Cortado
Data Protection & Compliance

EU GDPR-compliant MDM: Data protection and compliance for mobile devices

As soon as business smartphones and tablets are in use, personal data is processed – in every organization, regardless of industry or size. Cortado brings data protection, data sovereignty, and compliance together: with hosting in Germany and administration that even small IT teams can manage.

Smartphone and tablet with a shield icon symbolizing data protection on mobile devices

Starting point

Why data protection on mobile devices affects every organization

Email, contacts, calendars, documents, messengers: Business devices contain personal data from employees, customers, and partners. This means EU GDPR requirements apply – whether you have ten devices or ten thousand in use.

Without centralized management, many questions remain unanswered: Who has access, what happens if a device is lost, how are personal and business data separated, and how can all of this be documented in an audit?

CHALLENGES & SOLUTION

Where data protection on mobile devices fails – and how Cortado solves it

We know the typical stumbling blocks from hundreds of projects. Cortado addresses exactly those points: as focused Mobile Device Management from Germany that technically enforces requirements and makes them verifiable.

gavel

Requirements only on paper

Data protection and security requirements have been defined, but not technically implemented on smartphones and tablets. With Cortado, they become policies that automatically apply to every device.

cloud_off

Unclear legal jurisdiction for hosting

It is often impossible to document where data is processed. Cortado is developed and operated in Germany – including data processing under the EU GDPR.

visibility_off

No overview of the fleet

Which devices are in use, and how are they configured? Cortado shows device status, operating system versions, and compliance violations in a dashboard.

work

Personal and business data mixed

On personal or mixed-use devices, separation is missing. With work profiles for BYOD and COPE, personal data remains outside management.

extension_off

Existing solutions are too complex

Large suites create administrative effort, licensing costs, and training needs. Cortado focuses on mobile devices and can be administered without specialist knowledge.

fact_check

Evidence is missing in audits

Without documentation, every audit becomes a project. Cortado provides reports on configuration and compliance status as evidence.

Data center in Germany with a shield symbolizing data sovereignty

Data sovereignty

Hosting in Germany, software from Berlin

Cortado is developed in Germany and operated in German data centers. This keeps device, usage, and configuration data within a European legal jurisdiction – a factor that is often decisive in tenders, data protection impact assessments, and audits.

  • Processing and data storage in Germany
  • Data processing under the EU GDPR
  • Clear role and permission assignment in administration

THE SOLUTION IN DETAIL

How Cortado implements data protection and compliance

Compliance Management, Secure Mobile Work, and data sovereignty in one platform – for iOS, iPadOS, and Android.

policy

Enforce policies centrally

Passcodes, encryption, network access, app approvals, and restrictions are defined centrally and automatically enforced on all devices.

work

Separation of personal and business data

With work profiles and COPE/BYOD scenarios, personal data remains outside management – a key argument for data protection and employee representatives.

fact_check

Evidence for audits

Device status, compliance violations, and configurations can be viewed at any time and documented for audits.

phonelink_lock

Response to loss and theft

Lock, locate, and perform selective or full remote wipe – the most important building block against data leakage.

rocket_launch

Automated enrollment

Apple Business Manager and Android Enterprise: Devices arrive preconfigured for the team, without manual setup.

dashboard_customize

Administration without specialist knowledge

A streamlined portal instead of license and console sprawl – so even small IT teams remain effective.

IMPLEMENTATION

Achieve verifiable compliance in three steps

Together with IT, security, and data protection teams, you document the requirements, device types, and operating models and translate them into specific policies.

You configure the policies directly in the administration portal for a test group, check their effect on the devices, and coordinate them with governance and employee representatives.

The rollout runs automatically through Cortado in conjunction with Apple Business Manager and Android Enterprise. Reports document your fleet’s compliance status at any time.

WHO IT’S FOR

Suitable for any organization with business mobile devices

We support these use cases especially often – the requirements for data protection and verifiability are similar everywhere.

apartment

Companies of all sizes

Mixed iOS and Android fleets, distributed locations, and field teams – centrally managed instead of supported device by device.

account_balance

Public administration

Municipalities, public authorities, and municipal enterprises that want to implement digitalization projects while staying legally compliant.

school

Education

Schools, universities, and education providers that operate iPads and Android tablets in the classroom in compliance with data protection requirements.

local_hospital

Healthcare & regulated sectors

Hospitals, care providers, utilities, and financial service providers with especially sensitive data and audit requirements.

TRUST

Award-winning and recognized

Cortado has received multiple Leader awards in Mobile Device Management and holds the Software Made in Germany and Software Made in Europe quality seals.

Software Made in Germany 2026
Software Made in Europe 2026
OMR Reviews Leader Mobile Device Management
Android Enterprise Silver Partner

FREQUENTLY ASKED QUESTIONS

Questions about EU GDPR and MDM

What makes Cortado an EU GDPR-compliant MDM?

expand_more

Cortado is developed in Germany and operated in German data centers – including a data processing agreement under the EU GDPR. Business and personal data remain strictly separated in BYOD and COPE scenarios, device data collection follows the principle of data minimization, and administration rights can be assigned based on roles. Reporting and logs provide evidence for data protection and audits. Encryption, passcode policies, as well as remote lock and remote wipe secure the devices themselves.

How much effort does implementation require?

expand_more

A pilot with a small group of devices is typical, during which policies are coordinated and documented. The rollout then runs automatically: Devices are enrolled via Apple Business Manager or Android Enterprise and arrive preconfigured for the team. We involve data protection and employee representatives early so approval does not become a bottleneck.

Where is our data hosted?

expand_more

Operations run in German data centers. This keeps device and configuration data within the European legal jurisdiction – including a data processing agreement under the EU GDPR.

Does Cortado support NIS2 requirements?

expand_more

NIS2 requires risk management, access control, and verifiable security measures, among other things. For mobile devices, Cortado provides the technical building blocks for this: enforced security policies, up-to-date operating system versions, controlled app use, plus transparency and reporting on the state of the fleet.

What happens to employees’ personal data?

expand_more

In BYOD and COPE scenarios, business data is managed in a separate work profile. Personal content remains outside administrator access, and only business data can be deleted during offboarding.

Put data protection on mobile devices into practice now

Try Cortado MDM with no obligation – or discuss your requirements directly with our team.