BDSG Experts in Germany
in minutes from over 15,000 CVs with the power of AI.Hire experts who know the German Federal Data Protection Act, support GDPR alignment, draft internal privacy policies, and handle employee data or retention rules with care. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used BDSG
Henry Hanau
Last position:
Interim Manager IT-Compliance at Int. Fertigungsunternehmen
- Industry: mechanical engineering, vehicle manufacturing
- Regulations: Data Act
- Project focus: data governance, legally compliant use of machine data, data platforms
- Assigned by: CFO, platform product owner
Successes/Results (early phase):
- Compliance support for the setup of an internal standardized data usage platform based on Databricks.
- Created the basis for the legally compliant and effective use of machine data, including:
- Technical: gap analysis and closing of gaps in the segmentation and maintenance of collected machine data.
- Technical: consideration of data flows from the platform to users and third parties.
- Organizational: drafting and finalizing the required data usage agreements.
Regina Körnicke
Last position:
Data Protection Consultant at Promotional institute of a federal state (public credit institution)
Industry: Finance/Insurance
- Sparring partner for the data protection team
- Taking over tasks from the data protection backlog
- Updating data protection processes
- Updating TOMs
- Revising template documents (including DPA, data protection guidelines)
- Conducting audits (authorization concept, software development)
- Taking over tasks from day-to-day operations
- Processing data protection reports
- Conducting DPIA and TIA
- Reviewing data processing agreements
- Designing and delivering trainings
- Standard Data Protection Model
- AI and data protection
Result: Successfully supported the data protection team, worked through the data protection backlog, and delivered trainings successfully
Peter Konrad
Last position:
IT Audit Expert at Sparkasse
Support for Internal Audit:
Conducting an audit of the data protection officer and data protection management:
- Preparing an audit program based on the audit field concept
- Requesting the necessary audit documentation
- Carrying out control testing based on the audit program with the following focus:
- Reviewing the relevant PPS processes
- Reviewing the data protection mission statement, data protection policy, and data protection management concept
- Conducting audit interviews with the data protection officer
- Preparing the audit documentation
- Training a junior auditor in the methodology of Internal Audit
- Coordinating the audit documentation with the head of audit
Alicja Wilczek
Last position:
Integrated security and emergency documentation for a 24/7 logistics company at Medium-sized logistics company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), access control policy, vulnerability management policy, business resilience programme, risk governance plan
- Consolidation into an integrated emergency handbook (12 chapters) with immediate checklists for six emergency scenarios, a prioritized action table, and a formal approval structure
- Review of a penetration test report (Greenbone) with complete remediation of all findings and formal risk acceptance of a residual risk with documented compensating control
- Review and documentation of NIS2 and HinSchG applicability, including the legal reasoning for non-applicability
Christian Enderle
Last position:
IT Consulting / IT Rebuild at IT-Neuaufbau (PF)
- Analysis of requirements and the current situation
- Migration of an old domain structure and Tobit to Exchange 2019 with integration to MS365
- Evaluation of implementation paths and planning for securing sensitive data
- Planning regarding BSI basic protection, the German Federal Data Protection Act (BDSG), and GDPR
- IT governance and IT security backtests
- Support with ERP setup and securing mail transfer
- Hyper-V 2016/2022, Microsoft Terminal Services Cluster, Microsoft Exchange 2019
- Office 365, Microsoft 365, Azure AD, Teams, Salesforce
- Cisco, Zyxel, and HP switches, Sophos firewalls/UTMs, SecurePoint
- Microsoft IIS 2022, IPv4/IPv6, Veeam, Wortmann online backup, NextCloud
- Services: DNS, DHCP, TCP/IP, subnetting, firewalling, routing, VoIP, Group Policy (GPO), SIEM, remote work, home office, high availability, failover, VLAN, PRTG
George Ojog-Schulze
Last position:
IT Senior Consultant at Data Group
- IT Senior Consultant (bank infrastructure, Active Directory, Azure, security, PKI)
- Planning, design, and implementation of cloud solutions based on Microsoft Azure / M365
- Teams, M365, and cloud services
- Vulnerabilities, threats, attacks
- Security analysis, security policy, security architecture
- Conducting meetings and presentations at various management levels
- Organizing and leading team meetings to improve internal communication
- Tools: PowerShell, Active Directory, GPO, DNS, DHCP, scripting
Thomas Martini
Last position:
Consultant / System Administrator / IT Analyst at Thomas Martini IT-Services
- Analysis and audit of the current situation on-site and at customer locations
- Planning of IT infrastructures and advice on new hardware purchases as well as migration planning
- Planning and management of the IT budget
- Configuration and support of IT hardware under Windows 7, 8.x, 10 and Mac OS
- Review and update of documentation with regard to GDPR
- Analysis and expansion of technical and organizational measures in accordance with GDPR and BDSG
- Training of employees
- Training in AI-Assistant Consulting and Cybersecurity with AI
- Recording the current state and planning the target state
- 2nd/3rd level support (C/S/N)
- Technical environment: Exchange Administration, Active Directory, MS Server 2016 R2, MS Server 2022, MS SQL Developer, MS SQL, Visual Studio 2013+, Tivoli Monitoring, Tivoli Remote, TeamViewer, weclapp CRM Solution, RA-Micro, IT Compliance, Citrix, UltraEdit, SCCM, Windows XP–11, Office 2010–M365, VPN Solutions, Lexware Solutions, OKI Management Solutions, LogMyTime, SAGE Systems
