Practice area
Data protection law: advise, implement, represent
Processing personal data is part of many business processes. Companies and data subjects alike have an interest in that processing being in line with the GDPR.
We advise on data protection law, accompany its implementation inside the business and represent you before supervisory authorities and courts. From Hannover, and therefore close to the Data Protection Commissioner of Lower Saxony, the competent authority for matters seated in that state.
Data protection made to measure means that policies, training and procedures describe the processing operations of your organisation and not those of an imagined average business.
- Data protection made to measureWe advise on all questions of data protection law and align the implementation with your processing operations rather than with a template.
- Data protection officersThrough our sister company lexICT we provide your external data protection officers.
- Legal representationFines, damages, disclosure of data: we enforce your rights, in court and out of court.
Where data protection matters begin
The accountability principle in Art. 5(2) GDPR requires not only compliance but proof of it. Anyone unable to show compliance therefore stands in proceedings like someone who failed to comply.
Establishing where you stand
We compare processing operations, records and contracts against the statutory requirements and say what is missing and how much it matters. The result is an order of work, not an ungraded list of defects.
Policies and impact assessment
A tailored policy only works if it describes what actually happens. Where processing carries a high risk, a data protection impact assessment is added, and its threshold is frequently underestimated.
Training for staff
Most incidents begin not in the technology but at a desk. We train on the processing operations of your organisation rather than on the GDPR in general, and we record attendance, because that too is part of the accountability record.
Data breach and notification
The 72-hour period runs from the controller becoming aware, not from the attack. Only what is likely to create a risk has to be notified, but the assessment has to be recorded in every case, including where it comes out against notification.
Access, erasure and objection
Access requests rarely arrive alone and often pursue a purpose other than access. The right reaches further than most expect, but not without limit, since the rights of others and trade secrets bound it.
Transfers to third countries
With US providers the first question is whether the company is listed under the adequacy framework, and only then which safeguards remain necessary. That check belongs before procurement and has to be documented.
Fines and proceedings
Proceedings usually begin with a hearing, and what is written there shapes everything that follows. Under Art. 83 GDPR the range reaches up to 20 million euros or four per cent of worldwide annual group turnover.
Proceedings before the supervisory authority
We accompany you from the first hearing through requests for information to the fine notice and its challenge, before whichever supervisory authority is competent and throughout Germany. Under Art. 83 GDPR the range of fines reaches up to 20 million euros or four per cent of worldwide annual group turnover.
Are you GDPR compliant?
We tell you where you stand and what needs doing before the next inspection.
Arrange an initial callTopics in this practice area
- Access requestsAccess under Art. 15 GDPR: scope, the one-month deadline, the copy of the data and the limits set by third-party rights and trade secrets.
- Cookie bannersDesigning cookie banners that hold up: consent under German law, equal weight for rejection, documentation and the most common design mistakes.
- Damages under Article 82 GDPRA letter of claim has arrived. What the infringement proves, what it does not prove and what the amount actually turns on.
- Data breachNotification duty under Article 33 GDPR, the 72-hour deadline, informing data subjects: how to proceed after a data breach.
- Data protection auditData protection audit for the GDPR and German law: an assessment of your compliance, review of individual processes and a report you can show third parties.
- Data protection impact assessmentData protection impact assessment under Art. 35 GDPR: when it is required, what belongs in it and when the authority has to be consulted first.
- Data protection in esports clubsData protection in clubs: membership administration, communication over Discord, streaming at tournaments and the duties of the board.
- Data protection trainingData protection training for staff: onboarding and mandatory refreshers, delivered in house, as a webinar or as e-learning. Content tailored on request.
- Data quality and discriminationArticle 10 AI Act requires data governance against bias. Which quality criteria apply, what deployers owe, and how German equal treatment law fits in.
- Discord and team communicationRunning a server, roles and moderation, retention and transfers outside the EU: what a club has to settle when its communication runs on Discord.
- Fine proceedingsFines under Art. 83 GDPR: the criteria for setting them, the hearing, challenging the notice and the question of group liability.
- Inputs as training dataAre our inputs used for training? Confidentiality, trade secrets and how to draft the contract with AI providers.
- Joint controllershipIt arises from jointly determining purposes and means, without a contract and without intent. How far it reaches and what the arrangement has to settle.
- Microsoft 365 and the GDPRUsing Microsoft 365 in line with data protection law: impact assessment, privacy-friendly configuration and representation before the supervisory authority.
- Monitoring in the workplaceMonitoring potential usually arises as a side effect. How to establish it, reduce it technically and settle whatever remains with the works council.
- Online marketing and the GDPRUsing Google Analytics, consent management and targeted ads lawfully: review of your websites and advice on how to integrate them.
- Professional secrecy and IT providersOutsourcing by professionals bound to secrecy: why the processing agreement does not cover confidentiality and which providers are ruled out as a result.
- Receiving a warning letterWarning letters under trademark, copyright or competition law: assessing the claim, modified undertakings and fending off unfounded demands.
- Streaming matchesTournament, practice, scrim or your own channel: which legal basis carries the broadcast, who is the controller, and which technical choices reduce the effort.
- Supervisory authority proceedingsHearings, information requests, orders or fines: we act as your lawyers towards the data protection supervisory authority.
- Third-country transfersTransferring data to third countries: adequacy decisions, standard contractual clauses, transfer impact assessments and government access.
- Tracking under German lawTracking under the German Telecommunications Digital Services Data Protection Act: device access, the narrow necessity exception and the link to the GDPR.
- Transcription assistantsDeploying AI meeting notes lawfully: criminal law, employee data protection, works council participation and the usage policy to go with it.
- Video surveillance on business premisesWhat justifies a camera, where it may point, how long the footage may be kept and when it can be used in court.
Frequently asked questions
Do we have to report every data breach?
No. Only breaches likely to result in a risk to the rights and freedoms of natural persons must be reported. The assessment must be documented in every case, however, including when it comes out against reporting. Missing documentation is regularly the first point of attack in proceedings.
Does the 72-hour deadline run from the attack or from our awareness?
From the controller becoming aware. Noticing an incident on a Friday evening does not buy you until Monday. That is why a rehearsed notification process belongs in your preparation, not in the emergency.
A former employee is demanding access to all their data. How far does that reach?
Further than most expect, but not without limit. The right covers the personal data processed together with information on purposes, recipients and retention periods. Third-party rights and trade secrets set boundaries. We assess what must be disclosed and what may be withheld.
Do we need a processing agreement with every service provider?
No, only where processing is carried out for you on your instructions. Anyone deciding independently on purposes and means is a controller in their own right, for instance tax advisers, lawyers and banks. A processing agreement in that situation describes the relationship wrongly, and that shows up in the first review.
When do we need a data protection officer?
As a rule from twenty people permanently engaged in the automated processing of personal data. Regardless of that number, the duty applies where processing requires a data protection impact assessment or where data is processed commercially for the purpose of transfer. The appointment itself runs through lexICT GmbH as our service company.
May we use providers based in the United States?
Yes, where the conditions are met. The first question is whether the company is listed under the adequacy framework, in which case the transfer needs no further safeguard. If it is not, standard contractual clauses and an assessment of the legal situation in the destination country are added. Both belong before procurement and have to be documented.
Does every breach give rise to damages?
No. The Court of Justice of the European Union requires actual damage, and the breach alone is not enough. Nor is there a threshold of seriousness, and non-material damage can lie in a well-founded fear that data will be misused. The amounts usually stay low, the number of proceedings does not.