At the latest since the General Data Protection Regulation (DSGVO/GDPR), data protection has been a core compliance requirement for every company. Processing personal data lawfully — from customers to business partners to a company's own employees — and maintaining an appropriate level of protection present companies with growing challenges, not least because of the increasing use of artificial intelligence.
In parallel, a second body of rules has emerged: data law. With the Data Act (Regulation 2023/2854, applicable since September 2025), the Data Governance Act and adjacent legislation, it governs who may use, share and make data available — and treats personal and non-personal data on an equal footing, whereas data protection law applies only where data relates to an identifiable person. Where the Data Act and the GDPR meet, legally challenging overlaps arise.
Legal assessment of processes relevant under data protection law in your company — particularly in software procurement, in contractual relationships with business partners and processors, and in international data transfers. We examine whether your processing operations hold up under the GDPR — before someone else does.
02
Documentation
Support in implementing the extensive statutory documentation obligations: records of processing activities, data protection impact assessments, data processing agreements, technical and organizational measures. Prepared in a practicable way — not inflated.
03
Data law
Advice on the new Data Act and the Data Governance Act: data access rights for connected products, B2B data contracts, cloud-switching clauses, data intermediaries and data spaces. Anyone who generates or exploits machine, vehicle or IoT data has been subject to the Data Act since September 2025.
04
Risk management
Support in gray areas that have not yet been conclusively resolved — training data for AI systems, third-country transfers after Schrems II, identifiability in pseudonymized data, interfaces between the GDPR, the AI Act and the Data Act. Naming risks, weighing them, managing them.
Two legal regimes, one subject area
The GDPR governs what you must protect. Data law governs what you must make accessible.
The compliance triad
Three pillars.
Ensuring that personal data is processed lawfully and data subjects are properly informed.
Implementing technical and organizational measures.
Comprehensively documenting the processing of personal data.
Focus areas & mandates.
[ Selection ]
Employee data Employee monitoring
Employee data protection and employee monitoring
Data protection in the employment context is among the most conflict-prone areas of GDPR application. We advise companies on employee monitoring, on the introduction of technical systems with surveillance effects, and on the legally sound design of recruiting, HR and performance processes.
The tension between § 26 BDSG (German Federal Data Protection Act), the GDPR and § 87 Abs. 1 Nr. 6 BetrVG (German Works Constitution Act) is an advisory topic in its own right — and it grows with every new AI tool in HR.
Works councils Codetermination
Works councils: data protection training and codetermination advice
Works councils bear a special responsibility when new IT and AI systems are introduced — codetermination under the BetrVG meets data protection under the GDPR. Both areas require works councils to keep their knowledge current — a need that recent legislative reforms have expanded considerably.
We offer training for works council bodies on data protection and employee monitoring — also in combination with our AI training for works councils, when the council must at the same time assess new AI systems in the workplace. In addition, we advise in ongoing codetermination procedures and act as external experts where we are retained for that purpose.
Data Act Connected products
Data Act compliance for manufacturers and providers
Manufacturers of connected products and providers of related services have had to meet the requirements of the Data Act since September 12, 2025 — data access rights for users and third-party companies, data-sharing obligations, updates to standard terms and conditions, cloud-switching clauses. For products placed on the market after September 12, 2026, the “access by design” obligation applies in addition.
We assess the scope of application, draft contracts and develop compliance concepts — specifically for automotive, mechanical engineering and IoT companies with whom we already work in other client matters.
In-house Remote training
Training for companies and legal departments
Tailored formats on the GDPR, the Data Act, employee data protection and data protection impact assessments — from a basic module for mixed employee groups to advanced sessions for data protection officers and legal departments. Dates on request via our office.
Data subject rights Art. 15 & 17 DSGVO
Data subject rights — access, erasure, delisting
We assert data subject rights under the GDPR — access (Art. 15) as well as erasure and delisting (Art. 17), including against search engines. We cover the "right to be forgotten" and action against inaccurate search results in depth under Social media law.