Skip to content
How we help
  • Digital business models

    We support companies and their digitalisation plans from the initial concept right through to go-live, drawing on our legal expertise.

    In the case of critical business processes, it may be necessary to assess compliance with data protection law in an expert opinion. Our reports always conclude with a clear finding and practical recommendations for action. Where necessary, we also assist with the preparation of data protection impact assessments.

  • Data protection in transactions

    Whether it is an asset deal or a share deal, we advise companies on the legally compliant transfer of customer data in connection with corporate transactions. Even during due diligence, the question of whether a potential acquirer is permitted to access personal data regularly arises. We also advise insolvency practitioners on the realisation of assets containing personal data.

  • Consent forms and privacy notices

    We draft all the necessary legal documents: privacy notices for websites and apps, advertising consents, declarations of consent and social media guidelines. This also includes the specific wording of those rather tedious cookie banners and the integration of consent management tools.

  • Data protection projects

    As part of the implementation of the GDPR, we have supported data protection projects in many organisations, particularly larger ones. We can help ensure that your organisation, or specific departments within it, are GDPR-compliant. This now usually involves a re-evaluation of the record of processing activities or of existing data protection management systems.

  • AV contracts and joint control agreements

    When working with service providers and cooperation partners, the question of the legal basis under data protection law always arises. We assess the specific scenario from a data protection perspective (Article 28 of the GDPR, Article 26 of the GDPR or controller-to-controller) and draft the necessary legal documents.

  • Investigation of suspected breaches under Articles 33 and 34 of the GDPR

    Over the past two years, we have assessed more than 2,000 cases of potential data breaches to determine whether the incident needed to be reported to the relevant data protection authority. In many cases, it turns out that a report is not required, at least because there is unlikely to be any risk to the data subjects. We will usually provide you with a report on the incident on the same day, along with a clear recommendation regarding the reporting obligation and guidance on any immediate measures required by law.

  • Employee data protection

    We advise companies on all legal issues relating to the modern workplace. Our HR-IT team supports you with all matters concerning employee data protection. From the digitisation of the recruitment process and digital personnel files to working from home and remote working, right through to the use of digital management and monitoring measures – we ensure that the digitisation of your HR department and people management is carried out in full compliance with data protection and employment law!

  • Disputes with data protection authorities

    We have been representing clients in proceedings against German data protection authorities for some time, not just since the GDPR came into force. However, the number and significance of such proceedings have increased significantly in recent years. Our data protection litigation team handles many high-profile cases on behalf of companies against data protection authorities. Whilst some cases involve potentially substantial GDPR fines, others concern (alleged) minor issues that need to be resolved.

  • Transfer of data to third countries

    The adoption of the new Standard Contractual Clauses (SCCs) means that action is required, particularly for e-commerce operators. We would be happy to advise you on this and can review any standard contractual clauses you have been provided with, or draft templates for your standard contractual clauses (including provisions of the General Terms and Conditions of Contract). We support you in (re)negotiating, updating and replacing existing contractual relationships with standard contractual clauses, as well as in implementing the ‘third-country transfer / Schrems II’ project. Furthermore, we can assist you with carrying out the TIA or providing relevant templates, as well as with responding to questionnaires, drafting FAQs and guidelines, or delivering training for your sales, procurement or legal departments. Further information on the new standard data protection clauses can be found in our article here. You can also listen in to our webinar on this topic (registration required; providing real data is optional).

  • Data security: cyber attack or data breach?

    In the event of a cyber attack, a ransomware incident, a data breach or a suspected data protection breach, swift, coordinated and legally sound decisions are required. Companies must determine within a short space of time whether there is a reporting obligation, which authorities need to be informed, whether affected individuals must be notified, and how internal and external communication can be carried out in a legally compliant manner.

    Through our cyber emergency contact service, companies can gain rapid access to an initial legal assessment in the event of cyber attacks, data breaches, IT security incidents and questions regarding cyber incident response. HÄRTING Switzerland provides support in assessing reporting obligations under data protection law, in communicating with the authorities, in documenting the incident, and in coordinating with IT forensics experts, insurers and communications officers. We offer this support in Germany and Switzerland, as well as globally.

  • Data Protection Officer…

    …we are not that ourselves. We do not offer the services of an external data protection officer, as we are prevented from doing so by professional regulations. As solicitors, we cannot simultaneously advise you on data protection law and perform the duties of a supervisory data protection officer. However, we work with specialist data protection officers whose services we have every confidence in. Please do feel free to speak to us about this.

Ihr Ansprechpartner
Data protection law
Knowledge
More about us
Law firm
Compliance

The GDPR stipulates serious fines for non-compliance with data protection regulations. We provide support in the establishment of a data protection structure and the many data protection issues that arise in practice.

Learn more
Law firm
Employee data protection

We advise companies on all legal issues relating to contemporary working life. From the digitalisation of the application procedure and the maintenance of a digital personnel file to home office and mobile working to the use of digital management and control measures - we will put the digitalisation of your personnel department and employee management on a secure footing in terms of data protection and employment law.

Learn more