Fields of law
Practical questions
Three fields of law that almost always appear together in a project. Below each are the questions that reach us most often.
Data protection
Every processing operation needs a legal basis under Art. 6(1) GDPR, and the choice decides more than admissibility. Withdrawal, objection, the information duties and the question whether the purpose can still be changed later all hang on it. What follows is the continuing upkeep of that state, and it comes easier the more carefully the groundwork was done.
Incidents and requests
Access requests
What the copy under Art. 15(3) GDPR covers, how to handle the rights of others, and what the Court of Justice held in 2026 on abusive requests.
Data protection and security incidents
A personal data breach leaves 72 hours for investigation, defence and notification. When a duty to notify arises and which duties run alongside it.
The supervisory authority is asking
What sets the tone and scope of the reply, what the underlying reason says about the procedure, and why a complaint rarely ends in a fine.
Legal basis and admissibility
We are planning something
Why the selection is already the data protection decision and which points in time a project plan cannot move.
Automated individual decisions
When pre-selection in recruitment is already the decision, which exception then applies, and what has to be observed alongside Art. 22 GDPR.
Special categories of data
Where health data arises in the employment relationship, which permission covers it, and which additional measures section 22(2) BDSG requires.
Transfer impact assessment
Where the duty comes from although the name appears in no provision, where the third-country element actually sits, and how far the assessment has to reach.
Data protection impact assessment
Why the decision against an impact assessment needs reasons of its own, when it comes too late, and whose risk it actually assesses.
Contracts and controllership
Reviewing processing agreements
Why the role follows the facts and not the contract, how far the chain of sub-processors reaches, and what an annex on measures has to deliver.
Joint controllership
Why there is no group privilege, when cooperation turns into joint controllership, and what the arrangement has to deliver.
Works agreements as a legal basis
Why co-determination and legal basis are two questions, and why agreements predating the GDPR no longer cover today's systems.
Ongoing duties and records
Record of processing activities
Art. 30 GDPR requires a record. What belongs in it, how far the entries have to go and what its upkeep in the organisation depends on.
Information duties
Where separate privacy notices are needed, which items belong in them depending on where the data came from, and what makes a notice go stale.
Consent forms
When consent is the right legal basis at all, why one checkbox for several purposes is not enough, and what withdrawal requires.
Retention and erasure
Why the duty to erase exists without a request, why ten years does not apply to everything, and where legacy systems undo your own retention periods.
Systems in use
Microsoft 365
Why the question of principle is settled, which settings decide on lawfulness, and where the third-country element actually sits in day-to-day operation.
HR management systems
Why access rights are the real assessment, when a metric turns into behavioural monitoring, and what a group-wide roll-out requires in addition.
Video surveillance
Why section 4 BDSG does not apply to businesses, what the balancing exercise requires, and where the field of view and the signage go wrong.
Cookies and tracking
Why consent under sec. 25 TDDDG is not the legal basis for the processing, when a banner steers unlawfully, and what a comparison with the site reveals.
Sector-specific requirements
Healthcare
Why professional secrecy creates a separate criminal liability, and why the same outsourcing is assessed differently in two German states.
Esports and gaming
Roles between club, federation and league, the age limit in Art. 8 GDPR, streaming alongside image rights, and the automated ban issued by anti-cheat.
Research
Why consent is rarely the best basis, what the research privilege does, and when pseudonymised data are no longer personal at the partner.
Related topics
Microsoft 365 Copilot
Why section 26(1) BDSG is a shaky legal basis, when the works council has to co-determine, and which three questions the contract has to answer.
Technical and organisational measures
What Art. 32 GDPR requires, why a list of measures does not replace an assessment and how the evidence can be produced.
ChatGPT
Why the employer is the controller even for a private account, what is missing without a contract under Art. 28 GDPR, and what a governed access changes.
SOC and SIEM
What would have to be settled when running a SIEM and engaging a SOC. Legal basis, co-determination, retention and third party access.
