Formats for everyone who wants to understand data protection, cybersecurity and governance more clearly.
With 2fink Consulting you get formats in which we work on your real topics: Clarify governance, structure complex projects and strengthen internal managers.
Some things we do 1:1, others in Team ? online, on-site or hybrid.
This page is about: how We work together. What we specifically solve, you will find under Services.
Here you will find our core formats, specialized labs and selected public events that we offer in cooperation.
If you are unsure which format fits: Write to us hello@2fink.com or book your non-binding initial consultation.
Core formats ? how we work together
Mentoring & Peer?Coaching for internal managers
Many data protection?, cybersecurity? and compliance?roles sit between all chairs: Management, IT, departments, legal department, co-determination ? and should keep an eye on everything at the same time.
In mentoring and peer coaching, we work 1:1 with you on your real topics: we sort, prioritize, develop decision-making guidelines and communication strategies.
Typical occasions:
- New role assumed (e.g. DSB, Privacy Manager, Data Protection Coordination, CISO?Environment)
- Critical projects: AI?Introduction, new software, global rollout, M&A, Carve?out
- Areas of conflict with management, IT or co-determination
Format:
Online?sessions (1?2× per month) plus short ad?hoc?slots, duration 3?12 months.
Governance?Quick?Check
The governance "Quick Check" is your entry point if you want to know how sustainable your current data protection and cybersecurity organization really is.
Together we look at roles, decision paths, reporting, control mechanisms and interfaces to regimes such as GDPR, NIS2, AI Regulation (KIVO), DA and CRA.
Procedure (example):
- Short kick?off?call
- Sighting of selected documents (Org?Charts, guidelines, committees, central processes)
- 1?2 structured online?sessions
- Score + 3?5 concrete fields of action (no 40?page audit?report)
Ideal if you're facing a major change or feel like it could go better? ?, however, does not yet know exactly how and where.
Project?Sprints & Hands?on?Accompaniment
For larger projects, we go directly into the project with a ? in clearly defined sprints.
Typical topics are M&A transactions and carve-outs, business transitions, eCommerce spin-offs, web shops, global system introductions or roll-outs of applications or transformation and corporate restructuring.
We define goals and scope together, we help with governance?design, role clarification, risk? and use?case?assessment and the preparation of management?decisions.
Operational permanent tasks such as VVT?Care or Standard?Notes we deliberately leave to specialized partners:in ? our focus is on strategy, structure, responsibility and critical phases.
Thematic Labs (M&A, KI, NIS2, Privacy?Governance)
Labs are in-depth formats with a clearly defined topic and duration: Several sessions, some over a few weeks, with concrete deliverables at the end.
They can be set up as an open format (small group) or internally.
Currently, we mainly offer these labs:
M&A? & Carve?out?Lab ? Lifecycle, due diligence, integration planning, data migration
AI? & Digital?Governance?Lab ? Assessment, monitoring and governance for AI?/ Digital?Use?Cases
NIS2? & Regulation?Readiness?Lab ? GDPR, KIVO, NIS2 & Co. integrate into existing structures
Privacy?Governance?Design?Lab ? Debureaucratize and reorganize the data protection organization
Details can be found in the next section.
Labs ? our specialization formats
M&A & Carve?out?Lab
When data, systems and societies are moved, data protection and cybersecurity depend directly on deal value and time-to-integration.
In the M&A- & carve-out lab we look at:
Privacy & Cybersecurity Due Diligence
Data flows, lifecycle, CRM and eCommerce setups, third-party risks
Post-merger integration and governance of the new world?
Format (example):
3?6 sessions over 4?8 weeks, plus 1?2 focus workshops with your deal/project team.
KI & Digital?Governance?Lab (incl. KIVO?Seminar)
This lab is aimed at companies that use AI applications and digital products responsibly and at the same time want to comply with requirements such as the AI Regulation (KIVO), GDPR & Co.
Among other things, we are working on:
Use case inventory and risk classification
Roles, human-in-the-loop concepts and approval processes
Documentation and documentation, e.g. for KIVO compliance
KIVO variant:
Based on the same framework, we offer focused KIVO seminars or KIVO labs in which we specifically address the implementation of the AI Regulation in the corporate context ? in a practical manner and with a view to your existing structures.
Format (example):
4?6 sessions over 5?8 weeks, plus optional implementation workshop for specific use cases.
