Services
Solutions
Tools
Insights
References
Contact
Free initial consultation Ask a first question by email
About Deutsch

Mandatory digital requirements do not exist out of ill intent from regulators. They create reliability – in finances, working hours, data and the use of AI. When implemented correctly, they also bring internal clarity instead of overhead.

The Core Compliance Topics

  • E-Rechnung (mandatory e-invoicing) – Receiving mandatory since 2025, issuing from 2027. This topic has its own service page covering the whole path from document to posting batch.
  • GoBD (German digital bookkeeping regulations) – Governs how documents and accounting data must be stored: digitally, securely, and traceably. Covers everything from paper receipts and emails to digital invoices.
  • Time tracking – The German Working Hours Act requires complete, reliable recording of working hours. With Projectile I have implemented project time tracking in production for years; the obligation can be combined with real benefit.
  • EU AI Act – Phased application: competence and transparency obligations have applied since 2025, largely complete from August 2026. Affects anyone using AI in customer contact or decisions; I apply the Art. 50 labeling obligations on this very website.
  • NIS-2 (cybersecurity) – Risk management, reporting channels and supply chain requirements for companies from 50 employees in the regulated sectors. The German transposition is delayed; the demands on processes and systems are already clear.
  • EU Data Act – Applicable since September 2025; from September 2026, access by design applies to new connected products. Anyone collecting machine or IoT data needs access and contract processes: a data and interface topic.
How Implementation Works

Assessment: First, we jointly understand how your processes run today – which systems are in use, where documentation exists, and where it does not.

Define concrete requirements: “Become GoBD-compliant” is too vague. We clarify specifically: which data must be stored for how long, who is responsible, and what an audit trail looks like.

Tool selection and process design: Good solutions exist on the market – but new software only helps if the underlying processes are clearly defined.

Coordination with tax advisors and IT: Your tax advisor knows the legal details, your IT lead knows the system landscape. I make sure both sides arrive at a shared solution.

Training and anchoring: New software is useless if the teams do not understand how and why they should use it.

How Is This Different from Pure Legal Advice?

A tax advisor or lawyer tells you what the law requires. I translate that into:

  • Concrete process steps within your organization
  • System requirements for your IT
  • Training content for your teams
  • Documentation for your audits

The goal is that the requirement is not perceived as an external obligation, but fits into daily work.


Recent Articles on Compliance & Regulatory Requirements


Next Steps

Mandatory digital compliance topics are not optional. But how you implement them determines whether they become overhead or structure.

If you have a specific compliance topic ahead of you – whether GoBD, time tracking, AI Act, NIS-2 or Data Act – let us clarify in a conversation: Where does your organization stand today, which requirements are currently relevant, and how do we make this practical?

Get in touch

The next step costs nothing.

30 to 60 minutes, no strings attached: where is the biggest friction, what is the most effective lever, and is a collaboration a fit?