Skip to content
Call, 0511 – 47 55 58 11

Practice area

Data protection law: advise, implement, represent

Processing personal data is part of many business processes. Companies and data subjects alike have an interest in that processing being in line with the GDPR.

We advise on data protection law, accompany its implementation inside the business and represent you before supervisory authorities and courts. From Hannover, and therefore close to the Data Protection Commissioner of Lower Saxony, the competent authority for matters seated in that state.

Data protection made to measure means that policies, training and procedures describe the processing operations of your organisation and not those of an imagined average business.

Where data protection matters begin

The accountability principle in Art. 5(2) GDPR requires not only compliance but proof of it. Anyone unable to show compliance therefore stands in proceedings like someone who failed to comply.

Establishing where you stand

We compare processing operations, records and contracts against the statutory requirements and say what is missing and how much it matters. The result is an order of work, not an ungraded list of defects.

Data protection audit in detail

Policies and impact assessment

A tailored policy only works if it describes what actually happens. Where processing carries a high risk, a data protection impact assessment is added, and its threshold is frequently underestimated.

Impact assessment in detail

Training for staff

Most incidents begin not in the technology but at a desk. We train on the processing operations of your organisation rather than on the GDPR in general, and we record attendance, because that too is part of the accountability record.

Training in detail

Data breach and notification

The 72-hour period runs from the controller becoming aware, not from the attack. Only what is likely to create a risk has to be notified, but the assessment has to be recorded in every case, including where it comes out against notification.

How to handle a data breach

Access, erasure and objection

Access requests rarely arrive alone and often pursue a purpose other than access. The right reaches further than most expect, but not without limit, since the rights of others and trade secrets bound it.

Access requests in detail

Transfers to third countries

With US providers the first question is whether the company is listed under the adequacy framework, and only then which safeguards remain necessary. That check belongs before procurement and has to be documented.

Third country transfers in detail

Fines and proceedings

Proceedings usually begin with a hearing, and what is written there shapes everything that follows. Under Art. 83 GDPR the range reaches up to 20 million euros or four per cent of worldwide annual group turnover.

Fine proceedings in detail

Proceedings before the supervisory authority

We accompany you from the first hearing through requests for information to the fine notice and its challenge, before whichever supervisory authority is competent and throughout Germany. Under Art. 83 GDPR the range of fines reaches up to 20 million euros or four per cent of worldwide annual group turnover.

Are you GDPR compliant?

We tell you where you stand and what needs doing before the next inspection.

Arrange an initial call

Topics in this practice area

Frequently asked questions

Do we have to report every data breach?

No. Only breaches likely to result in a risk to the rights and freedoms of natural persons must be reported. The assessment must be documented in every case, however, including when it comes out against reporting. Missing documentation is regularly the first point of attack in proceedings.

Does the 72-hour deadline run from the attack or from our awareness?

From the controller becoming aware. Noticing an incident on a Friday evening does not buy you until Monday. That is why a rehearsed notification process belongs in your preparation, not in the emergency.

A former employee is demanding access to all their data. How far does that reach?

Further than most expect, but not without limit. The right covers the personal data processed together with information on purposes, recipients and retention periods. Third-party rights and trade secrets set boundaries. We assess what must be disclosed and what may be withheld.

Do we need a processing agreement with every service provider?

No, only where processing is carried out for you on your instructions. Anyone deciding independently on purposes and means is a controller in their own right, for instance tax advisers, lawyers and banks. A processing agreement in that situation describes the relationship wrongly, and that shows up in the first review.

When do we need a data protection officer?

As a rule from twenty people permanently engaged in the automated processing of personal data. Regardless of that number, the duty applies where processing requires a data protection impact assessment or where data is processed commercially for the purpose of transfer. The appointment itself runs through lexICT GmbH as our service company.

May we use providers based in the United States?

Yes, where the conditions are met. The first question is whether the company is listed under the adequacy framework, in which case the transfer needs no further safeguard. If it is not, standard contractual clauses and an assessment of the legal situation in the destination country are added. Both belong before procurement and have to be documented.

Does every breach give rise to damages?

No. The Court of Justice of the European Union requires actual damage, and the breach alone is not enough. Nor is there a threshold of seriousness, and non-material damage can lie in a well-founded fear that data will be misused. The amounts usually stay low, the number of proceedings does not.