Data protection law

Data protection law is becoming increasingly important, and enforcement of strict data protection regulations continues to intensify. Anyone who maintains an online presence today without complying with data protection regulations runs the risk of facing legal action from regulatory authorities or competitors. Financial penalties and fines are also a possibility.

Given that data flows can sometimes be complex, it’s not always immediately clear which data is flowing where. We can advise you on how to properly handle data within your company, as well as on the information provided on your website.

Data protection law: It’s about more than data

Data protection law encompasses not only the protection of “data” in the narrow sense, but is also sometimes used synonymously with the broader field of the protection of “confidential information.” For this and other reasons, data protection law in the broader sense encompasses all laws, regulations, and other rules dedicated to the protection of privacy and the right to informational self-determination, and which govern the handling of secrets and personal data.

Advertising, online store, Facebook presence, newsletter & co.

As soon as you collect, store, or use third-party data, you generally need the consent of the data subject or must at least inform them of this. The scope of data collection and processing is as diverse as the possibilities of the Internet. This ranges from a Facebook plugin on your own blog to the collection of customer data for analyzing purchasing behavior—and the list goes on. We’ll show you how to comply with data protection regulations despite strict requirements.

Special case of employee data protection

Employee data protection law (often referred to as workplace data protection law) is another key area of our practice. We advise you on issues ranging from video surveillance in the workplace and the monitoring of (personal) correspondence and telecommunications in general to the necessary coordination with the works council.

Data protection advice and support for the data protection officer

We are available to serve as consultants to management, the executive board, the works council, or the current data protection officer. We also conduct training sessions and assist in drafting contracts and policies to ensure data protection within your company.

You can find us at Kaiserstrasse 1a in Bonn. We support companies and organizations from the region and across Germany—from drafting privacy policies and processing agreements to assisting with regulatory proceedings. Please feel free to contact us if you’d like us to serve as your external data protection officer.

Frequently Asked Questions About Data Protection Law

Under current law, a data protection officer must be appointed if, as a general rule, at least twenty people are regularly engaged in the automated processing of personal data (Section 38(1) of the Federal Data Protection Act [BDSG]), regardless of whether the additional cases specified in Article 37 of the GDPR apply—such as in cases involving extensive processing of special categories of data. The Federal Government has announced that it will eliminate the twenty-person threshold by the end of 2026; until a relevant provision is published in the Federal Law Gazette, the current requirement remains in effect.

Depending on the nature of the violation, fines can range up to ten or twenty million euros; for companies, they can amount to up to two or four percent of global annual revenue, pursuant to Article 83 of the GDPR. The type, severity, and duration of the violation, as well as the extent to which the company cooperates in the investigation, are decisive factors. In addition, there may be claims for damages by data subjects and, depending on the circumstances of the case, consequences under competition law.

Within one month of receiving the request, Art. 12(3) of the GDPR. In the case of complex requests, this period may be extended by an additional two months; however, you must notify the data subject of this extension within the first month. In addition to the data itself, the information provided also includes the purposes, recipients, and retention period, which is why it’s worth having a prepared template.

Within 72 hours of the incident becoming known to the competent supervisory authority, unless a risk to the data subjects is unlikely, Art. 33 GDPR. If there is a high risk, the data subjects themselves must also be notified, Art. 34 GDPR. The deadline begins at the time you become sufficiently aware of the incident in concrete terms; therefore, the internal reporting chain should be established in advance.

Yes, Article 82 of the GDPR provides for compensation for material and non-material damages. According to the case law of the European Court of Justice, there is no materiality threshold; however, the data subject must demonstrate specific harm—the mere occurrence of a violation is not sufficient. Consequently, the amounts awarded vary accordingly.

Whenever a service provider processes personal data on your behalf and in accordance with your instructions, Art. 28 GDPR. In addition to hosting and cloud storage, this also applies to newsletter distribution, analytics tools, and external payroll accounting. The absence of a contract constitutes a separate violation in and of itself, regardless of whether anything actually happened to the data.

Your Contact for Data Protection Law

Florian Wagenknecht

Florian Wagenknecht

Partner & specialist lawyer for copyright & media law

Your Inquiry Regarding Data Protection Law

Current in the blog