Matthias Metzlaff
Last position:
Project Manager at HSBC
- Project manager for banking projects
Peter Dittkuhn
Last position:
Security Consultant at Public Institution of the City Administration
- Requirements management, process planning, interface role, ISMS implementation and documentation
- Implementation and establishment of an ISMS according to ISO 27001 as well as setup of emergency management / ITSCM
- Coordination of conditions with the authority-affiliated IT service provider
- Consideration of KRITIS relevance in the scope and implementation of a B3S
- Development of guidelines for document control and the continuous improvement process (KVP)
- Creation of relevant project documents
- Analysis of existing processes and development of guidelines
- Collection of requirements for ISMS and ITSCM and coordination with the IT service provider including definition of interfaces
- Analysis of communication processes and escalation paths
- Review of documents for risk management, ISMS, emergency preparedness and emergency response
- Development of a complete rebuild of all documentation and creation of new relevant documents
- Development of necessary rules, policies and concepts
- Interface function between customer and service provider to ensure document quality
- Coordination of protection needs with departments, especially regarding KRITIS relevance, and planning resulting measures
- Development of preventive measures to minimize data center outages for various scenarios such as pandemics or ransomware attacks
- Defining the test strategy for IT emergency exercises
- Initiation of necessary training measures for raising awareness in departments
- External Information Security Officer (ISB)
- Introduction of document control
Federico Leefhelm
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW. Developed and implemented a holistic process view covering both technical and organizational aspects Ensured end-to-end control of all IAM-related technical services Established clear responsibilities and accountabilities within the IAM landscape Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security Introduced and monitored governance policies to ensure compliance and security Continuously improved IAM processes and systems through regular audits and evaluations Participated in external audits of the process as part of official ISO audits Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units Conceptually advanced the KPI system to measure process quality
Michael Fitschen
Last position:
Project Manager Implementation B3S / ISO 27001 at Health Insurance Fund
- Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
- Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
- Collaborating with the Information Security Officer (ISO)
- Identifying company assets for IT risk management
- Developing a zone concept for IT risk management
- Creating an action plan for B3S
- Developing a template for risk analyses
Robert Vattig
Last position:
Freelance Consultant Information Security and Business Continuity at Freelance business consulting
- Provide consulting services nationwide in both private and public sectors
- Advise on information security management systems, IT-Grundschutz, KRITIS compliance, TISAX, business continuity and crisis management
- Support the introduction of policies, risk management methods, asset registers and supplier management
- Conduct internal audits, training workshops and support audit preparations
Frank Mühlenbrock
Last position:
Freelance Security + Data Protection Consultant at Deutsche Bahn
- Placed via recruiter 1st Solution with Deutsche Bahn. Supported and advised on Audit and Cyber Security matters there
- Carried out numerous CSAs (Control Self Assessments), with close exchange with application owners and development of possible remediation solutions, and entered them in DB's risk2value tool from vendor GBTEC2
- Advised on the creation of internal and external security risks
Dmitrii Shatov
Last position:
IT Risk & Compliance | DORA | IT Regulatory & Operational Resilience Senior Consultant at Jefferies GmbH
Leading Jefferies’ DORA-driven operational resilience programme by strengthening ICT risk governance, control design, and regulatory readiness across key technology and outsourcing domains. Partnering with senior stakeholders to translate regulatory requirements into pragmatic governance, reporting, and assurance processes suitable for a global investment banking environment.
- Developed the Enterprise Register of Information (DORA Art. 28.3) to align with regulatory requirements.
- Defined and embedded ICT Risk Appetite and tolerance levels aligned to the Global Operational Risk Framework, strengthening decision-making and risk acceptance governance.
- Drove audit readiness by reviewing and re-drafting 50+ IT & Information Security policies, improving clarity, ownership, and control alignment.
- Oversaw the Operational Resilience Testing Programme (including penetration testing) and tracked remediation to closure, strengthening control assurance and reducing open findings.
- Aligned 10+ intra-group agreements with DORA regulatory standards.
- Enhanced executive-level decision-making with an enterprise ICT Risk Dashboard featuring KPIs/KRIs.
Stephan Merckens
Last position:
Product Owner at Self-employed
- Industry: Health Care/ IT
- Tools: Internet, phone, email, Confluence, Azure DevOps, DISweb, Microsoft Teams, Microsoft Office, FHIR
- requirements engineering for implementing the e-prescription into existing practice management system and a web-based dialysis monitoring
- implementation of the archive and exchange interface of the KBV
- creation and maintenance of user stories and backlog management
- stakeholder management and support of developers in implementing the user stories
- reporting to management and conducting refinements
Discover over 15,000 top freelancers
Statistics of experts using BDSG
Aggregated from the professional profiles of matched freelancers.
