
BDSG Experts in Germany
for compliant data processing, matched fast with vetted freelancersHire experts who interpret the Bundesdatenschutzgesetz, design privacy processes and align BDSG requirements with GDPR controls. Work with vetted, available freelancers matched precisely to your project and ready to collaborate remotely or on site in Germany.
Meet FRATCH Experts in Germany, who have recently used BDSG
Peter D.
Last position:
Security Consultant at Public-law institution of the city administration
- Requirements management, process planning, interface function, ISMS setup, and documentation
- Setup and establishment of an ISMS according to ISO 27001 and establishment of emergency management / ITSCM
- Coordination of the circumstances with the public-sector IT service provider
- Consideration of KRITIS relevance within the scope and implementation of a B3S
- Development of requirements for document control and the continuous improvement process
- Preparation of relevant project documents
- Analysis of existing processes and preparation of guidelines
- Requirements gathering for ISMS and ITSCM and coordination with the IT service provider, including definition of interfaces
- Analysis of communication processes and escalation paths
- Review of documents for risk management, ISMS, emergency preparedness, and emergency response
- Redesign of the complete documentation and preparation of new relevant documents
- Development of necessary rules, policies, and concepts
- Interface between customer and service provider to ensure document quality
- Coordination of protection needs with specialist departments, particularly regarding KRITIS relevance, and planning of resulting measures
- Development of preventive measures to minimize the risk of data center outages in scenarios such as pandemics or ransomware attacks
- Definition of the test strategy for IT emergency exercises
- Initiation of necessary awareness training measures for specialist departments
- External Information Security Officer
- Introduction of document control
Henry H.
Last position:
Interim Manager IT-Compliance at Int. Fertigungsunternehmen
- Industry: mechanical engineering, vehicle manufacturing
- Regulations: Data Act
- Project focus: data governance, legally compliant use of machine data, data platforms
- Assigned by: CFO, platform product owner
Successes/Results (early phase):
- Compliance support for the setup of an internal standardized data usage platform based on Databricks.
- Created the basis for the legally compliant and effective use of machine data, including:
- Technical: gap analysis and closing of gaps in the segmentation and maintenance of collected machine data.
- Technical: consideration of data flows from the platform to users and third parties.
- Organizational: drafting and finalizing the required data usage agreements.
Regina K.
Last position:
Data Protection Consultant at Promotional institute of a federal state (public credit institution)
Industry: Finance/Insurance
- Sparring partner for the data protection team
- Taking over tasks from the data protection backlog
- Updating data protection processes
- Updating TOMs
- Revising template documents (including DPA, data protection guidelines)
- Conducting audits (authorization concept, software development)
- Taking over tasks from day-to-day operations
- Processing data protection reports
- Conducting DPIA and TIA
- Reviewing data processing agreements
- Designing and delivering trainings
- Standard Data Protection Model
- AI and data protection
Result: Successfully supported the data protection team, worked through the data protection backlog, and delivered trainings successfully
Alicja W.
Last position:
Integrated Security and Emergency Documentation for a 24/7 Logistics Company at Medium-Sized Logistics Company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), Access Control Policy, Vulnerability Management Policy, Business Resilience Programme, Risk Governance Plan
- Consolidation into an integrated emergency manual (12 chapters) with immediate-action checklists for six emergency scenarios, a prioritized action table and a formal approval structure
- Review and documentation of the applicability of NIS2 and HinSchG, including the legal justification for non-applicability
