Customer Story City of Merseburg

"In the audit of our information security management system by Robin Data GmbH, the current maturity level of our ISMS was audited against the standard of the IT-Grundschutz. Internal and external processes and documents were reviewed and open measures were documented."

Marco Voigt, Head of IT at Merseburg Municipality

Municipal data protection and information security

The city of Merseburg is a cathedral and university city in southern Saxony-Anhalt and has around 35,000 inhabitants. The medium-sized town is the administrative seat of the Saale district and part of the cross-border conurbation of the cities of Leipzig and Halle.

Logo of the city of Merseburg

City of Merseburg

The town of Merseburg has 24 administrative locations, schools and day-care centres. The administration has 14 offices and a data processing department.

www.merseburg.de/

Location: Merseburg

User: Marco Voigt (Head of IT), City of Merseburg

Industry: Administration, public bodies

Customer: since 2020

Initial situation and goals

At the beginning of the project, the city of Merseburg was in the process of developing its data protection and information security management system.
The goal of the cooperation was and is to further develop the data protection and information security management system on the basis of ComplianceOS® and the expertise of Robin Data and to transfer it into a continuous improvement process.

audit

At the beginning of the project, an audit was conducted based on the BSI Basic Protection Profile "Municipal Administration" (as of 2019). The audit gave Robin Data's consultants a detailed insight into the organisational structure of the municipality and the ICT infrastructure. As selected representatives of the management level took part in the audit, they were also able to gain a different view of the functionality of their own IT.
Findings (deviations from the standard) and positive aspects were recorded in the audit report. Improvement measures to be taken were documented and serve as a work plan for the next project steps. QuickWins has already been used to optimise the first processes with regard to IT security and service.

Implementation of the organisation in ComplianceOS

In another workshop, the organisational structure of the city of Merseburg was included in the ComplianceOS®. The focus was particularly on the data flows within the municipality as well as with external service providers.

Analysis of the processing activities

Together with the persons in charge, the existing specialised procedures were transferred to ComplianceOS®. The aim of the transfer was to identify critical procedures and suppliers and to determine the need for a data protection impact assessment as well as to initiate risk-minimising measures. Necessary activities were documented in ComplianceOS® and their implementation tracked.

Emergency management

The existing emergency management was analysed for new risks. The results of the analysis were specified in a business continuity concept and an "emergency management" guideline. The results were documented in ComplianceOS®.

Risk and asset management

Currently, asset and risk management is being rebuilt together with regional municipalities and implemented in ComplianceOS®.

"Through the consultation and clear distribution of responsibilities, we know any weaknesses and can now actively address them."

Marco Voigt, Head of IT at Merseburg Municipality

Project partner

Merseburg Municipality

Marco Voigt
+49 (0) 3461 445 120
adv@merseburg.de

Robin Data GmbH
Prof. Dr. Andre Döring
+49 (0) 3461 479236-0
info@robin-data.io

About Robin Data

Robin Data GmbH is a leading legal tech start-up for the digital management of compliance processes and their automation (compliance automation) in complex and regulated organisations.

For this purpose, customers of Robin Data GmbH use the highly secure, self-developed and data protection-compliant software-as-a-service platform "ComplianceOS" (Compliance Operating System).

TÜV seal of quality management system ISO 9001 of Robin Data GmbH
Certification of Robin Data GmbH according to DIN EN ISO/IEC 27001:2017
Robin Data is supported by financial assistance from the European Regional Development Fund (ERDF)

The easy and digital implementation of your data protection documentation starts here.



Record of processing activities



data protection impact assessment



Erasure concept

© Copyright - Robin Data GmbH
en_GB