Step 1: Understanding
We determine whether there is a legal obligation to appoint a data protection officer, which processing activities and systems fall within the scope, and which industry-specific requirements—such as those in the healthcare, financial, or education sectors—must be taken into account. In doing so, we also clarify whether we should take over an ongoing mandate or establish a new data protection framework.