Peter K.
Last position:
IT Audit Expert at Sparkasse
Support for Internal Audit:
Conducting an audit of the data protection officer and data protection management:
- Preparing an audit program based on the audit field concept
- Requesting the necessary audit documentation
- Carrying out control testing based on the audit program with the following focus:
- Reviewing the relevant PPS processes
- Reviewing the data protection mission statement, data protection policy, and data protection management concept
- Conducting audit interviews with the data protection officer
- Preparing the audit documentation
- Training a junior auditor in the methodology of Internal Audit
- Coordinating the audit documentation with the head of audit
Christian E.
Last position:
IT Consulting / IT Rebuild at IT-Neuaufbau (PF)
- Analysis of requirements and the current situation
- Migration of an old domain structure and Tobit to Exchange 2019 with integration to MS365
- Evaluation of implementation paths and planning for securing sensitive data
- Planning regarding BSI basic protection, the German Federal Data Protection Act (BDSG), and GDPR
- IT governance and IT security backtests
- Support with ERP setup and securing mail transfer
- Hyper-V 2016/2022, Microsoft Terminal Services Cluster, Microsoft Exchange 2019
- Office 365, Microsoft 365, Azure AD, Teams, Salesforce
- Cisco, Zyxel, and HP switches, Sophos firewalls/UTMs, SecurePoint
- Microsoft IIS 2022, IPv4/IPv6, Veeam, Wortmann online backup, NextCloud
- Services: DNS, DHCP, TCP/IP, subnetting, firewalling, routing, VoIP, Group Policy (GPO), SIEM, remote work, home office, high availability, failover, VLAN, PRTG
Matthias M.
Last position:
Project Manager at HSBC
- Project Manager for banking projects
- Management and coordination of the projects 'XONTRO T7 Migration' and 'UNO – Unified for New Opportunities'. Management of international stakeholders, preparation and leadership of steering committees, and coordination between departments, exchanges, and external partners.
- Project management of the strategic projects 'XONTRO T7 Migration' and 'UNO – Unified for New Opportunities'
- Management of international stakeholders including exchanges, custodians, and external project partners
- Coordination of functional and technical test activities at the exchanges between trading, IT, accounting, and mid-/back office
- Facilitation of steering committees at management level
- Preparation of decision papers, status reports, and risk analyses
- Conduct analyses in the areas of reporting (compliance, regulatory reporting, etc.), taxes on securities transactions & custody accounts, process analysis
- Enforcement of required requirements/specifications
- Coordination between business, IT, operations, and external market participants
- Coordination and alignment with external market participants, service providers, exchanges, and other project stakeholders
Pierre G.
Last position:
Ansible Automation, Windows Third Level Support at DB InfraGO AG
- PRISMA project
- Ansible automation
- Windows third-level support for Windows NT, Windows 2000, Windows 2013, Windows 2016, Windows 2019
Thomas M.
Last position:
Consultant / System Administrator / IT Analyst at Thomas Martini IT-Services
- Analysis and audit of the current situation on-site and at customer locations
- Planning of IT infrastructures and advice on new hardware purchases as well as migration planning
- Planning and management of the IT budget
- Configuration and support of IT hardware under Windows 7, 8.x, 10 and Mac OS
- Review and update of documentation with regard to GDPR
- Analysis and expansion of technical and organizational measures in accordance with GDPR and BDSG
- Training of employees
- Training in AI-Assistant Consulting and Cybersecurity with AI
- Recording the current state and planning the target state
- 2nd/3rd level support (C/S/N)
- Technical environment: Exchange Administration, Active Directory, MS Server 2016 R2, MS Server 2022, MS SQL Developer, MS SQL, Visual Studio 2013+, Tivoli Monitoring, Tivoli Remote, TeamViewer, weclapp CRM Solution, RA-Micro, IT Compliance, Citrix, UltraEdit, SCCM, Windows XP–11, Office 2010–M365, VPN Solutions, Lexware Solutions, OKI Management Solutions, LogMyTime, SAGE Systems
