0800 / 27 00 001
We are thrilled to serve you
About us
The founding of the company
“Frommel Datenschutz” was founded in January 2010 by Daniel Frommel in Bad Homburg as an individual enterprise, at that time still under the name “Frommel Multimedia”. The area of activity initially was in the field of information and communication technologies (ICT). This included projects in the area of installation, maintenance of IT infrastructures and communication systems. The focus was always on data protection and information security. We also concentrated on product sales with the corresponding consulting and services.
Change of focus towards data protection
Over time, however, the focus has changed. In 2012, we received our first data protection enquiries from small and medium-sized customers, asking whether we could also take over the role of the external data protection officer (DPO). Since we considered data protection to be a very important topic at that time, we participated in further training and certification courses in order to be able to cover the topic competently in the future. Since then, we have continued to expand the topic of data protection and have built up further qualifications and competencies.
On 25.05.2018, the GDPR (General Data Protection Regulation) came into force. This was confirmation for us that we were moving in the right direction.
Competence expansion in the direction of information security
As of 2017, the Federal Financial Supervisory Authority (BaFin) issued the following regulations that made the appointment of a Chief Information Security Officer (CISO) mandatory.
- Supervisory Requirements for IT in Financial Institutions (BAIT) of September 2018
- Supervisory Requirements for IT in Insurance Undertakings (VAIT) of March 2019
- Supervisory Requirements for IT in German Asset Managers (KAIT) of October 2019
- Supervisory Requirements for IT at Payment Services Providers (ZAIT of November 2021
The aforementioned regulations explicitly state framework conditions that allow the role of the chief information security officer (CISO) to be obtained as an external service. This option is popular with small to medium-sized companies. As a result, we received the first inquiries in 2019 about filling the role of external CISO. We took this as an opportunity to position ourselves competently in the area of information security through further qualifications and certifications.
Split into two different companies
In 2020, the area of data protection and information security was outsourced to the independent individual company “Frommel Datenschutz”. It turned out that these topics required our full attention, leaving no time for the other multimedia topics. Since this year, “Frommel Multimedia” and “Frommel Datenschutz” have been running as two separate companies. Daniel Frommel continues to manage “Frommel Datenschutz”, while “Frommel Multimedia” has been handed over to his wife Ulrike Frommel.
In January 2023, the EU finally passed the Digital Operational Resilience Act (DORA). DORA is a European Union regulation that aims to strengthen the resilience of financial institutions and financial market infrastructures against cyber attacks. Special emphasis is placed on ICT risk management, in which technical risks in the area of communication and information technology in particular must be identified and dealt with. Furthermore, all ICT-relevant service providers must be identified and assessed, monitored and managed with regard to potential ICT risks. The role responsible for this is the so-called ICT risk manager. We have taken this as an opportunity to develop further. We can therefore offer the role of external ICT risk manager if required. The numerous experiences and projects in the field of information and communication technologies are of benefit to us.
Conversion to a limited liability company
Finally, in 2024, the sole proprietorship “Frommel Datenschutz” was transformed into “Frommel Datenschutz GmbH”.
Our services
Frankfurt am Main is known as a banking and financial metropolis, among other things. This means that many financial service providers and capital management companies are based in Frankfurt and are subject to the aforementioned regulations. Our proximity to Frankfurt makes us the ideal partner for you if you need an external DPO, CISO or ICT risk manager. Since data protection and information security have many overlaps, especially with regard to technical and organizational measures, it makes sense to combine the functions of DPO, CISO and ICT risk manager in one person. This creates synergy effects and saves costs. We can therefore offer you a lucrative overall package.
We will be happy to answer any questions you may have. The initial consultation is always free of charge.
The following graphic shows the interplay between data protection, information security, ICT risk management and cyber security. These are also the subject areas in which we have outstanding know-how and many years of expertise.