Data Protection Consultancy
Data protection is more than a legal obligation; it is key to trust and sustainable success in the digital world. Companies process large amounts of personal data daily, and protecting this data is not only a legal requirement but also a sign of professionalism and respect towards customers, partners, and employees.
What is data protection?
Data protection involves safeguarding personal data against unauthorized access, misuse, loss, or unlawful processing. Its aim is to protect individuals' privacy and ensure their personal information is used in accordance with applicable laws and predefined purposes. To exercise their rights (e.g., access, erasure, or rectification), data subjects must be informed about what data is being processed and for what purpose. Data protection relies on data security, achieved through technical measures like data encryption and organizational measures like clear data processing guidelines.
What are the benefits of effective data protection management?
Effective data protection management offers numerous advantages. It helps avoid fines, claims for damages, and reputational damage by ensuring compliance with data protection laws. It also strengthens customer trust through transparency and security in handling personal data, leading to stronger customer loyalty and a positive corporate image. A robust data protection concept reduces the risk of security breaches and improves data processing efficiency.
How is data protection regulated?
Germany has numerous legal regulations, with the GDPR and the Federal Data Protection Act (BDSG) as central provisions, supported by data protection laws of individual federal states, social data protection under the Social Security Code, and specific church data protection laws (KDG for Catholic Church institutions and DSG-EKD for Protestant Church institutions).
Our services in the area of data protection consulting
- Review and adaptation of data protection processes
We analyze your existing structures and adapt them to current legal requirements. - Creation of data protection guidelines
We are happy to draw up clear and practical guidelines for employees and external partners. - Consulting and training
Data protection plays a role at all levels of the company, which is why we offer training courses for management, employees and works councils to inform and sensitize them in the area of data protection. - Representation in legal conflicts
In the event that conflicts do arise, our experts will support you in disputes with authorities or affected parties.
Contact persons
Bernhard Veeck
Attorney at Law | Partner
LL.M. (Media Law) | Adjunct Professor at Frankfurt University of Applied Sciences | Data Protection Officer (TÜV)
FAQ: Data Protection Advice
When considering current EU regulation, one might gain the impression that data protection is increasingly being displaced by topics such as IT security and Artificial Intelligence. That view is too narrow. In particular, the new IT security legislation frequently specifies the technical and organisational measures within the meaning of Article 32 GDPR and thus has a direct connection with data protection law. Regulatory instruments such as the AI Act and the Data Act also expressly refer to the GDPR and make clear that its requirements remain unaffected. In reality, the new requirements therefore lead to a significant specification of data protection obligations, particularly in the area of technical security measures. Against this background, the question is increasingly how data protection principles such as Privacy by Design and Privacy by Default can be reconciled with security-law requirements, such as the Need-to-Know principle. The central challenge is to create a balanced relationship between effective IT security and the protection of personal data.
Legal data protection advice is particularly useful when new processes, tools or service providers are introduced in which personal data play a role, for example CRM systems, HR tools, cloud services, AI applications or international co-operation. In international groups with centralised IT in particular, it is often difficult to determine whether there is processing on behalf of a controller or joint controllership. This determines who, as controller, must assess not only the lawfulness of the processing within its own group company but also the lawfulness of the transfer to another group company. At the latest in the event of data protection incidents, enquiries from supervisory authorities, data subject requests or major contract projects, a legal assessment should be undertaken of which obligations apply and how risks can be documented. In practice, early involvement is particularly helpful because data protection requirements can then be integrated directly into processes, contracts and technical concepts instead of having to be remedied later at considerable expense.
Common data protection gaps include outdated privacy notices, missing or inadequate data processing agreements, a record of processing activities that is not kept up to date and unclear deletion periods. New tools, cloud services or AI applications are also often introduced without first assessing the data protection requirements. Missing processes for data subject requests, data protection incidents, employee training and international data transfers are particularly critical.
Regular review, at least once a year and generally before material changes to data processing, is advisable because both the technologies used and the legal position continue to develop. In practice, the late incorporation of data protection requirements into software projects repeatedly causes the introduction of new software not only to be delayed but also to result in significant additional costs. In particular, adjustments should be made promptly after new tools, such as AI applications, are introduced or supervisory practice changes. Assigning clear responsibility for this review within the company makes compliance easier.