Federico L.
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW. Developed and implemented a holistic process view covering both technical and organizational aspects Ensured end-to-end control of all IAM-related technical services Established clear responsibilities and accountabilities within the IAM landscape Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security Introduced and monitored governance policies to ensure compliance and security Continuously improved IAM processes and systems through regular audits and evaluations Participated in external audits of the process as part of official ISO audits Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units Conceptually advanced the KPI system to measure process quality
Michael F.
Last position:
Project Manager Implementation B3S / ISO 27001 at Health Insurance Fund
- Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
- Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
- Collaborating with the Information Security Officer (ISO)
- Identifying company assets for IT risk management
- Developing a zone concept for IT risk management
- Creating an action plan for B3S
- Developing a template for risk analyses
George O.
Last position:
IT Senior Consultant at Data Group
- IT Senior Consultant (bank infrastructure, Active Directory, Azure, security, PKI)
- Planning, design, and implementation of cloud solutions based on Microsoft Azure / M365
- Teams, M365, and cloud services
- Vulnerabilities, threats, attacks
- Security analysis, security policy, security architecture
- Conducting meetings and presentations at various management levels
- Organizing and leading team meetings to improve internal communication
- Tools: PowerShell, Active Directory, GPO, DNS, DHCP, scripting
Robert V.
Last position:
Freelance Consultant Information Security and Business Continuity at Freelance business consulting
- Provide consulting services nationwide in both private and public sectors
- Advise on information security management systems, IT-Grundschutz, KRITIS compliance, TISAX, business continuity and crisis management
- Support the introduction of policies, risk management methods, asset registers and supplier management
- Conduct internal audits, training workshops and support audit preparations
Frank M.
Last position:
Freelance Security + Data Protection Consultant at Deutsche Bahn
- Placed via recruiter 1st Solution with Deutsche Bahn. Supported and advised on Audit and Cyber Security matters there
- Carried out numerous CSAs (Control Self Assessments), with close exchange with application owners and development of possible remediation solutions, and entered them in DB's risk2value tool from vendor GBTEC2
- Advised on the creation of internal and external security risks
Dmitrii S.
Last position:
IT Risk & Compliance | DORA | IT Regulatory & Operational Resilience Senior Consultant at Jefferies GmbH
Leading Jefferies’ DORA-driven operational resilience programme by strengthening ICT risk governance, control design, and regulatory readiness across key technology and outsourcing domains. Partnering with senior stakeholders to translate regulatory requirements into pragmatic governance, reporting, and assurance processes suitable for a global investment banking environment.
- Developed the Enterprise Register of Information (DORA Art. 28.3) to align with regulatory requirements.
- Defined and embedded ICT Risk Appetite and tolerance levels aligned to the Global Operational Risk Framework, strengthening decision-making and risk acceptance governance.
- Drove audit readiness by reviewing and re-drafting 50+ IT & Information Security policies, improving clarity, ownership, and control alignment.
- Oversaw the Operational Resilience Testing Programme (including penetration testing) and tracked remediation to closure, strengthening control assurance and reducing open findings.
- Aligned 10+ intra-group agreements with DORA regulatory standards.
- Enhanced executive-level decision-making with an enterprise ICT Risk Dashboard featuring KPIs/KRIs.
Discover over 15,000 top freelancers
Statistics of experts using BDSG
Aggregated from the professional profiles of matched freelancers.
Experience
25 years