Experience
25 years
Position duration
3.6 years
Positions per freelancer
14
Top business areas
Information Technology, Project Management, Legal
Top industries
Information Technology, Professional Services, Banking and Finance
Certification focus areas
Information Technology, Legal, Audit
Bachelor's degree or higher
88%
Master's degree or higher
65%
Doctorate
15%
Certifications per freelancer
7
Most common languages
German, English, French
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using BDSG
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What BDSG covers
BDSG is Germany’s Federal Data Protection Act. It works alongside the GDPR and sets the national rules that matter in everyday privacy work, especially for employee data, public-sector processing, and German-specific exemptions. Strong professionals translate legal text into clear company processes.
Typical project work
- review privacy notices and internal policies
- map lawful bases for HR and customer data
- support data subject requests and deletion workflows
- align processor contracts and retention rules
- prepare training and documentation for teams
Ecosystem and practice
In practice, BDSG work touches GDPR, consent management, records of processing, TOMs, and security policies. Experts also work with works councils, HR systems, ticketing tools, and document management setups. The best specialists know how legal requirements change day-to-day operations.
When companies bring in help
Companies usually need outside support when they are updating privacy policies, launching a new HR or CRM process, handling a regulator request, or cleaning up old data practices. In Germany, this often means balancing head-office standards with local BDSG details. Freelance specialists can step in for audits, short projects, or temporary coverage.
What strong professionals do
Strong BDSG professionals are precise, practical, and calm under pressure. They can explain the law in plain words, spot risky data flows, and turn findings into actions that teams can follow. They also document decisions well, because evidence matters as much as advice.
Why the fit matters
BDSG is not just about legal text. It affects how a company hires, stores, shares, and deletes personal data. The right specialist helps avoid guesswork, reduce friction between legal, HR, IT, and operations, and keep privacy work usable instead of abstract.
Frequently asked questions
Key details about BDSG, drawn from the questions we get asked most.
BDSG is Germany’s Federal Data Protection Act, and companies use it together with the GDPR to manage personal data in a German legal context. It matters most for employee data, public-sector processing, and national rules that sit on top of general EU privacy law. A good specialist turns those rules into workable policies and processes.
BDSG does not replace the GDPR; it complements it with German-specific rules and exceptions. In many projects, the GDPR sets the main framework while BDSG decides how that framework works in Germany. Companies usually need both understood together, not in isolation.
A strong BDSG specialist usually also knows GDPR, privacy governance, employee data handling, retention concepts, and data subject request workflows. Practical experience with HR systems, document management, and internal policy writing helps a lot. Coordination with legal, IT, and HR is often part of the job.
A BDSG project often needs outside help when a company is changing HR processes, rolling out a new tool, handling a privacy review, or responding to a data protection issue. It is also common when internal teams need a fast second opinion on German rules. Freelancers can cover audits, implementation work, or temporary gaps.
Yes, many BDSG projects can be done remotely because the work centers on documents, workflows, and stakeholder interviews. On-site time can still help when a specialist needs to review local processes, meet HR or works council contacts, or support workshops in Germany. The right setup depends on how much process observation is needed.
Ask how the BDSG specialist has handled employee data, policy updates, and data subject requests in real projects. Also ask how they work with GDPR gaps, works councils, and internal stakeholders. Clear examples matter more than general privacy knowledge.
Good BDSG work is clear, actionable, and traceable. Look for plain-language recommendations, documented decisions, and a strong link between legal findings and day-to-day process changes. If the output is only theory, it is usually not enough.
Yes, BDSG is the common abbreviation for the Bundesdatenschutzgesetz, Germany’s Federal Data Protection Act. In searches, people may also use BDSG-neu to refer to the newer version that came with GDPR alignment. A strong specialist understands the current rules and the terminology people still use.
The average hourly rate of freelancers in Germany who have used BDSG in their recent projects is 115 €, which corresponds to a daily rate of about 917 € based on an 8-hour working day.
Of the freelancers in Germany who have used BDSG in their recent projects, 88% hold at least a Bachelor's degree, 65% hold at least a Master's degree, and 15% hold a doctorate.
On average, freelancers in Germany who have used BDSG in their recent projects have 25 years of professional experience, with a single engagement typically lasting around 3.6 years.
The most common languages among freelancers in Germany who have used BDSG in their recent projects are German (100%), English (94%), and French (23%).
The most common industries among freelancers in Germany who have used BDSG in their recent projects are Information Technology (80%), Professional Services (69%), and Banking and Finance (46%).
The most common business areas among freelancers in Germany who have used BDSG in their recent projects are Information Technology (89%), Project Management (83%), and Legal (71%).
Main locations of FRATCH Experts, who have recently used BDSG
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
