Skip to main content
Success Story

I audit management systems for a living – I chose my own by the same criteria

How Tobias Hess manages a client portfolio with preeco | data protection as an external data protection officer and auditor – a workload other organizations staff entire teams for

Most user stories follow the same pattern: someone had a problem and found a piece of software. With Tobias Hess, the order is reversed. He audits data protection management systems for a living – as an auditor, his job is to determine whether an organization not only meets its obligations but can also demonstrate that it does. When he went looking for a system for his own consultancy, he applied exactly those standards.

One person, several roles

Since 2020, Tobias Hess has worked under the DSGVO-Service brand as an external data protection officer, consultant, and auditor. His clients are predominantly small and medium-sized enterprises – organizations without a data protection department of their own, for which data protection is an obligation alongside day-to-day business.

In larger organizations, this work is spread across several people: one maintains the record of processing activities, a second manages the processors, a third delivers training, a fourth audits. At DSGVO-Service, all these roles converge in one person. That is a deliberate decision – the client has a single point of contact who genuinely knows their operation, instead of shifting responsibilities. But it also means the working day consists of role changes.

"In a single day, I jump between very different tasks. If every one of those switches means switching tools and reorienting myself as well, I lose exactly the time my clients are actually paying me for."

— Tobias Hess, DSGVO-Service

Where a folder structure reaches its limit

Data protection documentation can be maintained with a word processor and spreadsheets. It can even be maintained well that way – for one client. The breaking point is not creating it, but keeping it current.

With a portfolio in the range of twenty to forty mandates, it is not the documentation that multiplies but the number of states that have to be kept current in parallel: Which version applies? Who approved what, and when? Which deadline is running for which client? Where is the reply that came in by email three weeks ago? With every additional mandate, the balance of work shifts further away from advising – towards administering your own status.

"The issue was never that I couldn’t get things done. The issue was that I spent more and more time administering my own status instead of moving clients forward."

— Tobias Hess, DSGVO-Service

The selection: the same questions as in an audit

This is where the auditor’s perspective helps. Anyone whose profession is assessing whether an organization can meet its accountability obligations does not ask about a software’s feature list first. They ask about evidence:

  • Does every approval produce a traceable version – or is the previous one overwritten?

  • Can you tell whether a document was altered after the fact?

  • Is it logged who changed what, and when?

  • Can records and reports be exported per client in a form that stands up to an audit?

  • Does the permission model enforce a clean separation between clients?

  • Where is the data held, and who operates the system?

preeco | data protection answers these questions at the system level: every approval creates a technically versioned copy whose integrity can be checked against stored checksums – a value like that does not make a file immutable, but it does make any subsequent change detectable. The activity log documents changes in the system. Records of processing activities and reports can be generated per client as PDF or DOCX. A multi-level permission model separates access, and operations run in ISO 27001-certified data centers in Germany.

"I assessed the software with the questions I normally put to others. That is an uncomfortable standard. But if I don’t apply it to myself, I can hardly demand it of anyone else."

— Tobias Hess, DSGVO-Service

Everyday work: one place instead of many

What has changed since is best described as a relocation. Processing activities, technical and organizational measures, data processing agreements, data protection impact assessments, data subject requests, and deadlines all sit in one place per client instead of being scattered across drives, mailboxes, and devices. Follow-up questions happen on the document, not in an email thread that has to be reconstructed later. Reminders surface on their own instead of getting lost on a to-do list.

For clients, what changes above all is the ability to give an answer. The question “Where do we actually stand right now?” is no longer research, it is simply information. And when it gets serious – a data subject request with a deadline, a query from the supervisory authority, a customer reviewing data protection before signing a contract – the evidence is not in the consultant’s memory, it is in the system.

The objection every small consultancy knows

Anyone engaging a solo consultant sooner or later asks the same question: what happens during holidays, during illness, during a handover? It is a legitimate objection, and it cannot be dispelled with assurances – only with structure.

This is exactly where it pays off that the state of each engagement sits entirely in the system rather than in people’s heads and local folders. A stand-in finds the current status waiting for them. A successor takes over managed documentation instead of a pile of data. And in every one of these cases, the client remains able to give answers and to act.

"The fact that I work alone must not be a risk for my clients. The proof that it isn’t one is not in my proposal – it is in the system."

— Tobias Hess, DSGVO-Service

What the software does not take off your hands

Honesty requires the other direction too. A cleanly maintained system does not yet prove that an organization actually works in a data-protection-compliant way. Unreported tools, homegrown local lists, missing deletion routines, untrained staff – deviations like these arise in day-to-day work, not in the documentation.

preeco | data protection provides the tools to track them down: recurring data collection forms for self-disclosure, reminders for periodic reviews, audits and audit catalogs, training with proof of completion, mandatory approvals before publication. Assessing what surfaces remains expert work – and that is precisely the service clients engage an external data protection officer for.

"The software takes the sorting off my hands. Not the judgment."

Tobias Hess

Data Protection Officer & Auditor, DSGVO-Service

Credibility is part of the service

One sentence sits above all his work, the one Tobias Hess puts at the very top of his website: “Those who live data protection authentically create trust.” With him, that is not a slogan – the same website has dedicated sections on how he handles data himself, points out the script blocker he uses, and makes accessibility a topic.

From this follows a selection criterion that rarely appears in requirement specifications and is nonetheless decisive for a data protection consultant: whoever advises on data protection stakes their own reputation on the tools they use and ask their clients to live with. From that perspective, development and operations in Germany are not an add-on feature but a prerequisite.

Outlook

DSGVO-Service plans to expand its client portfolio further and to integrate its own training and continuing-education offering more closely into ongoing support.

Do you support clients as an external data protection officer?

In a personal meeting, we will show you preeco | data protection and your options.