Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Services

Data protection consulting

We see our task as making a project possible and not shaping data protection into a brake on it. To that end we assess the risks realistically and reduce them until the project is defensible. Not every risk has to be eliminated.

Where consulting places its emphasis depends on the organisation

Advice that is right for a corporate group remains useless for an association, and the same holds the other way round. We therefore distinguish three situations.

Little time, no legal department, no internal data protection officer. The risk of a fine exists all the same.

What counts here is which pitfalls can be removed with modest effort. Those are usually the documents with external effect, meaning privacy notices and consent forms, and furthermore the securing of new software before it goes live.

A technology nobody has yet classified in legal terms, and a product whose design can hardly be changed later.

The return comes early here. What is built to be privacy-friendly during development costs nothing, and what has to be rebuilt afterwards costs twice. Our academic background helps where no settled view on a technology exists yet.

Distributed responsibilities, intra-group transfers, works councils, IT security and procurement with requirements of their own.

The legal question is rarely the hardest one here. What remains harder is finding an answer that every unit involved will support.

The same assessment has to hold up in three languages

An answer that is legally correct is not yet a basis for a decision. Three units test it against three different standards, and whoever serves only one of them gets an answer that fails at the other two.

Legal department

Tests the reasoning. It needs the provision, the source and the balancing, not the result on its own.

Management

Decides on the project. It needs the residual risk in one sentence and, next to it, what the alternatives cost.

IT

Implements. It needs the concrete requirement for system and configuration, not a reference to an article.

Mediating between these units we count as part of the task, not among its obstacles.

What a project typically stalls on, and how that can be resolved, is set out under We have something planned.

Three consulting formats, and what separates them

Our method has four steps, namely recording the facts, assessing the legal position, putting forward options and supporting the implementation. The three consulting formats differ in which of those steps they cover and where the result ends up.

Advice during ongoing operations

Most questions call for a placement rather than any notable formalities.

Three situations in which a placement is enough

Liste zu erledigender Punkte

  • A contract is on the table and is meant to be signed
  • A department would like to introduce a tool
  • A request from a data subject has arrived and the deadline is running

In those situations what matters first is a quick assessment, if need be in speech or as an informal email. Where a question turns out to be larger than expected, we say that too and suggest how to go deeper.

Not possible because of data protection? Usually it is.

Written assessment

An assessment writes the answer down, makes the reasoning transparent and shifts responsibility for the judgement onto us. That turns it into an instrument which releases a project and which can be put on the table, before management, a supervisory authority or a contracting partner.

The structure, in three steps

  1. The facts

    Together we record what is actually being discussed. Which data, which purposes, which parties, which systems.

  2. The legal position

    The analysis, drawing on the GDPR, the BDSG, the state data protection acts and, depending on the facts, further provisions.

  3. Recommendation

    The options with their respective risks, ordered by what we consider preferable.

3 von 3

The first step is the one most often underestimated. An imprecise description of the processing makes every later evaluation worthless, and in data protection law much turns on details that at first look incidental.

A new business model, a change of IT system, an acquisition. Often objections have already been raised and the project has stalled. In that situation an assessment is less a piece of information than a release. It states what is possible under which conditions and takes responsibility for that judgement away from the people carrying the project. In most cases that is what clears the blockage.

A short assessment of a defined question is a different undertaking from the review of a complete business model. We agree the scope beforehand and work to an agreed fixed price.

Audit

A data protection audit establishes the current state and names the deviations from the requirements that apply to it. It comes at the beginning, when nobody in the organisation knows that state precisely, and recurrently, when a review is wanted.

Four occasions we see regularly

Liste zu erledigender Punkte

  • Your own position is unknown, and it should be known before a decision
  • A new product or procedure is to be reviewed before it is introduced
  • A contracting partner or a customer requires evidence
  • A certification or a recurring review is due

The first two are the more frequent occasion. Both share the same situation, namely that a decision is pending and the basis for it is missing.

Four steps

  1. Step 1

    Agree the scope

    What is reviewed, to what end and against which requirements.

  2. Step 2

    Fact finding

    On site for the whole organisation, remote for single procedures or products.

  3. Step 3

    Evaluation

    Deviations are ordered by their weight, not by the order in which they were found.

  4. Step 4

    Report

    Findings and recommendations, usable towards third parties.

At the end there is a report. It names the deviations with their weight, distinguishing the urgent from the secondary, and gives a recommendation for each. It can be used with contracting partners and customers.

Where a legal opinion is required, we carry out assessments and audits in partnership with lexICT legal Rechtsanwaltsgesellschaft.

Frequently asked questions

How does an audit work?

That depends on the scope. An audit of the entire data protection setup usually takes place on site. Individual procedures or products can also be reviewed remotely.

How long does an audit take?

A short audit is possible in about two hours, a full one takes several days. The scope and the size of the organisation are what matter.

What do we get at the end of an audit?

A report naming the deviations with their weight and giving concrete recommendations. It can be used with contracting partners and customers.

What separates advice, a written assessment and an audit?

The starting point and the result. An audit establishes the current state where that state is unknown. A written assessment examines a particular question and puts the answer on paper. Advice during ongoing operations places a situation without producing a document.

Related pages

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.

More services