Article 6(1)(f) GDPR permits the processing of personal data without the data subject’s consent, provided that three requirements are met cumulatively. First, the controller or a third party must have a legitimate interest; this may be legal, economic or non-material in nature, for example fraud prevention, direct marketing to existing customers or ensuring IT security. In addition, processing must be necessary to pursue that interest, which requires that no other equally effective and, at the same time, more data-protective means is available. Finally, the interests, fundamental rights and freedoms of the data subject must not prevail in the balancing exercise. In practice, the assessment of necessity and the balancing of interests in particular present the central challenges. For conducting the balancing exercise, a three-stage assessment framework has become established in supervisory and advisory practice. In the Purpose Test, it must first be assessed whether the interest pursued is legitimate and has been identified with sufficient specificity. The Necessity Test then assesses whether the processing is actually necessary or whether more data-minimising alternatives are available. In the final Balancing Test, the controller’s interests are weighed against the interests and rights of the data subject. In particular, the data subject’s reasonable expectations under Recital 47 GDPR, the nature of the data processed, the possible effects of the processing and existing safeguards such as pseudonymisation, transparency measures or the ability to object must be taken into account. For a legally sound application, comprehensive documentation of the assessment carried out is advisable, in practice generally in the form of a Legitimate Interest Assessment, which can be referenced in the record of processing activities under Article 30 GDPR. If processing is carried out for direct marketing purposes, the right to object under Article 21(2) GDPR, which may be exercised without giving special reasons, must be expressly pointed out. The transparency obligations are also of particular importance: at the time of data collection, data subjects must be informed clearly and comprehensibly under Article 13 GDPR of the specific purpose of the processing and the legitimate interest pursued. If such information is not provided, the processing may ultimately be unlawful even if the substantive requirements of Article 6(1)(f) GDPR are satisfied. Transparency is therefore not merely an information obligation but an essential prerequisite for lawful processing.
The European Commission’s adequacy decision on the EU-U.S. Data Privacy Framework (DPF) of 10 July 2023 remains in force. Transfers of data to US companies certified under the DPF can therefore generally continue to be based on Article 45 GDPR without additional safeguards being required. Nevertheless, legal uncertainty surrounding the DPF has noticeably increased in recent years. The first direct action against the adequacy decision was dismissed by the General Court of the European Union in the Latombe case; an appeal against that decision is pending before the Court of Justice of the European Union and has not yet been decided. Additional doubts as to the DPF’s long-term durability arise from the discussion concerning the institutional independence of the Federal Trade Commission, whose independent supervisory and enforcement function forms an important basis for the European Commission’s adequacy assessment, since the FTC is primarily responsible for monitoring and enforcing the DPF obligations of certified companies. For legal practice, this means that the DPF can still be used as a valid legal basis at present, but relying exclusively on this mechanism involves increasing risks. Companies should therefore prepare Standard Contractual Clauses, including a Transfer Impact Assessment, as an alternative basis for transfers as a precaution. This avoids a legal gap in the event that the adequacy decision is potentially withdrawn, as occurred following the decisions on Safe Harbor and Privacy Shield. It is also advisable to structure privacy notices, data processing agreements and other documentation so that the basis for the transfer can be changed without extensive amendments to the contracts. In practice, reference is therefore often made both to the DPF as the primary basis and to Standard Contractual Clauses as a subsidiary safeguard. This dual safeguard has become an established pragmatic market standard, particularly when using cloud, SaaS and AI services provided by US companies.
The distinction is of considerable practical importance because it determines which type of contract must be concluded and how data protection responsibility and liability are allocated between the parties. Errors in this classification are among the most common causes of compliance breaches, administrative fine risks and objections by supervisory authorities, particularly in cloud and AI projects. Processing on behalf of a controller within the meaning of Article 28 GDPR exists where a service provider processes personal data exclusively on behalf of and on the instructions of the controller, without pursuing its own purposes. This is typically the case with hosting services, cloud storage or CRM systems. In these cases, a data processing agreement is required that contains the mandatory provisions of Article 28(3) GDPR and, in particular, regulates compliance with instructions and requirements concerning security, confidentiality and the use of sub-processors. By contrast, joint controllership under Article 26 GDPR exists where two or more entities jointly determine the purposes and means of processing. This situation is becoming increasingly important in connection with AI services: if the provider uses the processed data not solely to provide services to the customer but also for its own purposes, for example to improve models, produce analyses or use the data as training data, this will generally weigh against a purely processing-on-behalf-of-a-controller arrangement. In the Fashion ID decision (judgment of 29 July 2019, C-40/17), the Court of Justice of the European Union clarified that joint controllership can arise as soon as the parties take joint decisions in relation to individual processing steps; it is not necessary for both parties to have access to all data or to be involved to the same extent. The consequences differ significantly: whereas processing on behalf of a controller requires a data processing agreement containing provisions on compliance with instructions, sub-processors and obligations to delete and return data, joint controllership requires an agreement under Article 26 GDPR. This agreement must specify which party fulfils the information obligations towards data subjects and how data subject rights, such as rights of access, erasure or rectification, are handled; in addition, the substance of the agreement must be made available to data subjects. Particularly with AI providers, the contractual documents should be examined with great care. Providers not infrequently describe themselves as processors in their data processing agreements, while reserving extensive rights in their standard terms and conditions or privacy policies to use the data themselves. Such provisions may conflict with the allocation of roles contemplated by the contract and make a different assessment under data protection law necessary.

