NIS2: what affects mid-size companies — duties and deadlines
The revised network and information security directive: who is in scope, how supply chains pull in smaller firms and what can be prepared before transposition.
The revised network and information security directive: who is in scope, how supply chains pull in smaller firms and what can be prepared before transposition.
When the works council has a say on time recording, vehicle tracking and reporting, why mere suitability is enough, and what belongs in a works agreement.
Data protection in a digitisation project: the record of processing, a legal basis per operation, processor contracts, access rights, deletion and measures.
Monthly report still assembled by hand? How to replace it: fixed data sources, agreed metric definitions, a scheduled run and a controlled distribution.
Five metrics that genuinely steer a mid-sized company: lead time, on-time delivery, rework, utilisation, open receivables — source, refresh cycle and limits.
Retention duties and deletion duties only appear to conflict. How to build a filing concept with periods per record type, legal holds and documented runs.
Immutability, traceability, machine analysability: what the German GoBD mean for digital document storage and what belongs in the process documentation.
Text recognition realistically assessed: clean sources versus carbon copies, stamps and handwriting, measuring quality, fields to extract, effort per type.
From a folder of PDF files to a searchable archive: indexing, linking to the case, versions, access rights, retention and how to handle the existing backlog.