Services
Data protection consulting
We see our task as making a project possible and not shaping data protection into a brake on it. To that end we assess the risks realistically and reduce them until the project is defensible. Not every risk has to be eliminated.
Where consulting places its emphasis depends on the organisation
Advice that is right for a corporate group remains useless for an association, and the same holds the other way round. We therefore distinguish three situations.
Little time, no legal department, no internal data protection officer. The risk of a fine exists all the same.
What counts here is which pitfalls can be removed with modest effort. Those are usually the documents with external effect, meaning privacy notices and consent forms, and furthermore the securing of new software before it goes live.
A technology nobody has yet classified in legal terms, and a product whose design can hardly be changed later.
The return comes early here. What is built to be privacy-friendly during development costs nothing, and what has to be rebuilt afterwards costs twice. Our academic background helps where no settled view on a technology exists yet.
Distributed responsibilities, intra-group transfers, works councils, IT security and procurement with requirements of their own.
The legal question is rarely the hardest one here. What remains harder is finding an answer that every unit involved will support.
The same assessment has to hold up in three languages
An answer that is legally correct is not yet a basis for a decision. Three units test it against three different standards, and whoever serves only one of them gets an answer that fails at the other two.
Legal department
Tests the reasoning. It needs the provision, the source and the balancing, not the result on its own.
Management
Decides on the project. It needs the residual risk in one sentence and, next to it, what the alternatives cost.
IT
Implements. It needs the concrete requirement for system and configuration, not a reference to an article.
Mediating between these units we count as part of the task, not among its obstacles.
What a project typically stalls on, and how that can be resolved, is set out under We have something planned.
Three consulting formats, and what separates them
Our method has four steps, namely recording the facts, assessing the legal position, putting forward options and supporting the implementation. The three consulting formats differ in which of those steps they cover and where the result ends up.
Advice
Covers the first three steps without a document arising. The format for decisions during ongoing operations. To advice
Written assessment
Covers the first three steps and puts them on paper. The answer becomes something that can be produced. Responsibility for the judgement moves to us. To the written assessment
Audit
Covers the first step. It establishes where things stand and orders the deviations by their weight. To the audit
Advice during ongoing operations
Most questions call for a placement rather than any notable formalities.
Three situations in which a placement is enough
Liste zu erledigender Punkte
- A contract is on the table and is meant to be signed
- A department would like to introduce a tool
- A request from a data subject has arrived and the deadline is running
In those situations what matters first is a quick assessment, if need be in speech or as an informal email. Where a question turns out to be larger than expected, we say that too and suggest how to go deeper.
Not possible because of data protection? Usually it is.
Written assessment
An assessment writes the answer down, makes the reasoning transparent and shifts responsibility for the judgement onto us. That turns it into an instrument which releases a project and which can be put on the table, before management, a supervisory authority or a contracting partner.
The structure, in three steps
The facts
Together we record what is actually being discussed. Which data, which purposes, which parties, which systems.
The legal position
The analysis, drawing on the GDPR, the BDSG, the state data protection acts and, depending on the facts, further provisions.
Recommendation
The options with their respective risks, ordered by what we consider preferable.
3 von 3
The first step is the one most often underestimated. An imprecise description of the processing makes every later evaluation worthless, and in data protection law much turns on details that at first look incidental.
A new business model, a change of IT system, an acquisition. Often objections have already been raised and the project has stalled. In that situation an assessment is less a piece of information than a release. It states what is possible under which conditions and takes responsibility for that judgement away from the people carrying the project. In most cases that is what clears the blockage.
A short assessment of a defined question is a different undertaking from the review of a complete business model. We agree the scope beforehand and work to an agreed fixed price.
Audit
A data protection audit establishes the current state and names the deviations from the requirements that apply to it. It comes at the beginning, when nobody in the organisation knows that state precisely, and recurrently, when a review is wanted.
Four occasions we see regularly
Liste zu erledigender Punkte
- Your own position is unknown, and it should be known before a decision
- A new product or procedure is to be reviewed before it is introduced
- A contracting partner or a customer requires evidence
- A certification or a recurring review is due
The first two are the more frequent occasion. Both share the same situation, namely that a decision is pending and the basis for it is missing.
Four steps
Step 1
Agree the scope
What is reviewed, to what end and against which requirements.
Step 2
Fact finding
On site for the whole organisation, remote for single procedures or products.
Step 3
Evaluation
Deviations are ordered by their weight, not by the order in which they were found.
Step 4
Report
Findings and recommendations, usable towards third parties.
At the end there is a report. It names the deviations with their weight, distinguishing the urgent from the secondary, and gives a recommendation for each. It can be used with contracting partners and customers.
Where a legal opinion is required, we carry out assessments and audits in partnership with lexICT legal Rechtsanwaltsgesellschaft.
Frequently asked questions
How does an audit work?
That depends on the scope. An audit of the entire data protection setup usually takes place on site. Individual procedures or products can also be reviewed remotely.
How long does an audit take?
A short audit is possible in about two hours, a full one takes several days. The scope and the size of the organisation are what matter.
What do we get at the end of an audit?
A report naming the deviations with their weight and giving concrete recommendations. It can be used with contracting partners and customers.
What separates advice, a written assessment and an audit?
The starting point and the result. An audit establishes the current state where that state is unknown. A written assessment examines a particular question and puts the answer on paper. Advice during ongoing operations places a situation without producing a document.
Related pages
We are planning something
Why the selection is already the data protection decision and which points in time a project plan cannot move.
Data protection impact assessment
Why the decision against an impact assessment needs reasons of its own, when it comes too late, and whose risk it actually assesses.
Transfer impact assessment
Where the duty comes from although the name appears in no provision, where the third-country element actually sits, and how far the assessment has to reach.
Reviewing processing agreements
Why the role follows the facts and not the contract, how far the chain of sub-processors reaches, and what an annex on measures has to deliver.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.