In the interview with Georg Nestmann, CEO of Comcrypto GmbH.

Anyone wanting to send emails in compliance with data protection laws has so far had to go to considerable effort with end-to-end encryption. Today, we talk to Georg Nestmann, CEO of Comcrypto, about his practical solution to this problem.
DIGITAL FUTUREmag: In your company description, you state that the majority of business emails are not transmitted in compliance with data protection laws. Where does this knowledge come from?
Georg Nestmann: That is indeed the case. Just look in your Sent folder: How many of the emails you have sent to recipients outside your company contain personal data? Names, addresses, bank details, personal information? We don’t even need to mention insurance, health, financial or social data here – data protection requirements apply much earlier. And each of these emails should have been transmitted encrypted. Unfortunately, very few people do this because it is too difficult.
DIGITAL FUTUREmag: What is the difference between transport and content encryption, and when is each one mandatory?
Georg Nestmann: There are now finally clear statements from the German Data Protection Conference, i.e., the body of the data protection authorities of the federal states and the federal government. Since May 2020, it has been clear: a “normal” transport encryption, as is currently widely used, is sufficient at most for non-sensitive information. A better choice for secure email transmission is qualified transport encryption. While it is technically significantly more complex, once implemented, emails transmitted in this way can be considered equivalent to registered mail.
You can therefore be sure that your email has reached the correct recipient’s mailbox and that no unauthorized third party has had access to the data. This is sufficient for normal and high risk of damage and thus for everyday requirements in industry, business, social institutions and administration. Only if there is a duty of confidentiality must an email be end-to-end encrypted. This distinction is also absolutely understandable, because end-to-end encryption requires coordination with each individual recipient and is very complex. This is simply not feasible on a broad scale, and of course the Data Protection Conference is also aware of this.
DIGITAL FUTUREmag: As soon as emails contain personal data, they must be transmitted encrypted. How can you check whether this problem has already been sufficiently solved at server level?
Georg Nestmann: We have set up a test recipient for this. Simply send a test email to test@evaluation.comcrypto.de and wait for the test result. But I’ll say this right away: most email servers will fail because they simply cannot or practically manage the necessary security and data protection checks.
DIGITAL FUTUREmag: When is a normal risk present in the business area and when must one speak of an increased risk?
Georg Nestmann: The Data Protection Conference has provided many practical examples for this. Data with normal risk includes, for example, booking confirmations or invoices. High risk exists with salary statements or certificates, social data, or information about a person's health, political or sexual orientation. The rule of thumb is: If a data subject would face significant material or social harm if an email were lost or manipulated, or is the potential damage lower?
With our qualified transport encryption, you can dispense with this classification entirely; it meets the data protection requirements for all of these examples.
DIGITAL FUTUREmag: The Data Protection Conference of the data protection authorities of the federal states and the federal government (DSK) has confirmed your technology. This means it is considered GDPR-compliant. What else makes your solution simple and practical?
Georg Nestmann: Employees are relieved of the obligation to have to worry about data protection. They simply click "Send" on an email, and our software takes care of the rest. That is crucial. Think of companies and corporations with thousands of employees. The training efforts, control and monitoring workloads, and all these individual organizational measures. And yet the human error remains a risk. This creates a lot of friction, hinders digitalization and communication, and nobody enjoys it. Not the employees, not the data protection officers, not the IT department, and ultimately not the customer, patient, or citizen who never receives a response or has to deal with passwords just to read an email. With our solution, all of this is eliminated or reduced to the few cases where it is truly necessary. The product can actually be set up with a single click, and as a data protection officer or compliance officer, you have everything in view afterward and can take action from a central location. For the first time, you can see where data protection problems actually exist and centrally implement the data protection policy for email communication.
DIGITAL FUTUREmag: For which types and sizes of companies is your technology particularly suitable?
Georg Nestmann: With large companies, the effects are naturally the greatest, as potential savings can quickly reach the millions. The relief for employees is also considerable. If we then look at industries such as insurance, financial services, social services or healthcare, which handle large amounts of personal data in high-risk areas and are required to securely digitalize their processes, Comcrypto’s solution is the right answer and is highly compatible with any existing IT infrastructure these companies have built up.
However, we have developed this product so that it also works for SMEs, small and even very small companies, as well as freelancers, and is affordable. It is simply used as a monthly subscription, optionally as a cloud service. The price depends on the number of mailboxes the company has. How many emails are sent, to how many recipients, and whether large file attachments are included makes no difference—the program works quietly in the background.
DIGITAL FUTUREmag: We thank you for these important and interesting insights.
The interview questions were posed by Erika Alkemper-Heinrich
Contact:
comcrypto GmbH
Brückenstraße 4
09111 Chemnitz
Tel.: +49 (0) 371 256206-00
Mail: kontakt@comcrypto.de
Internet: https://www.comcrypto.de