Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Data protection.We make it work.

External data protection officers, consulting and training. From Hanover and Vienna, across Europe.

We advise on data processing agreements

SieGegenseite

What brings you here?

High-level data protection advice

The standard is the law, the work is the implementation. It requires that the legal position, the risk assessment, the measure and the technical execution are brought together.

  • Out of the Institute for Legal Informatics

    lexICT is a spin-off of the Institute for Legal Informatics at Leibniz University Hanover, with more than 500 academic publications. Complex facts and unsettled legal positions are our speciality.

  • Other fields of law through the firm

    Where a question goes beyond data protection law, the affiliated firm lexICT legal takes over. It advises in every field of law relevant to the implementation of an IT project.

  • With a nerd factor

    Our lawyers have a level of technical understanding that allows them to follow and assess technical facts. Correctly established facts are in turn the basis of a sound legal assessment.

About us

We strike the right chord for you

Our method rests on the triad of pragmatism, individuality and legal certainty.

News

5 August 2026Data protectionDatentransfers in die USA unter Druck – EDSA fordert Überprüfung des Data Privacy FrameworkAfter the Supreme Court ruling on the removal of FTC members, one of the assumptions underpinning the adequacy decision no longer applies. At the end of July 2026 the European Data Protection Board asked the Commission to review it, without calling for a suspension. The Data Privacy Framework continues to apply, but it does not serve as the sole and permanently secured basis. Read in German30 June 2026Data protectionBerliner Datenschutzbeauftragte zu Kontrollpflichten des Verantwortlichen bzgl. seiner AuftragsverarbeiterThe Berlin authority reprimanded the Berlin public transport operator for failing to check deletion at a service provider and for reporting an incident late. A data processing agreement alone is therefore not enough, and the Higher Regional Court of Dresden had held the same in 2024. The higher the risk, the tighter the checks, with confirmation of deletion, spot checks and agreed reporting channels. Read in German23 June 2026Data protectionDigital Omnibus und § 25 TDDDG: Die Auswirkungen auf ReichweitenmessungThe Commission's proposal moves the rules on access to terminal equipment out of the ePrivacy regime and into the GDPR. A new Art. 88a is intended to allow aggregated audience measurement for a provider's own purposes without consent. For personalised advertising and for tracking across several websites nothing changes. Read in German
All articles

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.