Data protection is not a paper exercise. We build structures that hold up in daily practice – and stand up to scrutiny.
Data is a core asset of any business. We support the implementation of the General Data Protection Regulation and the Austrian Data Protection Act, review existing processes and train teams. The result is legal certainty in handling sensitive data – with clear, practical solutions rather than a folder nobody reads.
Our services in data protection law
- Assessment and records of processing: mapping actual data flows, records under Article 30 DSGVO, legal bases for each processing activity.
- Agreements: processor agreements under Article 28, joint controllership arrangements, standard contractual clauses for third-country transfers.
- Information duties: privacy notices for websites and job applications, notices for customers, employees and video surveillance.
- Data subject rights: access, erasure, rectification, objection, portability – processes that keep the deadlines.
- Data protection impact assessments: assessing whether one is required and carrying it out for high-risk processing.
- Data breaches: incident response plan, assessment of the notification duty, notification to the authority and communication to those affected.
- Employee data protection: time recording, access controls, company phones and email use, works agreements.
- Proceedings: representation before the data protection authority, appeals to the Federal Administrative Court, defence against damages claims.
Beyond the GDPR: the new EU digital acts
The legal framework is growing beyond the GDPR: the AI Act already prohibits certain practices and obliges companies to ensure AI literacy among their staff, the Data Act has governed access to data from connected devices and eased switching between cloud providers since September 2025, and the NIS 2 Directive brings binding cybersecurity duties to many medium-sized companies for the first time. We determine which of these frameworks actually apply to your business – usually fewer than feared, but rarely none.
The most common gaps in practice
In our experience the problem is rarely goodwill but three specific points. The record of processing exists but does not reflect actual workflows. Processor agreements are in place with the large providers but not with the payroll bureau, the IT support contractor or the on-site document destruction service. And there is no practised procedure for the moment it matters – neither for an access request nor for a data breach with its 72-hour deadline. That is exactly where we start.
Data protection and professional secrecy
In some sectors data protection overlaps with special duties of confidentiality – for doctors, tax advisers, banks and insurers as well as within the legal profession itself. GDPR compliance alone is then not enough; professional rules sometimes go further and limit duties of disclosure and production. We know this tension from our own practice and take it into account in the arrangements we design.
Proceedings before the data protection authority
Complaints by individuals lead to formal proceedings before the Austrian data protection authority in Vienna; its decisions can be challenged before the Federal Administrative Court. Alongside this, civil claims for damages are increasing, including for non-material harm. We represent companies in both tracks and advise when cooperation and remedial action are the better route than a dispute.
Half a day of assessment saves months
The starting point is not a full audit but an honest overview: which data do you actually process, with which providers, on what basis? What genuinely needs doing follows from that – usually less than feared. Arrange an appointment.