AGIDAT – Datenschutz | Informationssicherheit

Last updated: Juni 2026

AGIDAT Trust Center

Transparency about our security measures, certifications and data protection practices — because as a data protection law firm, we practice what we recommend.

Certifications & Qualifications

Active

Certified Data Protection Officer

Dekra · since 2017

Active

ISO/IEC 27001 Expertise

Continuing Education & Practice · since 2013

Active

Certified Data Protection Officer

University of Applied Sciences · since 2009

Active

Certified Project Manager

since 1995

Technical & Organizational Measures

AGIDAT implements the measures we recommend to our clients. The full TOM documentation is available on request.

Access Control

  • Role-based access rights (RBAC)
  • Strong password policies & 2FA
  • Access logging
  • Principle of least privilege

Data Encryption

  • TLS 1.3 for all data transfers
  • Encryption of sensitive data at rest
  • Secure email transmission (STARTTLS)
  • Encrypted endpoint devices

Operational Security

  • Regular security updates
  • Automated backups (daily, encrypted)
  • Endpoint protection & antivirus
  • Monitored system integrity

Organizational Measures

  • Documented data protection & security policies
  • Annual employee training
  • Signed data protection confidentiality undertakings
  • Incident response plan (24-hour escalation chain)

Vendor Management

  • DPA with every processor
  • Annual vendor review
  • Third-country transfer documentation (SCC)
  • Up-to-date sub-processor register

Physical Security

  • Access-controlled office entry
  • Screen lock & clean-desk policy
  • Secure paper shredding (DIN 66399)
  • No public Wi-Fi for client data
Full TOM documentation on request → Go to the document center

How AGIDAT Handles Your Data

Purpose Limitation

Client data is used exclusively for the agreed advisory purpose. No disclosure to third parties without an explicit legal basis.

Data Minimization & Deletion Concept

We collect only what is strictly necessary to deliver our services. Once an engagement ends, data is systematically deleted according to a documented deletion concept.

Confidentiality

All staff are contractually bound to data protection. Client data is transmitted encrypted and processed exclusively on EU servers.

Data Location: Germany & the EU

We use exclusively providers with data centers in Germany or the EU. Third-country transfers (e.g. Microsoft USA) are safeguarded and documented via SCCs.

24-Hour Breach Notification

In the event of a data breach, we inform you within 24 hours — well ahead of the statutory 72-hour reporting deadline under Art. 33 GDPR.

Full Transparency on Request

You can request information at any time about the personal data AGIDAT holds about you (Art. 15 GDPR). We respond to requests within 72 hours.

Sub-Processors

Full sub-processor list on request

The list of all AGIDAT processors is available to clients and prospects on request. You will receive it by email within 48 hours.

Request access

Document Center

Public documents are directly accessible. Internal documents are provided after a brief identification step.

Privacy Policy

Public

Information on data processing under Art. 13/14 GDPR

View

Imprint

Public

Mandatory disclosures under § 5 DDG

View

Client Data Protection Information

On request

Information sheet on data processing within the advisory relationship

Request access

Sub-Processor List

On request

Complete list of all AGIDAT processors

Request access

Sample DPA

On request

Data processing agreement for clients engaging AGIDAT as a processor

Request access

TOM Documentation

On request

Full technical and organizational measures under Art. 32 GDPR

Request access

Information Security Policy

On request

AGIDAT's internal information security policy

Request access

Security or data protection questions?

Contact our Data Protection Officer directly:

dsb@agidat.de