Data (Protection) Law

The Internet of Things, Big Data, and the deployment of AI are transforming data into a valuable economic asset. The volume of digital data generated in industrial and commercial contexts is growing exponentially, and the legal challenges are mounting in parallel. The appetite for digital data extends far beyond companies with data-driven business models in the media, ICT, or sports sectors, being present in businesses operating in healthcare, transport, and financial services. The confidential handling, protection, integrity, and security of data are therefore gaining ever greater importance, particularly regarding the lawful processing of digitized personal data. Innovative digital technologies for data collection and processing enable companies to enhance their services and offerings, analyze customer interests and purchasing behavior through personalized profiles, or deliver targeted advertising. 

Any use of data today must satisfy the requirements of data protection law and information security. The primary legal framework is constituted by the General Data Protection Regulation (EU) 2016/679 (GDPR), the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG), and the Act on Data Protection and Privacy in Telecommunications and Digital Services (TDDDG). In an environment of constant regulatory change and landmark rulings from the Court of Justice of the European Union – such as its judgment on international data transfers (“Schrems II”) – legal certainty demands proactive attention to ongoing legislative developments and compliance standards. 

Data protection begins at the stage of technical design (Privacy by Design) and default settings (Privacy by Default). When procuring and implementing IT solutions, we ensure that these meet the requirements for anonymisation, pseudonymisation, and erasure and documentation frameworks. Only through early legal involvement can liability risks and the severe sanctions under the GDPR – fines of up to EUR 20 million or 4% of global annual turnover – be effectively avoided.  

Beyond the GDPR, a new generation of EU regulations is shaping the handling of data and establishing an integrated European data space: 

Data Act (EU) 2023/2854: This Regulation establishes entirely new rights of access to and use of data generated by connected devices (IoT). It governs data sharing between manufacturers and users, prohibits unfair contractual terms in data licensing agreements, and facilitates switching between cloud service providers through interoperability standards. 

Data Governance Act (EU) 2022/868 (DGA): As a complement to the Open Data Directive, the DGA promotes data availability through secure sharing models, data intermediaries, and the re-use of public sector datasets. 

Digital Services Act (EU) 2022/2065 (DSA) and Digital Markets Act (EU) 2022/1925 (DMA): While the DSA enhances the protection of user rights on online platforms through transparency and due diligence obligations, the DMA addresses data processing by systemically significant “gatekeepers.” It enforces fair competitive conditions through rules on interoperability and data portability. 

We support you in strategically navigating this complex interplay of new EU data regulations, designing your processes in a legally compliant manner, and managing data as a valuable economic asset with confidence. We also keep a close eye on legislative developments on your behalf: the European Commission is planning to consolidate a significant portion of data-related provisions within the Data Act and to improve its interaction with the GDPR in the digital age.

The right to data portability under Article 20 GDPR reinforces the autonomy of data subjects: users are entitled to receive their personal data in a structured, commonly used, and machine-readable format, or to obtain the direct transmission of that data to another controller. This right is designed primarily to facilitate seamless switching between providers and to promote the interoperability of digital services. 

The exercise of this right is, however, subject to clear legal limits. It does not apply where processing is carried out in the performance of a task in the public interest or in the exercise of official authority. Furthermore, portability must not adversely affect the rights and freedoms of third parties. 

Under Articles 13 and 14 GDPR, companies are required to proactively inform data subjects of the existence of this right. A key compliance consideration: the right to erasure (the “right to be forgotten” under Article 17 GDPR) is unaffected by this right and must be upheld concurrently. We assist you in implementing efficient processes for data transfers and ensuring that the requisite information obligations are met in a legally sound manner. 

Data protection law safeguards the individual’s right of personality against interference arising from the processing of personal data (Article 1 GDPR). As a general rule, any processing of personal data is only permissible where a statutory basis or valid consent exists. For media companies, however, the media privilege opens up a significant area of latitude: editorial offices, broadcasting organizations, and online media outlets may, under certain conditions, use data without consent in order to fulfil their constitutionally guaranteed journalistic function. 

Giving effect to the opening clause enshrined in Article 85 GDPR requires, in practice, a nuanced balancing exercise between the right to informational self-determination on the one hand, and freedom of expression and freedom of information on the other. This necessary weighing of competing interests applies equally to the publication of images under the Act on the Copyright of Works of Visual Arts (Kunsturhebergesetz – KUG). We assist media houses and content creators in navigating these legal boundaries with confidence, securing journalistic work through the protection afforded by the media privilege, and – where conflicts arise between data protection and press freedom – constructing a robust legal position vis-à-vis data subjects and supervisory authorities. 

FRE Leistungen Unterseiten Motiv 0

What we do for you

We see ourselves as your partner for data protection, security, and data strategy. Combining legal excellence with deep technical understanding, we guide your organization through all processes relating to data protection and information security. Our goal is your comprehensive legal protection. Working closely with you, we develop tailored legal, technical, and organizational measures precisely calibrated to your specific data flows. The frameworks we develop together are then advocated and negotiated on your behalf with the competent supervisory authorities. 

In doing so, we regard data protection not as a brake on innovation, but as the foundation for modern business models. We support your operations across all matters relating to: 

Digitalisation and the cloud – the legally sound introduction of cloud services, big data analytics, and AI technologies; 

Building and scaling data-driven business models and CRM systems; 

The legal safeguarding of international data flows and the structuring of complex data processing agreements (Article 28 GDPR); 

Establishing efficient compliance management systems and automated access and notification processes for data subjects. 

We represent your interests resolutely before supervisory authorities, consumer protection and competition associations, and in court. To ensure your team is equipped for regulatory demands over the long term, our firm – including in collaboration with specialist technical experts – provides ongoing practical training and in-house seminars on current topics in data protection and information security.

Who we work for

Our clients in the area of data protection on the right come from all industries. They include medium-sized and large companies from the ICT and media industry, the construction industry, personnel service providers, content aggregators, specialized portal providers or startups (such as app developers). We also advise local authorities on data protection issues.

Our focus

  • European data protection Law (GDPR)
  • National data protection law (BDSG)
  • ePrivacy regulations
  • Interstate Treaty on Media & Broadcasting
  • State media and state press laws
  • Telemedia Law
  • Telecommunications Law
  • Right to own picture