Where does your compliance organisation stand today?
Which area fits your company is something we clarify in the initial conversation — non-binding and with no preparation required on your side.
Arrange a conversationData protection has been joined by whistleblower protection, the AI Regulation and rising requirements for IT security. The obligations stem from different sets of rules, concern different departments and cannot be discharged with a single tool. Some require a named person, some knowledge among staff, some well-maintained documentation, some properly built technology.
We take on functions provided for by law — with everything that belongs to them.
This area brings together three functions for which CAYADA is appointed or commissioned by the company. Appointment is the common feature: here someone takes on a role, not a task.
CAYADA takes on the function of external data protection officer under Art. 37 to 39 GDPR. This includes independent information and advice on data protection obligations, risk-oriented monitoring of the data protection organisation, advice on the data protection impact assessment and cooperation with the supervisory authority. Fixed contacts, regular coordination and traceable reports provide continuity. Responsibility for decisions and their implementation remains with the controller.
Not included are representation of the company in contentious proceedings, legal defence before authorities or courts, and legal advice outside the statutory scope of duties of the data protection officer.
We record structures, responsibilities, processes and existing records against criteria agreed in advance. Observations and organisational or technical room for improvement are documented in a prioritised action plan. The check is not a certification and, outside a DPO mandate, not a legal review of the individual case.
We facilitate the recording of processing activities, structure information on technical and organisational measures, coordinate tasks and support the documentation of data protection impact assessments and vendor processes. Decisions on the purposes and means of processing, legal bases, balancing of interests and approvals are taken by the controller — where needed after separate legal advice.
For companies without an establishment in the European Union we act as representative under Art. 27 GDPR, where the statutory conditions are met. We are the point of contact for data subjects and supervisory authorities and maintain the record of processing activities in the prescribed form.
Companies above a certain headcount must set up an internal reporting office; the law expressly permits commissioning a third party for this. CAYADA takes on that function: protected intake channel, acknowledgement and deadline tracking, confidential handling, documentation and feedback to the reporting person. The decision on follow-up measures and their implementation remains with the employer.
This service concerns operating the reporting office as a commissioned third party. The whistleblower channel in the portal is to be distinguished from it: there, you or the office you appoint operate the software yourselves.
Within a DPO mandate, the data protection impact assessment for AI-supported processing and the data protection side of AI use fall within the scope of duties. We do not carry out any classification of applicability or risk under the AI Regulation.
Your people understand what applies — and can work accordingly.
We deliver training on site, online or hybrid — tailored to the role and prior knowledge of the participants.
The AI Regulation requires companies using AI to ensure sufficient AI literacy among the staff involved. We convey what the regulation requires, which roles are affected and what responsible use looks like in everyday work — based on practical examples and tailored to the respective role.
The training is directed at conveying literacy. Whether a particular system used by a participant falls under the regulation is not the subject of the training.
In the portal you work yourselves: you record, review and approve. CAYADA provides the structure, the templates and the traceability — so that your documentation carries on between appointments.
See the portal outlookTraceability is created while building, not afterwards.
Anyone who builds a system so that accesses, changes and data flows are logged from the outset does not have to reconstruct the records later. We work on the technical side: assessment, architecture and data flows, logging, access concepts, documentation of system characteristics and privacy-oriented system integration.
Organisational and technical preparation for agreed security requirements, policies and security concepts, risk and measure management, incident response and contingency processes, and support with certification projects.
The services comprise technical assessments, security organisation and documentation support. A binding legal review of whether, and with what legal consequences, a company is covered by NIS2 or other regulatory frameworks is not part of this CAYADA service.
We support companies in taking inventory of the AI systems in use, assigning internal responsibilities and designing approval, documentation and training processes.
Which area fits your company is something we clarify in the initial conversation — non-binding and with no preparation required on your side.
Arrange a conversationCAYADA GmbH is a compliance and technology company and not a law firm. Where CAYADA is appointed as external data protection officer, the service also covers the statutory information and advisory duties within the scope of Art. 39 GDPR. Legal advice outside that scope, legal representation and other services reserved to lawyers are not provided by CAYADA. Where a matter requires handling by a lawyer, a separate mandate with an independently acting lawyer or law firm is needed; the client remains free in that choice. A mandate as data protection officer is not combined, for the same controller, either with the function of EU representative or with the technical build of the systems that would subsequently have to be monitored.