Down­loads

All down­loads are of an infor­ma­ti­ve natu­re. We do not accept any lia­bi­li­ty for them.

Check­lists & guidelines

On the imple­men­ta­ti­on of data pro­tec­tion law by com­pa­nies you will find ins­truc­tions here. You can down­load check­lists and a gui­de as a PDF here:

for SMEs
for lar­ger companies

Data pro­tec­tion impact assessment

A tem­p­la­te for data pro­tec­tion impact assess­ments (inclu­ding a thres­hold analysis).

The DSFA is Struc­tu­red accor­ding to pro­ce­s­sing prin­ci­ples – This makes it easier to fill out, but abo­ve all it cor­re­sponds to the pur­po­se of the FADP: In the case of pri­va­te com­pa­nies, it is the pro­ce­s­sing prin­ci­ples that pro­tect the data sub­jects, which is why risks must be mea­su­red against the­se principles. 

With regard to the risks, a distinc­tion must be made bet­ween the hig­hest risks that can gene­ral­ly be expec­ted (= Gross risks(taking into account mea­su­res that are not plan­ned any­way, i.e. mea­su­res that are firm­ly plan­ned) and the Net risksi.e. the pos­si­bly lower risks that the con­trol­ler is wil­ling to accept after fur­ther mea­su­res. This exami­na­ti­on and the con­clu­si­on from gross to net risk is the actu­al core of the DPIA, which is why our tem­p­la­te distin­gu­is­hes bet­ween the­se two risk levels: 

Ger­man form (as at 15.10.2024)
Form Eng­lish (as of 27.9.2023)

A Chat­bot for a DSFA is at our prompts available. The VUD has also published a tem­p­la­te for a DPIA:

Pro­ce­s­sing direc­to­ry and regulations

Pro­ce­s­sing direc­to­ry – simp­le tem­p­la­te for a respon­si­ble per­son and order pro­ces­sor (Excel, in German)

Form for pro­ce­s­sing regu­la­ti­ons (by Sarah Bischof, Maria Wink­ler, David Rosen­thal and David Vasella)

Deal­ing with requests for information

Buil­ding blocks Answer

Buil­ding blocks for a respon­se to requests for infor­ma­ti­on under the DPA (as at 21.11.2024)

Pro­ce­du­re for requests for infor­ma­ti­on (flow­chart)

Pri­va­cy statements

The­se tem­pla­tes ori­gi­na­te from DSATa set of forms that allo­ws a struc­tu­red self-assess­ment of a company’s data pro­tec­tion com­pli­ance. DSAT was deve­lo­ped by David Rosen­thal and is tech­ni­cal­ly super­vi­sed by him and David Vasella.