RKSV & GDPR.
Austrian tax law, data protection law and EU regulation are not checkboxes at the end of a project. I implement compliance technically correctly — from the start, in the architecture, audit-proof.
Cash Register Compliance
The Austrian cash register obligation requires DEP7, a signature creation unit and a FinanzOnline connection. I implement all mandatory components in compliance with the law, including in existing systems without an official vendor interface.
Signature creation unit (SCU)
Every receipt is cryptographically signed. I integrate certified SCUs into new or existing software.
Data collection protocol DEP7
Immutable, chained receipt journal in the statutory format. Exportable for tax audits at the push of a button.
FinanzOnline connection
Automatic cash register registration and DEP transmission, in the background, fully automated.
Monthly & annual receipts
Automatic generation and verification of mandatory receipts for each billing period.
Middleware for existing systems
Your POS stays. I add the RKSV layer in between, independent of the manufacturer.
GDPR - Technical Data Protection
Data protection is created in the architecture. Row-level security, encryption and deletion concepts are built into the software from the start, not added retrospectively.
Privacy by Design
Data minimisation, secure authentication and minimal data retention are considered in the architecture from day one.
Technical documentation
Processing register (RoPA), TOMs and DPIA for high-risk processing, complete and audit-proof.
Row-level security & encryption
Every user sees only their own data. Sensitive fields are end-to-end encrypted.
Data processing agreements
DPAs with all service providers who process your data, substantively correct and legally sound.
Data breach management
Processes and tools for the emergency: detection, documentation and supervisory authority notification on time.
EU AI Act - AI Compliance
The EU AI Act has been binding since 2025. Companies that deploy or develop AI systems must classify risk levels, fulfil transparency obligations and ensure human oversight.
Risk level classification
Your AI system is correctly classified under the EU AI Act, with all resulting technical and documentary requirements.
Transparency & labelling
Users receive clear information when they interact with an AI system. Legally required labelling included.
Human oversight
The system supports decisions and does not make them independently. Approval processes are firmly built in.
Documentation obligations
Technical documentation, risk assessments and logging in accordance with EU AI Act requirements.
Compliance that holds up under audit.
I review your current situation and tell you what is genuinely urgent — and what can wait.