GDPR & Data Protection
Records of processing activities (ROPA), data processing agreements (DPA), technical and organisational measures (TOM) under Article 32, DPIA, cookie banner, Schrems II, data breach notification — the GDPR practice track for DACH SMEs.
The most important GDPR topics in detail
Step-by-step guides with templates, regulatory references and audit checklists.
Create records of processing activities 2026
Excel template + 14 SME examples + 9 mandatory fields
DPA template 2026 (Article 28 GDPR)
Model contract + 8 mandatory contents + Schrems II annex
TOM under Article 32: 8-area checklist
60-measure catalogue · State of the art 2026
Cookie banner Section 25 TDDDG
Equal-Choice + 12-point audit
Schrems II + DPF update 2026
Trump executive order + 12 EU alternatives
Data breach notification 72h
Articles 33/34 GDPR step by step
GDPR fining procedure: 8 steps
From incoming complaint to court action
When is a DPO required?
Section 38 BDSG + cost comparison internal vs. external
Listicles & top lists
Compact overviews — perfect for board meetings, newsletters or as an A4 print template.
Practice clusters & glossary
Special topics by industry, use case and mandatory terminology.
Audit-ready in 2-4 hours
Instead of months of research: deployable templates, personalised with your company name, one-off investment instead of consultancy fees.
View GDPR Kit →Sources
- Regulation (EU) 2016/679 (GDPR) — English full text, EUR-Lex (as of 27 April 2016, in force since 25 May 2018)
- German Federal Data Protection Act (BDSG) — gesetze-im-internet.de (ongoing, German Federal Ministry of Justice service)
- European Commission — Data Protection main page (ongoing)
- European Commission — Digital Omnibus press release (as of 19 November 2025, trilogue ongoing)