Skip to main content

Compliance Glossary

All key terms from data protection, information security, whistleblower protection and sustainability – clearly explained.

Accountability

The obligation of the controller to not only comply with all GDPR principles, but to be able to actively demonstrate that compliance — Art. 5(2) GDPR.

DS
Anonymous Reporting

A report submitted without disclosing the reporter's identity, so that neither the reporting channel nor the affected organisation can identify the

HG
Audit

A systematic, independent examination to determine whether processes and measures comply with defined requirements.

CA
BSI IT-Grundschutz

A comprehensive information security framework developed by Germany's Federal Office for Information Security (BSI) for systematic IT protection.

IS
Business Continuity Management (BCM)

A management process that ensures an organization can continue delivering critical services during and after disruptive incidents.

IS
Carbon Footprint

The total amount of greenhouse gas emissions caused directly and indirectly, often broken down into Scope 1, 2, and 3.

NH
CISIS12

A 12-step information security model designed as an accessible entry point for smaller organizations, particularly municipalities and SMEs.

IS
Compliance Management System (CMS)

A systematic approach to ensuring that an organisation adheres to legal, regulatory, and internal requirements.

CA
Consent

A freely given, specific, informed, and unambiguous indication of a data subject's wishes, as required by Art. 7 GDPR.

DS
CSRD (Corporate Sustainability Reporting Directive)

The EU directive 2022/2464 that introduces expanded sustainability reporting requirements for companies above certain thresholds.

NH
Data Breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data, reportable to

DS
Data Deletion Concept

A systematic plan for the timely deletion of personal data once the purpose for which it was collected has ceased to apply, as required by Art. 17

DS
Data Processing Agreement (DPA)

A contractual arrangement required by Art. 28 GDPR whenever a service provider processes personal data on behalf of a controller.

DS
Data Protection Compliance

The totality of measures taken to comply with data protection legal requirements, in particular the GDPR.

CA
Data Protection Impact Assessment (DPIA)

A structured risk analysis required by Art. 35 GDPR before processing activities that are likely to result in a high risk to the rights of data

DS
Data Protection Officer (DPO)

The person designated under Art. 37 GDPR to oversee data protection compliance within an organisation.

DS
Data Subject Rights

The rights of natural persons to access, rectify, erase, restrict, port, and object to the processing of their personal data under Art. 15–21 GDPR.

DS
DORA (Digital Operational Resilience Act)

EU Regulation 2022/2554 establishing ICT risk management, incident reporting, and resilience testing requirements for the financial sector.

IS
Double Materiality

The analysis of both how sustainability topics affect the company and how the company's activities affect the environment and society.

NH
ESG (Environmental, Social, Governance)

The framework for evaluating companies based on environmental, social, and governance criteria.

NH
ESRS (European Sustainability Reporting Standards)

The standards developed by EFRAG that CSRD-obligated companies must use to prepare their sustainability reports.

NH
EU Taxonomy

The EU classification system for defining environmentally sustainable economic activities.

NH
EU Whistleblower Directive

Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law, which all EU member states were required to transpose by 17

HG
German Supply Chain Due Diligence Act (LkSG)

The German law on human rights and environmental due diligence obligations in global supply chains.

NH
GRC (Governance, Risk & Compliance)

The integrated approach to managing corporate governance, risk management, and compliance adherence.

CA
GRI Standards

The world's most widely used sustainability reporting framework, developed by the Global Reporting Initiative.

NH
Internal Reporting Channel

The designated function that organisations with 50 or more employees must establish under the HinSchG to receive and handle reports of wrongdoing.

HG
ISMS (Information Security Management System)

A systematic framework of policies, processes, and controls for managing an organization's information security risks.

IS
ISO 27001

The international standard specifying requirements for establishing, implementing, maintaining, and continually improving an ISMS.

IS
Joint Controllership

Exists when two or more controllers jointly determine the purposes and means of processing personal data, as defined in Art. 26 GDPR.

DS
Multi-Tenancy

The ability of software to manage multiple legally separate organisations (tenants) within a single system with strict data separation.

CA
NIS 2 Directive

EU Directive 2022/2555 strengthening cybersecurity requirements for essential and important entities across the European Union.

IS
NIS2 Applicability Assessment

The process of determining whether an organization qualifies as an essential or important entity under the NIS 2 Directive.

IS
NIS2 Reporting Obligation

The obligation of affected entities to report significant security incidents to the competent authority within 24 hours of detection.

IS
Ombudsperson

An external, impartial trusted intermediary – often a lawyer – who serves as a confidential point of contact for whistleblowers and is bound by strict

HG
Personal Data

Any information relating to an identified or identifiable natural person, as defined in Art. 4(1) GDPR.

DS
Prohibition of Retaliation

The legal prohibition on taking adverse measures – such as dismissal or demotion – against whistleblowers as a consequence of their report.

HG
Record of Processing Activities (ROPA)

The mandatory register of all processing activities that every controller must maintain under Art. 30 GDPR.

DS
Risk Assessment

The systematic process of identifying, analyzing, and evaluating risks to an organization's information security.

IS
SaaS (Software as a Service)

A cloud-based delivery model in which software is accessed and used over the internet as a service.

CA
Scope 1 / 2 / 3 Emissions

The classification of greenhouse gas emissions into direct (Scope 1), energy-related indirect (Scope 2), and other indirect (Scope 3).

NH
Security Incident

An event that compromises or threatens the confidentiality, integrity, or availability of information or information systems.

IS
Statement of Applicability (SoA)

A mandatory ISO 27001 document that lists all Annex A controls, states which are applicable, and explains why others are excluded.

IS
Status Notification

The mandatory feedback that organisations must provide to a whistleblower within three months of acknowledging their report, informing them of any

HG
Technical and Organisational Measures (TOMs)

Security safeguards that controllers and processors must implement under Art. 32 GDPR to ensure a level of protection appropriate to the risk.

DS
Third Country Transfer

The transfer of personal data to countries outside the EEA, which requires specific safeguards under Art. 44–49 GDPR.

DS
VDA ISA / TISAX

The German automotive industry's information security assessment catalogue, audited through the TISAX scheme managed by the ENX Association.

IS
Whistleblower Protection Act (HinSchG)

The German law protecting whistleblowers, transposing EU Whistleblower Directive 2019/1937 into national law.

HG
Whistleblower System / Reporting Channel

A technical system enabling the secure and, where applicable, anonymous submission of reports about legal violations.

HG
Whistleblowing

The act of reporting misconduct, legal violations, or unethical behaviour within an organisation to a responsible authority.

HG