Services

One obligation has become many.

Data protection has been joined by whistleblower protection, the AI Regulation and rising requirements for IT security. The obligations stem from different sets of rules, concern different departments and cannot be discharged with a single tool. Some require a named person, some knowledge among staff, some well-maintained documentation, some properly built technology.

Area 01

Appointed functions

We take on functions provided for by law — with everything that belongs to them.

This area brings together three functions for which CAYADA is appointed or commissioned by the company. Appointment is the common feature: here someone takes on a role, not a task.

External data protection officer

Art. 37 to 39 GDPR

CAYADA takes on the function of external data protection officer under Art. 37 to 39 GDPR. This includes independent information and advice on data protection obligations, risk-oriented monitoring of the data protection organisation, advice on the data protection impact assessment and cooperation with the supervisory authority. Fixed contacts, regular coordination and traceable reports provide continuity. Responsibility for decisions and their implementation remains with the controller.

Scope of services

Not included are representation of the company in contentious proceedings, legal defence before authorities or courts, and legal advice outside the statutory scope of duties of the data protection officer.

Data protection organisation check

Assessment

We record structures, responsibilities, processes and existing records against criteria agreed in advance. Observations and organisational or technical room for improvement are documented in a prioritised action plan. The check is not a certification and, outside a DPO mandate, not a legal review of the individual case.

Data protection organisation

Ongoing support

We facilitate the recording of processing activities, structure information on technical and organisational measures, coordinate tasks and support the documentation of data protection impact assessments and vendor processes. Decisions on the purposes and means of processing, legal bases, balancing of interests and approvals are taken by the controller — where needed after separate legal advice.

EU representative

Art. 27 GDPR

For companies without an establishment in the European Union we act as representative under Art. 27 GDPR, where the statutory conditions are met. We are the point of contact for data subjects and supervisory authorities and maintain the record of processing activities in the prescribed form.

Internal reporting office as commissioned third party

Operated function

Companies above a certain headcount must set up an internal reporting office; the law expressly permits commissioning a third party for this. CAYADA takes on that function: protected intake channel, acknowledgement and deadline tracking, confidential handling, documentation and feedback to the reporting person. The decision on follow-up measures and their implementation remains with the employer.

Scope of services

This service concerns operating the reporting office as a commissioned third party. The whistleblower channel in the portal is to be distinguished from it: there, you or the office you appoint operate the software yourselves.

AI Regulation

Within a DPO mandate, the data protection impact assessment for AI-supported processing and the data protection side of AI use fall within the scope of duties. We do not carry out any classification of applicability or risk under the AI Regulation.

Area 02

Training

Your people understand what applies — and can work accordingly.

We deliver training on site, online or hybrid — tailored to the role and prior knowledge of the participants.

  • Fundamentals for employees
  • Workshops for management and senior staff
  • Data protection for specialist departments
  • AI literacy and responsible use of AI
  • Specialist topics for HR, IT and security
AI Regulation

AI literacy among staff

The AI Regulation requires companies using AI to ensure sufficient AI literacy among the staff involved. We convey what the regulation requires, which roles are affected and what responsible use looks like in everyday work — based on practical examples and tailored to the respective role.

The training is directed at conveying literacy. Whether a particular system used by a participant falls under the regulation is not the subject of the training.

Area 03 · From October 2026

CAYADA compliance portal

In the portal you work yourselves: you record, review and approve. CAYADA provides the structure, the templates and the traceability — so that your documentation carries on between appointments.

See the portal outlook
Area 04

Building AI systems properly

Traceability is created while building, not afterwards.

Anyone who builds a system so that accesses, changes and data flows are logged from the outset does not have to reconstruct the records later. We work on the technical side: assessment, architecture and data flows, logging, access concepts, documentation of system characteristics and privacy-oriented system integration.

Security organisation

Work service

Organisational and technical preparation for agreed security requirements, policies and security concepts, risk and measure management, incident response and contingency processes, and support with certification projects.

Scope of services

The services comprise technical assessments, security organisation and documentation support. A binding legal review of whether, and with what legal consequences, a company is covered by NIS2 or other regulatory frameworks is not part of this CAYADA service.

AI governance and organisational compliance management

Organisation and documentation

We support companies in taking inventory of the AI systems in use, assigning internal responsibilities and designing approval, documentation and training processes.

  • AI inventory and structured system records
  • internal roles and responsibilities
  • organisational approval and documentation workflows
  • working templates for internal guardrails
  • training and literacy concepts
  • risk and measure register as a documentation tool

Where does your compliance organisation stand today?

Which area fits your company is something we clarify in the initial conversation — non-binding and with no preparation required on your side.

Arrange a conversation

CAYADA GmbH is a compliance and technology company and not a law firm. Where CAYADA is appointed as external data protection officer, the service also covers the statutory information and advisory duties within the scope of Art. 39 GDPR. Legal advice outside that scope, legal representation and other services reserved to lawyers are not provided by CAYADA. Where a matter requires handling by a lawyer, a separate mandate with an independently acting lawyer or law firm is needed; the client remains free in that choice. A mandate as data protection officer is not combined, for the same controller, either with the function of EU representative or with the technical build of the systems that would subsequently have to be monitored.