All employees of Second IT are bound by the data secrecy requirement under § 5 of the BDSG. This means that they may not process or disclose personal data that they might come into contact with in the course of their work without authorization, even after their employment has ended. Internal guidelines, regular training, and strict controls ensure that this obligation is observed in everyday life. The obligation is documented in a comprehensible way for your audit requirements. Together with the certified data deletion a double protection is created: technically, because the data are permanently removed, and organizationally, because every person in the process is obliged to maintain confidentiality.
Yes, Second IT also processes and destroys classified documents of the VS-NfD classification level („For service use only“). VS-NfD is the lowest level of confidentiality for government classified documents and primarily applies to authorities, public institutions, and their contractors. Processing follows the classified documents guidelines and is handled by experienced specialists working in secure areas. Data media that cannot be deleted securely are mechanically destroyed in-house according to DIN 66399. Every step is logged and is traceable in audits. Details about the destruction process can be found here. Data carrier destruction.
Yes, Second IT concludes tailor-made confidentiality agreements (NDAs) with its clients upon request. These contractually stipulate that your information is used solely for the agreed-upon purposes and is made accessible only to the intended individuals. The contractual commitment is complemented by technical and organizational measures: logged access, physically protected data rooms, and strict access controls. Depending on the agreement, the confidentiality may also include information about the project itself, not just the contents of your data carriers. In this way, you create a reliable foundation before the first hardware leaves your premises. It is best to discuss your requirements for an NDA directly during the request process.
All employees undergo regular training in data protection, IT security, and compliance; a certificate for employee training in accordance with the EU GDPR exists for this purpose. Awareness-raising campaigns on topics such as phishing, password security, and the handling of sensitive data ensure that security policies are not only known but also internalized. Well-trained employees are the first line of defense against security risks and a prerequisite for compliance with standards such as ISO/IEC 27001. The logistics team has also been specifically trained to ensure the safe handling of IT hardware. This creates a security culture that permeates every step of the process, from transport to disposal.
ISO/IEC 27001 is the international standard for information security management systems, and Second IT is certified in accordance with it. The standard requires that risks be systematically assessed, protective measures established and regularly reviewed. At Second IT, this means that every process step is controlled by coordinated security protocols, monitored in real time and documented on a 365-day basis. Accesses are logged, data rooms are physically protected and regular audits ensure that the measures remain effective. For you, this creates a seamless chain of evidence from the initial capture to the final deletion or destruction.