Skip to content

Law, security & funding

Digitised workflows touch obligations that used to be handled on paper. This category sets out what applies: retention periods and process documentation under German accounting principles, data protection for staff and customer data, works council codetermination for systems capable of recording behaviour or performance, and the IT security requirements that reach smaller companies through supply chains. It also covers funding options for digitisation projects and what paperwork an application requires. Written factually and without offering legal advice — assessing a specific case remains a matter for a lawyer.

Packaging reporting driven by the item master

Which field is missing on the item, how packaging weights per variant and shipping carton are maintained, and how delivery note quantities become a defensible reported tonnage per material type.

16 min read

Handling access requests: deadline, scope, data sources

An access request starts a one-month deadline: what the response has to cover, where the data actually sits and what should remain provable afterwards.

18 min read

Electronic signatures: which form is legally valid

Written form, electronic form, text form: which signature level satisfies which statutory form, and where the law keeps the electronic form excluded.

18 min read

Preparing the stocktake: choosing a method that fits

Four methods, one inventory: how far the counting day may sit from the closing date, which deadlines apply and which data work has to happen first.

17 min read

Data Act: using machine data from September 2026

From 12 September 2026 new connected products must release operating data by default. Which deadlines apply, who is exempt and what to prepare now.

17 min read

Cyber Resilience Act: a reporting process in 24 hours

From 11 September 2026 the reporting duty in Article 14 applies. Who reports to whom, what happens in the first 24 hours and which records remain at the end.

16 min read

Account Access When Staff Join and Leave the Company

How access is ready on the first working day and reliably ends after someone leaves: taking stock, roles, a trigger from the HR system, annual review.

13 min read

Own server or data centre: making the decision soberly

Cost over five years, availability, responsibility during incidents, data protection and getting data back — how mid-sized firms decide where their servers run.

14 min read

Writing process documentation for tax audits

Process documentation under the German GoBD rules: the four required parts, how detailed it must be, how to keep it current and what its absence can mean.

14 min read

Backups that hold up: copies, distance and a proven way back

Several copies, one off site, one without a permanent connection: how firms set recovery time and tolerable data loss, and how to test restores for real.

14 min read

Interface security: accounts, keys and permissions

Sign-in, key handling, encryption in transit, minimal permissions, separate test accounts and key rotation: what to settle for every interface you run.

14 min read

Digitisation funding: types, paperwork and sequence

Grants, subsidised loans, consulting subsidies: what German funding covers, which documents an application needs and why it must precede any binding order.

14 min read

NIS2: what affects mid-size companies — duties and deadlines

The revised network and information security directive: who is in scope, how supply chains pull in smaller firms and what can be prepared before transposition.

15 min read

Works council codetermination in IT projects

When the works council has a say on time recording, vehicle tracking and reporting, why mere suitability is enough, and what belongs in a works agreement.

14 min read

Data protection when digitising processes: in practice

Data protection in a digitisation project: the record of processing, a legal basis per operation, processor contracts, access rights, deletion and measures.

14 min read