Customer data, employee data, website and new software: Data protection affects many decisions in companies. We help you to clarify the legal requirements for specific processing processes and translate them into understandable agreements, information and responsibilities.
Lawrence Thiemann advises and represents companies and public figures in press and speech law, copyright and media law, and competition law. His areas of focus include accompanying critical reporting and protecting reputation. He also advises and represents in employment law and data protection law.
Dr. Nik Sarafi represents creators, streamers and other parties involved in press and speech law disputes. Other focal areas include media and gaming law as well as digital business models. He is responsible for the direction of the law firm.
A privacy policy alone does not yet describe a resilient organization. The decisive factor is which information is actually processed, where it comes from and who can access it. Together with you, we record the facts and determine the scope of the audit. The focus can be on individual services as well as on existing documents, data subject inquiries or communication with a supervisory authority.
01
AI tools & internal knowledge databases
We review the handling of personal data in prompts, documents and AI-based knowledge systems. Provider roles, access rights and, if applicable, a data protection impact assessment are related to the specific use.
We review data protection information and assist you in legally classifying your processing operations. This includes customer management, applications and employee data. Templates are tailored to the actual process; technical and organizational facts must be described comprehensibly for this purpose.
03
Service providers, websites and tools
New software and external service providers raise questions about roles, contracts and data flows. We review the documents provided and assist with the legal evaluation. In the case of websites, we look at the specific services used and the associated information and consent processes.
In the event of a request for information, a complaint or a data protection incident, we support the legal review and further communication. For classification, we need the complete process, including reactions that have already taken place. Let us know when a letter includes a deadline.
The first request
These documents help with the exam.
First, briefly describe the facts. We will coordinate with you how to submit further documents.
Description of data processing
Existing data protection documents
Contracts with affected service providers
Requests, letters and previous answers
Working with us
From the request to the mandate.
Before the assignment, we agree on the scope of services and remuneration. When taking over, we will name your legal contact person.
01
inquiry
They describe the facts, the parties involved and known deadlines.
02
Acceptance of your matter
We agree on performance and compensation and name your contact person.
03
machining
The responsible lawyer will check your documents and coordinate the procedure with you.
Data protection law
Questions & answers.
Are you also testing individual tools?
Yes Name the tool, planned use, and processed data. Relevant provider documents and settings help to determine the legal issues of the specific deployment.
Can existing documents be revised?
Yes A revision should be based on actual processes. We clarify which processes the documents should represent and whether existing information still complies with operational practice.
How do I make a request about an incident?
First, describe the nature, time and known scope of the incident without any unnecessary individual personal information. We will clarify the possible takeover and a suitable route for the required documents.
English translation of our German website. Statutory references concern German or EU law. The German original remains available through the language selector.