Daten-Sicherheit und Datenschutzbeauftragte aus Köln – English
Datenschutzbeauftragter in Köln

You focus on your business. We make sure data protection and information security work.

GDPR, ISO 27001, NIS2, and BSI – implemented pragmatically instead of documented bureaucratically.

Tulos IT-Sicherheit und Datenschutz aus Köln

4.9 out of 5 stars based on 36 google reviews.

Greater customer trust with the Tulos Secured Seal

Effective protection against costly data protection penalties

Enhanced security across digital value chains

Over 20 years of enterprise experience. Mid-sized business pragmatism.

We understand the requirements of customers, auditors, insurers, and regulatory authorities—and implement them in a pragmatic, cost-effective, and practical way for small and medium-sized businesses.

Datenschutzbeauftragter Köln

Why Companies Choose Tulos

We ensure transparent data processing—resulting in greater security and less operational effort.

Ensure Compliance

Meet the requirements of GDPR, ISO 27001, and NIS2.

Reduce Risks

Prevent cyberattacks and minimize liability risks.

Work More Efficiently

Less effort. More transparency. Better processes.

We understand the root causes and have developed practical, proven solutions for your business.

Roderich Pilars de Pilar, Founder of Tulos Consulting GmbH

Our Solutions

Tulos – certified Lead Auditors and Data Protection Officers based in Cologne.

We understand the risks and protect our clients from GDPR penalties and unnecessary effort caused by errors in data processing.

Solutions for Data Protection

Solutions for Information Security

  • External CISO
  • ISMS Implementation
  • Audit Readiness

  • NIS2 Readiness

Get advice from one of our data security experts. The initial consultation is free!

About Tulos

Who We Are and What We Do

Tulos stands for results. Our goal is to deliver measurable outcomes.

We are certified Data Protection Officers and experts in information security.

We have many years of experience in analyzing and auditing business processes, particularly with regard to risks in data processing.

Our Lead Auditors and information security experts are ISO-certified and provide consulting and support in implementing information security measures, including IT infrastructures, servers, networks, and websites.

Tulos provides employee training in the areas of data protection (GDPR) and information security. The secure handling of confidential data is one of the most important measures for reducing risks.

We work according to measurable standards, including ISO 27001, BSI, and NIS2.

Equal Opportunities Statement

Equal opportunities are a matter of course – regardless of origin, sexual identity, gender, age, or religion.

At Tulos Consulting, inclusion, diversity, and tolerance are among the company’s core values. Terms referring to persons on our website and in print materials apply equally to all genders unless explicitly stated otherwise.

Roderich Pilars de Pilar, Datenschutzbeauftragter
Roderich Pilars de Pilar

Founder, Tulos Consulting GmbH

Nalan Erol
Nalan Erol

Nalan Erol Dipl.-Computer Scientist | CISA

Elena Pano, Master of Laws und Datenschutzbeauftragte
Elena Pano

Master of Laws (LL.M.)

Tulos Consulting is an IHK-certified training company.

Tulos is listed with the Chamber of Crafts NRW as a provider for IT security and data protection.

Handwerk Digital NRW Datenschutz

Legal compliance and technical implementation from one source

20 years of international project experience

Tulos services are eligible for government funding.

Tulos – Your Experienced Data Protection Officer in Cologne

What our Clients Say

“Roderich Pilars de Pilar is our Data Protection Officer at Corporate Momentum GmbH. He explained in simple terms what really matters when it comes to data security. Tulos analyzed our company for vulnerabilities and implemented the necessary measures for us. Everything was handled quickly and pragmatically.”

Corporate Momentum

“We have all websites of our (new) clients reviewed by Tulos first. Nothing would be worse than a failure of websites and online shops – because even the best online marketing is of little help in that situation.”

Wolfram Strachwitz
FaceGuard

“GDPR is important for my company, but it also requires a lot of work. Roderich Pilar from Tulos showed us in simple terms what matters and took care of everything necessary for data protection at de Booij Immobilien. It was easy and efficient. THANK YOU VERY MUCH FOR THE EXCELLENT ADVICE AND SUPPORT!”

de booij immobilien logo

Hendrik de Booij
DeBooij Immobilien

“A reliable, competent, and high-performing company that we trust as online shop operators. Tulos Data Protection and its measures are a true recommendation even for smaller companies.”

Madeleine Treuleben
Ellabee

More Clients Who Trust Us

Get advice from one of our Data Protection Officers and Information Security Experts. The initial consultation is free!

9 Typical Causes of Vulnerabilities in Companies, Everyone has experienced

1

Dangerous Convenience

Neglected data processing not only attracts cybercriminals but also encourages improper handling of valuable company data. Both can lead to costly additional efforts.