Position duration
3.6 years

Positions per freelancer
14

Top business areas
Information Technology, Project Management, Legal

Top industries
Information Technology, Professional Services, Banking and Finance

Certification focus areas
Information Technology, Legal, Audit
Bachelor's degree or higher
88%
Master's degree or higher
65%
Doctorate
15%

Certifications per freelancer
7

Most common languages
German, English, French

Speak two or more languages
100%
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using BDSG
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
BDSG experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (80%)
- Professional Services (69%)
- Banking and Finance (46%)
- Manufacturing (43%)
- Healthcare (40%)
- Education (37%)
- Insurance (37%)
- Government and Administration (37%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
Legal foundation
The BDSG, or Bundesdatenschutzgesetz, is Germany’s federal data protection law. It supplements the General Data Protection Regulation (GDPR) with national rules for areas such as employee data, video surveillance, scoring and data protection officers. Companies use it to assess processing activities and define lawful, transparent handling of personal data.
Where it applies
BDSG requirements appear wherever organisations in Germany collect, use, share or store personal information. Typical settings include employment, customer management, healthcare, finance, retail, public services and technology operations.
- Review employee and applicant data processing
- Assess surveillance and access-control practices
- Align German procedures with GDPR obligations
- Document lawful bases, retention and disclosures
Ecosystem and skills
Professionals working with BDSG usually connect legal interpretation with operational privacy work. Their toolkit may include records of processing, data protection impact assessments, deletion concepts, consent management, contracts for processors and incident response procedures. They also understand interfaces with information security, HR, procurement and IT governance.
When companies need help
Freelance expertise is useful during a new system launch, an audit, a restructuring or an expansion into Germany. It can also support organisations that need to update privacy notices, review vendors or clarify responsibilities between controllers and processors. In Germany, specialists may work with local teams on site or coordinate securely with distributed stakeholders.
- Prepare a BDSG and GDPR gap assessment
- Review software, vendors and processing agreements
- Create practical policies for HR and operations
- Support responses to incidents or authority requests
What strong experts deliver
Strong professionals translate BDSG obligations into clear decisions and usable controls. They distinguish legal requirements from sensible risk reduction, ask precise questions about data flows and leave behind documentation that teams can maintain. Experience across German and European privacy contexts helps when one process must serve several jurisdictions.
Choosing the right specialist
Look for evidence of work with the data types, systems and industry constraints involved in your project. Ask how the specialist handles conflicts between BDSG, GDPR, employment law, security controls and business needs. A good engagement should define scope, stakeholders, deliverables and escalation paths before detailed reviews begin.
Frequently asked questions
Key details about BDSG, drawn from the questions we get asked most.
The BDSG is Germany’s federal data protection law. It supplements the GDPR with rules and clarifications for topics such as employee data, video surveillance, scoring, data protection officers and certain remedies.
The BDSG does not replace the GDPR; it works alongside it. The GDPR provides the main European framework, while the German law adds national provisions where European law allows or requires further detail.
A strong BDSG specialist should understand GDPR, records of processing, data protection impact assessments, processor contracts and information security. Knowledge of HR processes, procurement and incident response is valuable for projects involving operational data flows.
The right level of BDSG experience depends on the scope. A focused policy review may need a specialist who can assess a defined process, while a transformation, audit response or multi-system programme calls for broader work across legal, technical and organisational controls.
Much BDSG work can be completed remotely through secure document sharing, workshops and access to process owners. On-site collaboration can help when the engagement involves physical security, workplace observation, sensitive records or close coordination with German teams.
Bring in a BDSG specialist before launching a system that processes personal data, changing HR practices, selecting a major vendor or responding to a suspected breach. Early review can identify unclear responsibilities, excessive collection and weak retention controls before they become costly issues.
Ask a BDSG professional to explain a comparable engagement, the assumptions behind their assessment and the evidence they would request. Quality shows in precise data-flow analysis, practical recommendations, well-structured documentation and a clear distinction between mandatory controls and optional improvements.
A BDSG freelancer may deliver a gap assessment, processing records, privacy notices, retention rules, vendor reviews, employee-data guidance or a data protection impact assessment. The deliverables should be tailored to the organisation’s systems, risk profile and relationship with the GDPR.
The average hourly rate of freelancers in Germany who have used BDSG in their recent projects is 116 €, which corresponds to a daily rate of about 927 € based on an 8-hour working day.
Of the freelancers in Germany who have used BDSG in their recent projects, 88% hold at least a Bachelor's degree, 65% hold at least a Master's degree, and 15% hold a doctorate.
On average, freelancers in Germany who have used BDSG in their recent projects have 25 years of professional experience, with a single engagement typically lasting around 3.6 years.
The most common languages among freelancers in Germany who have used BDSG in their recent projects are German (100%), English (94%), and French (23%).
The most common industries among freelancers in Germany who have used BDSG in their recent projects are Information Technology (80%), Professional Services (69%), and Banking and Finance (46%).
The most common business areas among freelancers in Germany who have used BDSG in their recent projects are Information Technology (89%), Project Management (83%), and Legal (71%).
Main locations of FRATCH Experts, who have recently used BDSG
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
