← Back to About

Certification

Certified Data Protection Officer

On a website, data protection is not a footnote at the end. It is a construction decision at the start. This certificate shows that I know the rules I make those decisions by.

Issued by Developer Akademie GmbH AZAV-accredited training providerMarch 2026

View certificate (PDF) (Certified Data Protection Officer, opens in a new tab)

The record

Issuer
Developer Akademie GmbH
Issued
Focus
DevSecOps foundational certificate · part of the DevSecOps program

Competencies

  • GDPR
  • BSI Grundschutz
  • ISO 27001
  • Legal Foundations

What the certificate states

It was issued by Developer Akademie GmbH, an AZAV-accredited training provider, in March 2026. The document lists GDPR, BSI Grundschutz, ISO 27001 and legal foundations as competencies. It exists as a PDF — you can view it on this page without asking me for it.

What it is not

The certificate does not make me your Data Protection Officer. Appointing a DPO is a separate, formal step, and whether your business needs one at all is not decided by your website. What the certificate does is something else, and often more useful to you: the decisions made while your website is built are made by someone who has read the rules.

What it changes during the build

Most data protection problems on a website come from convenience, not ill will: a font served from Google, an embedded map, an analytics script in the header. Each of those sends your visitor's IP address to someone else's machine before they could consent to anything. So I build the other way round: fonts sit on your server, maps load only after consent, and anything not needed is simply never embedded.

How you can check it on this site

This site is built by the same rules I offer you. The map on the contact page loads no tile before you agree. The analytics service is wired in and deliberately switched off. The privacy policy names each processing operation and its legal basis instead of repeating a template.

What this means for your project

  • Your site loads no fonts, maps or scripts from third-party servers before someone has consented.
  • Forms store what is needed to answer them — and the policy says for how long.
  • Legal texts are written alongside the technology, not bolted on afterwards from a template.
  • For every embed you get an answer to one question: where does the data go, and why does it have to go there?

Other certificates

Not sure what leaks data on your website?

Send me the address. I will check which third-party servers your page contacts on first load, and tell you what can go.

Project inquiry