GDPR, NIS2 & Regulation?Readiness?Lab
Many companies need to integrate GDPR, NIS2, CRA, DA and other regimes into their existing compliance and governance structures.
In the Readiness Lab we create:
a compact gap image (Gap analysis, Is vs.
a mapping of existing roles, committees and processes
a prioritized roadmap with risk assessment
Ideal if you feel that new demands are coming your way, but you don't yet have a clear picture of where to start.
Format (example):
3?4 sessions over 3?5 weeks, including a joint timetable workshop.
Privacy?Governance?Design?Lab
This is about the question: What does a data protection organization look like that really helps you instead of blocking you with bureaucracy?
We are working on:
Analysis of your current structure: Processes, roles, templates
Design of a new governance model with clear role models and decision-making pathways
Interfaces to IT security, compliance and risk management
Meaningful application points for legal tech and AI tools
Format (example):
4?5 sessions over 4?6 weeks, with a final model workshop.
Current public dates & Cooperations
In addition to our own formats, we work in selected cooperations with ? primarily around founding and community formats.
Foundation compact Special ? Data protection & Cybersecurity (IHK)
In cooperation with the IHK (e.g. Nuremberg for Middle Franconia), we design special modules on data protection and cybersecurity within the framework of start-up formats.
Here you get as an aspiring founder:in a compact, practical overview, which basics you should set up clean from the beginning.
Founder's Talk ? Praxiskompass Datenschutz & Cybersecurity (SCHWUNG et al.)
In formats such as the Founder’s Talk at the incubator SCHWUNG Schwabach, we talk to founders about how they can think about data protection and cybersecurity right from the start ? without being overwhelmed.
It's about real examples, typical stumbling blocks and pragmatic first steps.
AI, Privacy & Cybersecurity ? Half a day in Schwabach
In this format, seminars or open half-day workshops take place on site in Schwabach.
On site · Paid · Schwabach
A structured half-day for managers from management, IT and compliance who want to know what the AI Regulation (KIVO), NIS2 and a changed risk situation mean in concrete terms.
Normally a Friday from 9:00 to 12:00 | Gründerzentrum SCHWUNG, Schwabach
From 190 ? net. Exact dates and final conditions will follow shortly.Past public events (selection)
Workshop: The Matrix Challenge ? Data Protection Management in Matrix Organisations | IAPP Munich KnowledgeNet, 2025
IAPP Munich, 2025 - Interactive workshop in the framework of the IAPP European Privacy KnowledgeNet in Munich on how to set up data protection and governance structures in matrix organisations in such a way that responsibilities remain clear despite multiple reporting lines.
Workshop: Data protection basics for companies
SCHWUNG Schwabach, 2026 – Compact workshop on basics, typical processing, first to-dos for SMEs (in cooperation with a start-up initiative).
Presentation: Praxiskompass Datenschutz & Cybersecurity
SCHWUNG, Schwabach, 2026 – Data protection as a competitive advantage in customer contact: Consent, information obligations, website and social media ? compact and directly implementable.
Community?Talks about AI & Privacy
Ongoing format, 2025/2026 - Open panels on current AI and data protection issues with changing themes and sessions where we discuss AI?Use?Cases practical governance? approaches with founders and SMEs.
AI
AI, and then what? Your KIVO seminar.
KIVO is more than a new compliance obligation. It is fundamentally changing how companies can develop, procure and use AI. Anyone who operates high-risk AI systems - whether in HR, finance, medical technology or everyday business - is faced with a clear question: Can I prove that my system is trustworthy?
The AI Regulation (KIVO) changes what companies have to prove when using AI. In this hands-on seminar, you will learn how to classify AI systems, structure assessments and seamlessly integrate data protection obligations.
From rebranding cases to significant changes to automated decisions. We make real-life case studies of legal text into lived compliance.
For whom?
Data protection officers, compliance managers, controllers, and anyone who adopts, procures, or operates AI systems.
When?
We're just browsing the calendar …
Where?
costs
— EUR (net) per participant:in
The participation fee is exclusive of statutory VAT.
You will receive an invoice.
I've changed my mind
You can cancel your participation by sending us an email.
Until …, the cancellation of your participation is free of charge. If you do not participate or cancel later, the participation fee will be due in full.
Of course, you can send a replacement.
Write it to us: hello@2fink.com