Practice areas › IT Law & Data Protection
Core practice

IT Law & Data Protection

Digital business models need contracts and a data protection setup that survives scrutiny. We put that in place before a regulator or a counterparty asks.

We advise companies on software and IT services contracts and on implementing the GDPR in day-to-day operations — from the question of which legal basis under Art. 6 GDPR a processing activity rests on, through to representation in fine proceedings under Art. 83 GDPR. We draft contracts so that responsibilities between customer and provider are clearly allocated, and bring data protection documentation to a standard that holds up in an audit.

Statutory references follow German law; the section numbers in brackets point to the German provision so that you can pass them straight to in-house counsel or an auditor.

Diese Seite auf Deutsch ›

How we help

  • Implementing the GDPRRecords of processing (Art. 30), legal bases (Art. 6) and information duties (Arts. 13/14 GDPR).
  • Contracts with IT providersReviewing and drafting data processing agreements (Art. 28 GDPR), including sub-processors.
  • Handling a data breachNotification to the supervisory authority within 72 hours (Art. 33) and to data subjects (Art. 34 GDPR).
  • Software & cloud contractsSaaS, maintenance and SLAs, service vs. works contract (secs. 631, 611 BGB) and licence rights (secs. 69a et seq. UrhG).
  • Defending against finesRepresentation in supervisory authority proceedings (Art. 83 GDPR) and defence against damages claims (Art. 82 GDPR).
  • AI & trackingCookie consent (sec. 25 TDDDG), email marketing (sec. 7 UWG) and obligations under the AI Act.

Is this your situation?

Describe it to us. We usually reply within one working day.