. Companies must ensure compliance with both European and German data protection requirements.
NIS2 Directive
The European NIS2 Directive significantly strengthens cybersecurity requirements for companies. Organisations within its scope are required to implement appropriate security measures, document risks, and report security incidents. Of particular importance is the increased responsibility and accountability of senior management for cybersecurity matters.
German IT Security Act
The German IT Security Act requires companies – particularly operators of critical infrastructure – to implement appropriate technical and organisational security measures. Its purpose is to protect digital systems against cyberattacks, disruptions, and manipulation.
ISO/IEC 27001
ISO/IEC 27001 is an internationally recognised standard for Information Security Management Systems (ISMS). It enables companies to establish structured processes for identifying, assessing, and mitigating information security risks. Compliance with recognised information security standards has increasingly become a prerequisite for many customers, business partners, and tender processes.
EU AI Act
With the EU AI Act, the European Union has introduced a comprehensive binding regulatory framework for the use of artificial intelligence. Companies must assess AI systems according to their risk classification and comply with specific transparency, documentation, and oversight requirements. High-risk AI systems, in particular, are subject to stringent regulatory requirements.
Additional Requirements for the Use of AI
In addition to the EU AI Act, data protection law, copyright law, and governance requirements also play an important role. Companies must maintain transparent and traceable documentation of how AI systems are used, what data is processed, and how associated risks are managed. The responsible use of AI is increasingly becoming a key factor in building trust and maintaining a competitive advantage
Data Protection Officer
If at least 20 employees within a company – including managing directors, interns, students, etc. – are regularly involved in the processing of personal data, the company is generally required to appoint a Data Protection Officer (DPO). Under certain circumstances, this requirement may apply irrespective of the number of employees. The appointed DPO must be duly notified to the competent supervisory authority.
An internal DPO must not have any conflict of interest with their regular role within the organisation. This generally means that members of senior management, heads of IT, marketing or sales, or individuals in comparable roles should not be appointed as DPO where their responsibilities would conflict with the independent performance of the DPO’s duties. An employee appointed as an internal DPO also benefits from special protection against dismissal under German law.
Companies may also appoint an external Data Protection Officer. Based on a service agreement, this approach generally provides greater flexibility and can be more cost-effective for many small and medium-sized enterprises (SMEs).