Skip to content
Corpshore Deutschland

EU compliance

The regulatory stack, made legible.

Choose a regime. You see what it requires, how Corpshore meets it, and which documentation you can request.

Three professionals reviewing documents in a formal meeting room.
General information, not legal advice. This content is to be reviewed by counsel before publication and does not replace advice in an individual case.
GDPR and the Federal Data Protection Act

What it requires

A legal basis for each processing activity, a record of processing, technical and organisational measures, and for third-country transfers a mechanism with an impact assessment.

How Corpshore meets it

We work in full GDPR compliance, deliver from Poland intra-EU with no third-country transfer, and for Türkiye, Egypt and Uzbekistan through the EU Standard Contractual Clauses with an impact assessment and supplementary measures.

Documentation you can request

Data processing agreement, sub-processor list, transfer impact assessment and a description of the technical and organisational measures.

AI Act

What it requires

A classification of the AI system, technical documentation, data governance, logging and effective human oversight, with different obligations for providers and deployers.

How Corpshore meets it

We support classification, technical documentation, data governance records and the design of human oversight mapped to the real workflow, and settle the provider and deployer split in the contract.

Documentation you can request

Classification analysis with reasoning, technical documentation, a data governance record and the documented oversight design.

DORA (digital operational resilience)

What it requires

For financial entities: prescribed contractual terms with ICT providers, a register of information, resilience testing and documented exit arrangements.

How Corpshore meets it

We supply the prescribed contractual terms, the information for your register, participation in resilience testing and documented exit arrangements, ideally already at contracting.

Documentation you can request

ICT contractual addendum, register entries, testing evidence and the exit and transition arrangement.

NIS2 implementation (Germany)

What it requires

Risk management measures for network and information security and reporting obligations with statutory deadlines that reach into the supply chain.

How Corpshore meets it

Our security operations are built for continuous monitoring and for meeting statutory reporting deadlines, with German-language reporting at both technical and board level.

Documentation you can request

A description of the security measures, incident response runbooks and evidence of detection and reporting.

Supply chain due diligence act

What it requires

Due diligence obligations in respect of human rights and the environment that reach into supplier relationships.

How Corpshore meets it

We supply the information you need for your supply chain due diligence and align our own employment and working conditions accordingly.

Documentation you can request

Supply chain statement, code of conduct and information on employment conditions at the delivery locations.

Accessibility Strengthening Act

What it requires

Accessibility for a defined set of consumer-facing products and services, with a genuine accessibility declaration.

How Corpshore meets it

Where our services touch consumer-facing surfaces, we work to WCAG 2.2 AA and supply the evidence for your declaration.

Documentation you can request

Conformance evidence, a test report and the information for your accessibility declaration.

BaFin outsourcing regime

What it requires

For supervised institutions: entry in the outsourcing register, audit and control rights, information and instruction rights and orderly exit arrangements.

How Corpshore meets it

We supply the documentation for your outsourcing register, agree audit and inspection rights and align reporting to your supervisory obligations, built to survive a review.

Documentation you can request

Register entries, agreed audit and inspection rights, escalation and information rights and the reporting structure.

For Switzerland the revised Federal Act on Data Protection and the FINMA expectations apply on their own terms. See the Switzerland market page. Switzerland

Let us talk about what you need.

Tell us which function you want to outsource, in which languages and at what scale. You get a substantive answer rather than a brochure.

We answer every enquiry within six hours.