Practice areas
/

Data Protection Law (GDPR)

Implementing data protection reliably and anchoring it in day-to-day operations – we tell you frankly how we assess your matter and give you an estimate of the costs.

Data protection is not a paper exercise. We build structures that hold up in daily practice – and stand up to scrutiny.

Data is a core asset of any business. We support the implementation of the General Data Protection Regulation and the Austrian Data Protection Act, review existing processes and train teams. The result is legal certainty in handling sensitive data – with clear, practical solutions rather than a folder nobody reads.

Our services in data protection law

  • Assessment and records of processing: mapping actual data flows, records under Article 30 DSGVO, legal bases for each processing activity.
  • Agreements: processor agreements under Article 28, joint controllership arrangements, standard contractual clauses for third-country transfers.
  • Information duties: privacy notices for websites and job applications, notices for customers, employees and video surveillance.
  • Data subject rights: access, erasure, rectification, objection, portability – processes that keep the deadlines.
  • Data protection impact assessments: assessing whether one is required and carrying it out for high-risk processing.
  • Data breaches: incident response plan, assessment of the notification duty, notification to the authority and communication to those affected.
  • Employee data protection: time recording, access controls, company phones and email use, works agreements.
  • Proceedings: representation before the data protection authority, appeals to the Federal Administrative Court, defence against damages claims.

Beyond the GDPR: the new EU digital acts

The legal framework is growing beyond the GDPR: the AI Act already prohibits certain practices and obliges companies to ensure AI literacy among their staff, the Data Act has governed access to data from connected devices and eased switching between cloud providers since September 2025, and the NIS 2 Directive brings binding cybersecurity duties to many medium-sized companies for the first time. We determine which of these frameworks actually apply to your business – usually fewer than feared, but rarely none.

The most common gaps in practice

In our experience the problem is rarely goodwill but three specific points. The record of processing exists but does not reflect actual workflows. Processor agreements are in place with the large providers but not with the payroll bureau, the IT support contractor or the on-site document destruction service. And there is no practised procedure for the moment it matters – neither for an access request nor for a data breach with its 72-hour deadline. That is exactly where we start.

Data protection and professional secrecy

In some sectors data protection overlaps with special duties of confidentiality – for doctors, tax advisers, banks and insurers as well as within the legal profession itself. GDPR compliance alone is then not enough; professional rules sometimes go further and limit duties of disclosure and production. We know this tension from our own practice and take it into account in the arrangements we design.

Proceedings before the data protection authority

Complaints by individuals lead to formal proceedings before the Austrian data protection authority in Vienna; its decisions can be challenged before the Federal Administrative Court. Alongside this, civil claims for damages are increasing, including for non-material harm. We represent companies in both tracks and advise when cooperation and remedial action are the better route than a dispute.

Half a day of assessment saves months

The starting point is not a full audit but an honest overview: which data do you actually process, with which providers, on what basis? What genuinely needs doing follows from that – usually less than feared. Arrange an appointment.

/

Frequently asked questions

Does my company need a data protection officer?

Does my company need a data protection officer?

Appointment is mandatory for public authorities, where extensive regular and systematic monitoring of individuals is a core activity, and where special categories of data such as health data are processed on a large scale. Many medium-sized businesses are therefore not obliged to appoint one; a voluntary appointment can still make sense but then triggers the same statutory requirements. We assess the thresholds against your actual processing activities.

What must I do after a data breach?

What must I do after a data breach?

A personal data breach must be reported to the data protection authority within 72 hours of becoming aware of it, provided it poses a risk to the individuals concerned. Where the risk is high, those individuals must be informed as well. Independently of that, every incident must be documented internally – including those that need not be reported. The 72 hours pass quickly; a prepared response plan is decisive.

What is a processor agreement and when do I need one?

What is a processor agreement and when do I need one?

Whenever a service provider processes personal data on your behalf – payroll, IT support, cloud storage, newsletter dispatch, document destruction. The agreement under Article 28 DSGVO governs subject matter, duration, instructions, sub-processors, technical measures and deletion. Without one, both sides are in breach – and the controller remains responsible towards the individuals concerned.

May I transfer data to the United States?

May I transfer data to the United States?

Since the 2023 adequacy decision on the EU-US Data Privacy Framework, transfers to recipients certified under it are permitted without additional safeguards. Transfers to non-certified recipients still require standard contractual clauses together with a case-by-case assessment. Because such decisions can be challenged, we recommend documenting the legal basis for each provider and monitoring developments.

How high are the penalties for breaches?

How high are the penalties for breaches?

The GDPR provides for fines of up to EUR 20 million or four per cent of worldwide annual turnover, whichever is higher. In practice the Austrian data protection authority imposes fines considerably more cautiously and gives weight to cooperation and remedial measures. In addition, affected individuals have claims for damages, including for non-material harm.

What does my company need to consider when using AI tools?

What does my company need to consider when using AI tools?

Two things. Under data protection law, the familiar principles apply: legal basis, information duties, a processing agreement with the provider, and no entry of personal or confidential data into services whose processing you do not control. Added to this is the EU AI Act, which becomes applicable in stages: prohibited practices and the duty to ensure AI literacy among staff already apply, the obligations for high-risk systems follow. For most businesses this means in practice: an internal AI policy, training, and an approved list of permitted tools – manageable, if approached in a structured way.

How must our company respond to an access request?

How must our company respond to an access request?

Data subjects are entitled to information about the data processed about them, including purposes, recipients, origin and the intended retention period, as well as a copy. The response must be given without undue delay, at the latest within one month; in complex cases an extension of a further two months is permitted if you give reasoned notice of it. Third-party rights and trade secrets justify redactions, but not a blanket refusal. An established procedure with clear responsibility and a deadline calendar avoids most complaints here.

Last reviewed August 2026

This overview is general in nature and does not replace advice on an individual case. We research carefully; even so, errors cannot be ruled out and the law keeps changing. Binding information is given in a personal consultation.

Questions about data protection law (gdpr)?

Tell us about your case – we will give you a candid assessment and a clear picture of the cost.

+43 662 26033