AI and works council participation
When section 87(1) no. 6 BetrVG applies to AI, why the duty to inform starts earlier, and what section 80(3) means for experts.
AI governance
Why the roles are not free to allocate, why the data protection officer cannot approve, and what the approval route has to settle before deployment.
Claude
Why the purpose set at introduction limits everything after it, and why every tool connection is a processing operation with a basis of its own.
Using AI in line with data protection law
Why training and use are two processing operations with two legal bases, and why the roles under the AI Act are not those under the GDPR.
Transcription and meeting assistants
Why section 201 of the Criminal Code governs the recording rather than consent, how the information route differs per group, and when the audio has to go.
Artificial intelligence
Classification comes before every duty, into the categories set out in the AI Act. It separates prohibited practices, high-risk systems and everything else. Beside those sit the general-purpose AI models as a category of their own. Equally relevant is the role as provider or deployer.
Classification and role
AI Act risk classification
Why classification under Art. 6 AI Act precedes every duty and how the fundamental rights impact assessment attaches to the data protection impact assessment.
Transparency duties under Art. 50 AI Act
Why Art. 50 AI Act has two different addressees, and how an organisation becomes a provider itself without having developed a model.
Using AI in line with data protection law
Why training and use are two processing operations with two legal bases, and why the roles under the AI Act are not those under the GDPR.
Duties that cut across
AI literacy under Art. 4 AI Act
What Art. 4 AI Act actually requires, why the necessary training scope follows the system in use, and how compliance can later be shown.
The AI policy at work
Why an organisation answers for tools it knows nothing about, why a ban relocates the use, and why the policy itself is subject to co-determination.
AI governance
Why the roles are not free to allocate, why the data protection officer cannot approve, and what the approval route has to settle before deployment.
Individual systems in use
Microsoft 365 Copilot
Why section 26(1) BDSG is a shaky legal basis, when the works council has to co-determine, and which three questions the contract has to answer.
ChatGPT
Why the employer is the controller even for a private account, what is missing without a contract under Art. 28 GDPR, and what a governed access changes.
Claude
Why the purpose set at introduction limits everything after it, and why every tool connection is a processing operation with a basis of its own.
Transcription and meeting assistants
Why section 201 of the Criminal Code governs the recording rather than consent, how the information route differs per group, and when the audio has to go.
Particular fields of use
AI and works council participation
When section 87(1) no. 6 BetrVG applies to AI, why the duty to inform starts earlier, and what section 80(3) means for experts.
AI in public administration
Why authorities cannot rely on a balancing exercise, when a decision may issue fully automatically, and whom the fundamental rights impact assessment binds.
Information security
Information security law consists of a multitude of separate rules. Art. 32 GDPR alone reaches everyone who processes personal data. The others attach to sector and size, to a critical installation or to the manufacturer role. None of them names a measure, because all four require appropriateness and the state of the art. Standards such as ISO 27001 and the German IT-Grundschutz fill that gap without being binding themselves.
Scope and addressees
Checking whether NIS2 applies
Why the federal office does not tell you that you are in scope, what the classification turns on, and from which moment the three months for registration run.
Cyber Resilience Act
How a business becomes a manufacturer under Art. 3(13), Art. 21 and Art. 22 CRA, when a modification is substantial, and since when the reporting duty applies.
Supply chain security
How far section 30(2) no. 4 BSIG reaches into the chain, why only the data protection chain continues by law, and what remains negotiable.
Implementation and evidence
Technical and organisational measures
What Art. 32 GDPR requires, why a list of measures does not replace an assessment and how the evidence can be produced.
Implementing NIS2
What the ten subjects of section 30 BSIG require, what the management owes personally, and why a second clock runs alongside the report to the federal office.
SOC and SIEM
What would have to be settled when running a SIEM and engaging a SOC. Legal basis, co-determination, retention and third party access.
And the services for it
A practical question says what it is about. The shape the answer arrives in is under services.
To the services