2

Websites with GDPR and Security Issues

Especially for online shops: deficiencies are unacceptable. Websites simply need to work reliably.

3

Lack of Transparency in Data Processing

The growing volume of data creates increasing risks if it is not properly managed.

4

Lack of Awareness of Risks

Insufficient employee awareness of data protection is one of the most widespread issues.

5

Missing Evidence in Legal Disputes

Under the GDPR, an organization accused of wrongdoing often has to prove its compliance.

6

Missing Risk Management

Avoiding foreseeable damage should be obvious – yet it is often neglected.

7

Lack of Standards in Data Processing

This leads to unnecessary effort and costly surprises caused by cyber incidents.

8

Errors During Digitalization

Employees are not sufficiently involved, and IT systems are not properly understood.

9

Inefficient IT Systems

They lead to frustrated users and can also result in insecure data processing.

Get advice from one of our Data Protection Officers and Information Security Experts. The initial consultation is free!

Your Data Protection Officer in Cologne Answers Your Questions

FAQ on Data Protection and Data Security

What does an external data protection officer do?

An external data protection officer supports companies in implementing the GDPR, monitors data protection processes, and helps reduce legal risks and unnecessary administrative efforts. They act as a point of contact for all data protection-related questions and support companies during audits or inquiries from authorities.

When does a company need a data protection officer?

Under the General Data Protection Regulation (GDPR), companies are required to appoint a data protection officer if certain legal conditions are met. The obligation does not depend solely on the size of the company, but primarily on the type, scope, and purpose of the data processing activities.

A data protection officer is required, for example, if the company’s core activities involve the regular and systematic monitoring of individuals on a large scale, such as tracking user behavior, analyzing customer data, or processing extensive personal profiles.

The appointment is also mandatory if a company processes large amounts of special categories of personal data, including health data, biometric data, genetic data, or information about religious beliefs, political opinions, or other particularly sensitive information.

In Germany, a data protection officer may also be required under additional national regulations. According to the German Federal Data Protection Act (BDSG), companies generally need to appoint a data protection officer if 20 or more employees regularly process personal data as part of their work.

Even when there is no legal obligation, appointing an external data protection officer can be beneficial. Especially for small and medium-sized enterprises, an external expert provides independent advice, ensures GDPR compliance, supports documentation requirements, and helps reduce legal and operational risks.

An external data protection officer from Tulos supports companies with the implementation of GDPR requirements, the review of processes, employee training, data protection audits, and ongoing compliance management. This allows companies to meet their legal obligations while focusing on their core business.

Why should a company appoint an external data protection officer?

An external data protection officer provides companies with up-to-date expertise, independent advice, and saves internal resources. For many small and medium-sized businesses, outsourcing this role is often more efficient and cost-effective than developing internal data protection expertise.

What is the difference between data protection and information security?

Data protection primarily focuses on the lawful handling of personal data. Information security, on the other hand, protects all important company information from loss, manipulation, unauthorized access, or misuse. Both areas are closely connected and should be addressed together.

How does Tulos support companies with GDPR compliance?

Tulos analyzes existing processes, identifies risks, and supports companies in the practical implementation of GDPR requirements. This includes data protection audits, documentation, templates, employee training, and continuous support from experienced data protection experts.

What is an ISMS and why does a company need one?

An Information Security Management System (ISMS) provides structured processes to protect information, IT systems, and business operations over the long term. It helps companies systematically assess risks and implement security measures in a transparent and documented way.

Does Tulos support companies with ISO 27001 certification?

Yes. Tulos supports companies in implementing and developing Information Security Management Systems and preparing for ISO 27001 requirements. The consulting services are provided by experienced ISO-certified experts.

What is NIS2 and does the directive affect my company?

The NIS2 Directive expands cybersecurity requirements for many companies and organizations. Tulos helps businesses assess their current security level and implement the necessary measures to achieve NIS2 compliance.

Does Tulos offer data protection training for employees?

Yes. Tulos provides training in the areas of data protection and information security to help employees recognize risks and handle confidential information securely.

Can data protection and information security services be subsidized?

Yes, certain consulting services related to data protection and digitalization may qualify for government funding under specific conditions. Tulos helps companies identify suitable funding opportunities.

Which companies can benefit from Tulos services?

Tulos supports companies from various industries – from small and medium-sized businesses to organizations with complex requirements – in the areas of data protection, information security, and compliance with important standards such as GDPR, ISO 27001, BSI, and NIS2.

Contact form

Interested in: *

* Required fields

For privacy reasons Google Maps needs your permission to be loaded.
Go to Top