Last updated: Juni 2026
AGIDAT Trust Center
Transparency about our security measures, certifications and data protection practices — because as a data protection law firm, we practice what we recommend.
Certifications & Qualifications
Certified Data Protection Officer
Dekra · since 2017
ISO/IEC 27001 Expertise
Continuing Education & Practice · since 2013
Certified Data Protection Officer
University of Applied Sciences · since 2009
Certified Project Manager
since 1995
Technical & Organizational Measures
AGIDAT implements the measures we recommend to our clients. The full TOM documentation is available on request.
Access Control
- Role-based access rights (RBAC)
- Strong password policies & 2FA
- Access logging
- Principle of least privilege
Data Encryption
- TLS 1.3 for all data transfers
- Encryption of sensitive data at rest
- Secure email transmission (STARTTLS)
- Encrypted endpoint devices
Operational Security
- Regular security updates
- Automated backups (daily, encrypted)
- Endpoint protection & antivirus
- Monitored system integrity
Organizational Measures
- Documented data protection & security policies
- Annual employee training
- Signed data protection confidentiality undertakings
- Incident response plan (24-hour escalation chain)
Vendor Management
- DPA with every processor
- Annual vendor review
- Third-country transfer documentation (SCC)
- Up-to-date sub-processor register
Physical Security
- Access-controlled office entry
- Screen lock & clean-desk policy
- Secure paper shredding (DIN 66399)
- No public Wi-Fi for client data
How AGIDAT Handles Your Data
Purpose Limitation
Client data is used exclusively for the agreed advisory purpose. No disclosure to third parties without an explicit legal basis.
Data Minimization & Deletion Concept
We collect only what is strictly necessary to deliver our services. Once an engagement ends, data is systematically deleted according to a documented deletion concept.
Confidentiality
All staff are contractually bound to data protection. Client data is transmitted encrypted and processed exclusively on EU servers.
Data Location: Germany & the EU
We use exclusively providers with data centers in Germany or the EU. Third-country transfers (e.g. Microsoft USA) are safeguarded and documented via SCCs.
24-Hour Breach Notification
In the event of a data breach, we inform you within 24 hours — well ahead of the statutory 72-hour reporting deadline under Art. 33 GDPR.
Full Transparency on Request
You can request information at any time about the personal data AGIDAT holds about you (Art. 15 GDPR). We respond to requests within 72 hours.
Sub-Processors
Full sub-processor list on request
The list of all AGIDAT processors is available to clients and prospects on request. You will receive it by email within 48 hours.
Request accessDocument Center
Public documents are directly accessible. Internal documents are provided after a brief identification step.
Client Data Protection Information
On requestInformation sheet on data processing within the advisory relationship
Request accessSample DPA
On requestData processing agreement for clients engaging AGIDAT as a processor
Request accessTOM Documentation
On requestFull technical and organizational measures under Art. 32 GDPR
Request access