Compliance software · Germany

DSGVO and GRC compliance software for the German Mittelstand

German SMEs face the DSGVO and BDSG, a NIS2 implementation that reaches far more companies than before, customers who ask for ISO 27001 or TISAX, and a whistleblower act for every employer with 50 staff. AI Pazz Govnex runs all of it in one workspace — with data kept in Germany on Dedicated Hosting.

In short

German organisations must follow the GDPR (DSGVO) and the Federal Data Protection Act (BDSG), which requires a Data Protection Officer once at least 20 people regularly process personal data automatically. NIS2 widens cyber security duties to many medium-sized firms, and employers with 50 or more staff need an internal whistleblowing channel. Govnex holds the GDPR, ISO 27001 and ISO 37002 as ready-made control sets.

Reviewed . A plain-language guide, not legal advice — check the regulator's site for the current position.

The laws and rules that apply in Germany

What each asks of a business, who it applies to, what happens if you fall short — and whether Govnex holds it as a ready-made control set.

DSGVO / BDSG

GDPR (DSGVO) and the Federal Data Protection Act (BDSG)

Ready-made in the Govnex Library
Regulator
The data protection authority of each federal state, and the Federal Commissioner (BfDI)
Who it applies to
Every organisation in Germany that processes personal data.
If you fall short
Up to €20 million or 4% of annual worldwide turnover, whichever is higher.
What it asks of you
  • A record of processing activities (Verzeichnis von Verarbeitungstätigkeiten) and a lawful basis for each
  • A Data Protection Officer (Datenschutzbeauftragter) once at least 20 people regularly process personal data automatically — or whatever the size, where a DPIA is required
  • Technical and organisational measures (TOMs) and DPIAs for high-risk processing
  • Report a data breach to the authority within 72 hours

Source: bfdi.bund.de

NIS2

NIS2 implementation (NIS2UmsuCG) and the BSI Act

Track it with your own controls
Regulator
Federal Office for Information Security (BSI)
Who it applies to
Medium and large essential and important entities in the sectors NIS2 lists — many thousands of German companies, far more than the earlier KRITIS rules.
If you fall short
Up to €10 million or 2% of worldwide turnover for essential entities.
What it asks of you
  • Risk management measures, with management responsible and trained
  • Registration with the BSI
  • Early warning of a significant incident within 24 hours, notification within 72 hours and a final report within a month

Source: bsi.bund.de

HinSchG

Whistleblower Protection Act (Hinweisgeberschutzgesetz, HinSchG)

Ready-made in the Govnex Library
Regulator
Federal Office of Justice (external reporting channel)
Who it applies to
Employers with 50 or more employees.
If you fall short
Fines of up to €50,000 for obstructing reports or reprisals.
What it asks of you
  • An internal reporting channel, acknowledged within seven days
  • Feedback to the whistleblower within three months
  • Protection from reprisal and confidentiality of identity

Source: bundesjustizamt.de

EU AI Act

EU Artificial Intelligence Act

Ready-made in the Govnex Library
Regulator
Federal Network Agency (Bundesnetzagentur) and other market surveillance authorities
Who it applies to
Providers and deployers of AI systems, with obligations phasing in from 2025.
If you fall short
Up to €35 million or 7% of worldwide turnover for prohibited practices.
What it asks of you
  • No prohibited practices, AI literacy, and risk management and oversight for high-risk systems

Source: EUR-Lex

Standards Germany buyers ask for

How AI Pazz Govnex helps in Germany

What you needHow Govnex does itModule
Verzeichnis von VerarbeitungstätigkeitenEvery processing activity with data, owners, lawful basis, recipients and TOMs, with a checklist per activity.
DSGVO, ISO 27001 and TISAX controlsAdopt the GDPR and ISO 27001 control sets, add TISAX specifics, assign owners and collect evidence.
NIS2 risk managementCyber risks in a register with treatments, owners and management approval.
Whistleblowing reportsEach report an issue with confidential owners, the seven-day and three-month deadlines, and its outcome.
Internal audits before certificationPlan and run internal audits with workpapers, findings and corrective actions.

Your first 90 days

  1. 1Build your record of processing activities and check whether you need a Datenschutzbeauftragter.
  2. 2Adopt the GDPR and ISO 27001 control sets and assign owners.
  3. 3Check whether NIS2 applies to your sector and size, and register with the BSI if so.
  4. 4Set up your internal whistleblowing channel if you employ 50 or more people.
  5. 5Audit internally, close findings and report to management.

Start with what applies to you

Adopt the control sets that fit, add your own for the rest, and give every control an owner. The first months are free.

Start free

Compliance in Germany: questions and answers

When does a German company need a Datenschutzbeauftragter?
Under the BDSG, once at least 20 people are regularly engaged in the automated processing of personal data — or regardless of size, where processing requires a data protection impact assessment or personal data is processed commercially for transfer or research.
Does NIS2 apply to the Mittelstand?
Yes, much more than KRITIS did: medium-sized companies (50 or more employees, or over €10 million turnover) in the listed sectors can be important entities, with registration, risk management and incident reporting duties.
What does the Hinweisgeberschutzgesetz require?
Employers with 50 or more employees must run an internal reporting channel, acknowledge reports within seven days and give feedback within three months, while protecting the whistleblower from reprisal.
Can our data stay in Germany?
Yes. Dedicated Hosting runs your own deployment with data and files stored in the Azure region you choose, including Germany.
Does Govnex support TISAX?
TISAX builds on ISO 27001, a ready-made control set in Govnex; add the VDA ISA specifics as your own controls and track them the same way.
What else does Govnex include?
Policies, risk registers, issues, internal audits, regulatory change, a data register and ESG & EHS — for supply chain and sustainability duties too.

Modules Germany teams start with

Small business and up

Data protection compliance software

Data Compliance Tracker

What you hold data about and what you do with it: entities and their records with a business owner and a data owner for each, and Records of Processing Activities with a compliance checklist answered item by item.

  • Entities — Customer, Employee, Supplier — each with a business owner and a data owner
  • A RoPA for each activity: its purpose, its owners, and the records it processes — what they hold read beside it
More about Data Compliance Tracker
Every plan

Compliance management software

Compliance and Control Tracker

Track recurring compliance obligations, assign owners and record the evidence, cycle by cycle.

  • Adopt controls from the Compliance Library — ISO 27001, SOC 2, GDPR, Sri Lanka PDPA and more — as your own editable copies
  • Cycles and assessments whose scope is fixed the moment they open
  • Coverage and maturity scoring, withheld below a coverage floor you set
More about Compliance and Control Tracker
Small business and up

Internal audit management software

Audit Management

Run internal audit programmes: the scopes audited in each, tests with their samples, findings answered by management, issued reports, and every finding handed over to Issue & Remediation for tracking.

  • The year's audits in one plan, approved by an audit lead — anything added afterwards is marked unplanned until the plan is approved again
  • A work programme generated from the controls you track for the standards in scope — with each control's latest recorded verdict and evidence beside the auditor's own conclusion, never written back
  • Findings written as condition, criteria, cause, effect and recommendation, rated on your own scale, with a link to the earlier finding they repeat
More about Audit Management