Our wiki on compliance, data protection and information security

Find out about the most important basic terms and introductory topics in compliance, data protection and information security. You can find white papers and videos on many of our topics directly in the wiki articles.

Robin Data stands for highest
quality and safety standards
and is TÜV certified.

Introduction

Topics around compliance, data protection and information security for beginners as well as explanation of basic terms.

NIS2: EU directive for more cyber security

What does the NIS-2 Directive mean for organisations in Germany? Implementation obligations, sanctions, tips for implementation.

Manage audits efficiently

Understanding and implementing audit management: Step-by-step explanation, background information, examples and definitions. Read now!

Asset management: Practical implementation

Efficient asset management: structure, implementation, example for classes and categories, protection needs assessment. Read now!

Environmental management according to ISO 14001

Environmental management according to ISO 14001: structure, implementation, example of measures and requirements Environmental management system. Read now!

Occupational health and safety management according to ISO 45001

The occupational health and safety management system according to ISO 45001: structure, implementation, high level structure and information. Read now!

All information on quality management

The most important things about quality management: tasks, norms and standards, and setting up a quality management system.

Risk management in the company

The most important facts about risk management: definitions, instruments, norms and standards and the structure of a risk management system.

Compliance management in the company

The most important information on compliance management: corporate obligations, norms and standards, and setting up a compliance management system.

ISMS: definition, implementation, standards

All information on the information security management system: delimitation of DPMS, notes on implementation, norms and standards

Pseudonymised data

Find out what pseudonomised data is according to GDPR and what you have to observe in terms of data protection law.

Personal data

What are personal data in data protection? What must be observed when processing in accordance with GDPR?

Data protection supervisory authority

Tasks, powers and responsibilities of data protection supervisory authorities. In Europe and in Germany per federal state

Protection of information and data

What is information security? Tasks of the information security officer and differentiation from data protection.

Informational self-determination

The right to informational self-determination has increasing importance in the digital age and is directly related to data protection and the GDPR.

Data protection

Data protection is generally the protection of personal data of each individual against their unauthorised collection, processing and disclosure.

Data processing

All information on the legal situation and forms of data processing. Learn about lawful processing of personal data.

Anonymised data

What is anonymous data? Difference pseudonymised data ✔ Relevance for data protection and GDPR.

The new Federal Data Protection Act

All information on the Federal Data Protection Act (BDSG-neu) and the differences to the General Data Protection Regulation (DSGVO).

Data Protection Breaches

When is an incident reportable? How can the risk be reduced? How to report data breaches correctly in accordance with the GDPR.

General Data Protection Regulation EU-GDPR

Content and application of the EU Data Protection Regulation: Basic principles, data subject rights, obligations for companies.

Tasks

Tasks related to compliance, data protection and information security.

activity report according to GDPR

Templates, whitepapers and implementation of the activity report according to the GDPR. Create the activity report automatically in just a few steps.

Erasure concept according to the GDPR

Samples, templates and examples for your GDPR erasure concept according to DIN 66398. Automatically create the erasure concept.

Record of processing activities

List of processing activities according to Art. 30 GDPR. Explained step by step with extensive information. Data protection made easy.

Technical organisational measures (TOMs)

All information on the technical organisational measures according to the GDPR. What do responsible parties have to observe during implementation and documentation?

Create a GDPR-compliant data processing agreement

All information on the data processing agreement according to GDPR. What do controllers have to consider when creating and managing?

Microsoft 365: GDPR-compliant use in the company

Can Microsoft Office 365 be used in compliance with the GDPR? We show how the configuration complies with data protection.

data protection impact assessment

Detailed description of the data protection impact assessment pursuant to Article 35 of the GDPR as well as specifications for the practical implementation of the DPIA.

Duty of information of the GDPR

Find out how you fulfil your information obligations and which nine specific points you must observe.

Documentation requirements of the GDPR

Documentation requirements of the DSGVO: Every company must document data protection measures. But what exactly must be documented?

Data subjects' rights in the General Data Protection Regulation

The DSGVO strengthens the rights of those affected. What should companies consider? How should opening requests be handled? Inform now and avoid fines!

Data protection and anonymisation procedures

Anonymisation and data protection: Find out which procedures exist and what has to be observed.

Controllers for processing according to GDPR

The role of the person responsible is precisely defined in the DSGVO. Find out in the article which tasks and duties the responsible person has.

Practical data security measures for more data protection

In addition to the measures described in the DSGVO, the article answers fundamental questions about technical security measures for more data protection.

Data Protection Officer

When do companies have to appoint a data protection officer? Learn about the tasks and position of a data protection officer.

Special topics

Special topics in the area of compliance, data protection and information security for external representatives Experts.

The EU-U.S. Data Privacy Framework

On 10 July 2023, the EU-U.S. Data Privacy Framework entered into force. All background information on the adequacy decision.

The Supply Chain Act (LkSG)

The Supply Chain Act (LkSG) came into force on 01.01.2023. Learn about the current regulations and obligations for companies in the article.
IT security incident

What to do in the event of an IT security incident?

The most important facts about IT security incidents. Learn practical tips on recognising and dealing with IT emergencies in the article.

What is the TTDSG or TDDDG?

The TTDSG became the Telecommunications Digital Services Data Protection Act (TDDDG) on 13 May 2024 as a result of the harmonisation with the EU Directive.

The new EU standard contract clauses

On 07 June 2021, the European Commission published the new version of the EU Standard Contractual Clauses for the international transfer of personal data.

Passwordless authentication via FIDO2

What does passwordless authentication via FIDO2 mean? Why the password is obsolete and you should rely on the security standard!

Data protection of children on the Internet

Information by parents and concrete rules on media use are useful. How can the use of digital media be taught?

The ePrivacy Regulation

The e-Privacy Regulation is controversial. Economic interests are opposed to data protection. Learn how your company has to prepare.

Privacy by Design

The technical conception and development of IT systems in conformity with data protection regulations has consequences for data protection and advantages for companies.

Data protection in the energy and environment sector

Companies in the energy and environmental sector have to comply with extensive documentation and accountability obligations as well as measures for order processing and data transfer.

Data transmission to countries outside the European Union (third countries)

When personal data are transferred to third countries, the lawfulness of this transfer must be examined and possibly regulated by contract.

Data protection in marketing

Data protection and marketing, marketing lives on data and is becoming more and more personalized, in addition, personal data is increasingly processed. In addition, there are new court rulings that directly affect marketing activities, we give an overview of data protection measures for the most important marketing areas.

Data protection in the craft sector

Data protection also applies in craft enterprises, regardless of the size of the enterprise. Find out what you need to consider and what solutions are available.

How to use the EU-US Privacy Shield

The Privacy Shield regulates the data protection compliant transfer of personal data to the United States of America (U.S.).
© Copyright - Robin Data GmbH
en_GB