activelawSpecialty Areas
Data Protection

Data Protection in Hannover. Turning rules into processes.

We build data protection governance, review contracts and transfers, and guide you through breaches, access requests and regulatory proceedings.

Softwareentwickler zeigt auf einen Bildschirm mit Programmcode am Arbeitsplatz
Data protection governance

From the record to a process that works

Data protection rarely fails for want of documents; it fails because nobody uses them. We turn the requirements into routines that survive day-to-day operations and stand up in an inspection.

  • Building and reworking a data protection management system
  • Record of processing activities, retention schedule and deletion concept
  • Technical and organisational measures, agreed with the IT function
  • Appointing the data protection officer and fitting the role into the organisation, internally or externally
  • The personal liability of the management for the organisation is handled by our practice area Corporate Law
Processors and suppliers

Supplier agreements that hold when it matters

Anyone processing data on your behalf needs an agreement for it, in place before the processing begins. Where it is missing, that is a breach carrying a fine in its own right, whether or not anything has gone wrong.

  • Processor agreements, and review of the forms put forward by the provider
  • Drawing the line between processing, joint controllership and acting in one own right
  • Joint controllership arrangements, for instance for audience measurement on social networks
  • Control of sub-processors and supplier audits
  • The underlying cloud and SaaS agreements are drafted by our practice area IT Law
International transfers

Putting transfers to third countries on a footing

As soon as a supplier sits outside the EU, or has access from there, the transfer needs a basis of its own. An adequacy decision can fall away, so a fallback belongs in the contract.

  • Reviewing the transfer routes, including remote access from a third country
  • EU standard contractual clauses and the transfer impact assessment that goes with them
  • Reliance on adequacy decisions, including the Data Privacy Framework
  • Binding corporate rules within a group
  • The international supply and services agreements behind them are handled by our practice area Commercial Law
Impact assessment and AI

Assessing processing that carries high risk

Where processing carries a high risk, the GDPR requires an impact assessment before it starts. With AI, the training data, the outputs and the intellectual property have to be assessed separately.

  • Risk analysis and data protection impact assessment, including consultation with the authority
  • Assessment of AI systems, profiling and automated decisions
  • Legal bases for using existing data holdings for new purposes
  • Anonymisation and pseudonymisation as a route out of the scope of the rules
  • Rights in training data and in outputs are reviewed by our practice area Intellectual Property
Breaches and regulatory proceedings

Meeting the deadline, conducting the proceedings

The 72 hours run from awareness, not from the end of the investigation. A report that says openly what is still unclear is therefore better than a complete one that comes late.

  • Assessing whether the breach is notifiable and preparing the report to the authority
  • Informing the individuals concerned where the risk is high, and in what form
  • Internal documentation of breaches that are not notifiable as well
  • Acting in regulatory and fine proceedings, including the hearing
  • Whether the cyber policy covers the loss is checked by our practice area Insurance Law
Employee data and individual rights

Data in the HR function and requests from individuals

In the HR function data protection and employment law meet directly. Access requests often arise out of a live conflict, so the answer has to fit the employment position in substance and in tone.

  • Recruitment, retention periods and the handling of rejections
  • Subject access requests, including the limits where the right is invoked abusively
  • Erasure, rectification and objection, including after the employment has ended
  • Monitoring at work, works agreements and the limits of surveillance
  • The employment law side of these cases is led by our practice area Employment Law

Find the right adviser

No items found.
Frequently Asked Questions

Answers to the most important questions

Can’t find your question here? Please get in touch! We’ll usually get back to you within two working days.

Ask question
How quickly must a data breach be reported?
add

Within 72 hours of becoming aware of it, to the competent supervisory authority. The report is only dispensed with where the breach is unlikely to result in a risk to the individuals concerned. Where the risk is high they must be informed as well. Every breach is documented internally, even where no report is made.

Do I need a processor agreement with every supplier?
add

With every supplier that processes personal data on your behalf and on your instructions, such as cloud providers, IT services or payroll. You do not need one with bodies acting in their own right, such as tax advisers or banks. Where the agreement is missing, that is itself a breach carrying a fine.

How high can fines under the GDPR be?
add

Up to 20 million euros, or up to four per cent of worldwide annual turnover, whichever is higher. In practice the authorities look to the seriousness, the duration and the degree of fault, and to how far the company cooperated. Claims for damages by the individuals concerned come on top.

Do we need a data protection officer?
add

In Germany from 20 people permanently engaged in the automated processing of personal data. Regardless of that number, the duty also arises where an impact assessment is required or where special categories of data are part of the core activity. The role may be filled internally or externally.

What must a response to a subject access request contain?
add

A copy of the data processed, together with the purposes, the recipients, the retention period and the source. The period is one month and can be extended by two months for complex requests, provided the individual is told. The rights of third parties must be protected, for instance by redaction.

For how long may application documents be kept?
add

Six months after the rejection is the usual period. It follows from the two-month period for bringing claims under the German equal treatment legislation, plus an allowance for service and proceedings. Anyone wishing to keep the documents longer needs consent for that.

What to expect

How we work at activelaw

01

Your information

You explain your situation to us, and we’ll review your documents. We’ll provide you with an initial assessment of your case as soon as possible.

02

Our promise

We advise and represent you in all legal matters until your case has been successfully resolved.

03

Your opportunities

Our experts will advise you on your chances of success and the specific options available in your case.