Foundation

    IT Governance and Compliance

    By Redaktion techport.ai, IT-Beratung · Last updated on

    Ten years ago IT law was a topic for the legal department in mid-sized companies, if there was one. Today it decides whether you may deliver, whether you win contracts and whether management is personally liable. The obligations come from different directions and with their own deadlines: data protection, cyber security, artificial intelligence, invoicing, accessibility, retention.

    We do not provide legal advice. We make sure you know what applies to you, that the technology can do it, and that you hold evidence rather than statements of intent when an audit comes.

    Typical problems

    • Nobody has an overview of which obligations affect the company and who owns them.
    • The record of processing activities was written in 2018 and never touched since.
    • AI tools are in use without anyone having classified or approved them.
    • Licence contracts renew automatically and evidence is missing at the next vendor audit.
    • The obligation to receive electronic invoices applies but the system can only partly do it.

    What we do in this field

    We build an overview of the IT related obligations with owners, deadlines and evidence. We implement data protection requirements technically, from permissions through deletion concepts to processor agreements. We classify your AI applications under the AI Act and set up an approval process. We bring licences and contracts into a register that knows notice periods and usage rights. And we make sure that e-invoicing and digital accessibility are delivered on time.

    Topics in this field

    Häufige Fragen

    Do you replace our data protection officer or our lawyers?

    No. We work with your advisers and translate their requirements into technology, processes and evidence. In the other direction we raise questions that get lost in daily work, for example third country transfers created by a new cloud service, or log data for which nobody ever set a retention period.

    How much documentation is enough?

    Enough that a competent third party can follow what you do and why. For most mid-sized companies that means a policy, an overview of systems and data, a record of processing activities, an access concept and evidence of the measures carried out. Anything beyond that needs a concrete reason.

    Let us talk about your situation

    In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.