Adresse:
Location Werft 16
Werftstraße 16
40549 Düsseldorf
Kontakt:
Tel: +49 211 545532 80
Fax: +49 211 545532 99
Email: anchor@reef-legal.com

Data Protection & Data Security

| Reef Rechtsanwälte Düsseldorf
Data Protection & Data Security

Data Protection Violations Are Not an IT Problem, but a Business Risk

For companies, they mean fines in the millions, personal liability of senior management, reputational damage and follow-on litigation. Reef Rechtsanwälte supports companies in managing data protection risks strategically: preventively through compliance and data protection structures, and reactively through defence in fine and court proceedings.

Data Protection & Data Security

Why Data Protection Compliance Is “Business-Critical” for Companies

With the General Data Protection Regulation (GDPR), the handling of personal data has become a central compliance issue. Violations can be punished with fines of up to EUR 10 million or 2% of total worldwide annual turnover; in particularly serious cases, the framework rises to up to EUR 20 million or 4% of the total worldwide annual turnover of the group to which the company belongs (Art. 83 paras. 4, 5 GDPR; CJEU, judgment of 13.02.2025 – fine ceiling based on total group turnover).

  • At the same time, the CJEU and the BGH have clarified the requirements for fines and damages: the CJEU has confirmed that fines may be imposed against companies as an “economic unit” – without identifying a specific natural person – provided that an intentional or negligent violation exists (inter alia CJEU, judgment of 05.12.2023 – C‑683/21 “NVSC”; CJEU, Case C‑807/21 “Deutsche Wohnen”).
  • At the same time, the CJEU has held that not every GDPR violation automatically triggers a damages claim under Art. 82 GDPR; a specific non-material damage is required.
  • The BGH has continued this line and addressed, inter alia, the question of non-material damage in connection with unlawful advertising, loss of control, and the mere apprehension of data misuse (BGH, judgment of 18.11.2024 – VI ZR 10/24; continued in judgment of 27.01.2025 on unsolicited advertising emails).

For companies, this means: supervisory authorities, competitors and data subjects are increasingly able to challenge data protection violations more effectively – fines, injunctions, damages and reputational harm are mutually reinforcing.

Datenschutz Tastatur | Reef Rechtsanwälte Düsseldorf
Data Protection & Data Security

Data Protection Administrative Offence Proceedings – Strategic Defence Instead of Damage Limitation

2.1. Legal Framework for Administrative Offence Proceedings in Data Protection

The GDPR, together with the Federal Data Protection Act (BDSG), forms the framework for data protection administrative offences:

  • Art. 83 GDPR sets out the general conditions and sanction frameworks for fines.
  • § 41 BDSG declares the Act on Administrative Offences (OWiG) applicable, thereby referencing key procedural provisions, including § 55 OWiG (hearing) and § 77 OWiG (free judicial evaluation of evidence) in court proceedings.

The EU law requirements on fine calculation are further specified by the guidelines of the European Data Protection Board (EDPB). The current Guidelines 04/2022 on the calculation of administrative fines provide supervisory authorities with a five-step scheme: identification of the relevant violation, determination of the turnover threshold, classification of severity, adjustment based on the criteria of Art. 83 para. 2 GDPR, and a final proportionality review.

Key issues currently clarified:

  • Company concept and § 30 OWiG: The question of whether a GDPR fine requires proof of a senior person within the meaning of § 30 OWiG was disputed in German case law (LG Bonn vs. LG Berlin). The CJEU has strengthened supervisory authorities by confirming direct corporate liability in the EU law sense.
  • Fault: At the same time, the CJEU requires intentional or negligent conduct by the controller as a precondition for a fine – strict liability is not permissible.

Reef Rechtsanwälte combines these EU law guardrails with the particularities of German administrative offence procedural law and develops tailored defence strategies on this basis.

Data Protection & Data Security

Typical Course of Data Protection Administrative Offence Proceedings

Course of Data Protection Administrative Offence Proceedings: Preliminary Procedure and Main Proceedings
Data protection administrative offence proceedings regularly follow two phases:

Phase 1: Preliminary Procedure before the Supervisory Authority

1. Starting point

Common triggers are:

  • Complaints from data subjects
  • Notifications of data breaches (Art. 33 GDPR)
  • Reports from competitors or employees
  • Proactive reviews by supervisory authorities

2. Information request and initial statement

The competent state data protection authority contacts the company with an information request. This letter regularly contains detailed questions on technical and organisational measures (TOMs), legal bases, contracts with service providers, and internal processes.

3. Formal hearing pursuant to § 55 OWiG

If there is an initial suspicion, the authority initiates a formal hearing procedure. The company is given the opportunity to submit comments on the allegations. This statement is regularly decisive for the further direction of the proceedings.

4. Decision by the authority

Based on the investigation results and the statement, the authority decides whether the proceedings are

  • discontinued,
  • concluded with a warning,
  • or continued with a fine notice.

At this stage it is of central importance to cooperate sufficiently without unnecessarily disclosing incriminating facts – also against the background of the privilege against self-incrimination and the reporting obligations under Art. 33 GDPR.

Phase 2: Main Proceedings before the Local Court (Amtsgericht)

If a fine notice is issued, the company may lodge an objection. The local court decides on the objection in administrative offence court proceedings. In particular, the following apply:

  • § 77 OWiG (free judicial evaluation of evidence)
  • Full proof by witnesses, documents, expert witnesses
  • Fresh review of the application of the law, the amount of the fine, and proportionality

Courts review, inter alia:

  • whether the authority correctly applied the EDPB guidelines on fine calculation,
  • whether a functioning compliance system existed (this can have a mitigating effect on the fine),
  • whether the company turnover used as a basis meets EU law requirements (group turnover).

Reef Rechtsanwälte takes on court representation, develops evidence strategies, challenges investigative deficiencies and, where appropriate, negotiates consensual solutions.

Mitarbeiter | Reef Rechtsanwälte Düsseldorf
Data Protection & Data Security

Typical GDPR Violations – and How REEF Rechtsanwälte Helps to Avoid Them

1. Missing Legal Basis (Art. 6 GDPR)

The most frequent violation is the processing of personal data without an adequate legal basis:

  • Unlawful use of email addresses for marketing purposes without valid consent
  • Extensive profiling without a legitimate balancing of interests
  • Excessive retention of employee, customer, or applicant data

Case law is increasingly addressing the interplay between GDPR violations and competition law, for example in the context of deficient or non-transparent information obligations and consent mechanisms.

Services of Reef Rechtsanwälte: Analysis of processing operations, legal classification under Art. 6 GDPR, drafting and documentation of consent declarations and balancing-of-interests assessments, defence against injunction and damages claims.

2. Deficient Data Processing Agreements (Art. 28 GDPR)

Whenever an external service provider processes personal data on instructions, a compliant data processing agreement (DPA) is mandatory.

Key points pursuant to Art. 28 GDPR:

  • Subject matter, duration, purpose and nature of processing
  • Categories of data and data subjects
  • Right to give instructions by the controller
  • Confidentiality obligations
  • Detailed description of TOMs (Art. 32 GDPR)
  • Regulation of sub-processors
  • Reporting obligation in the event of data protection incidents (Art. 33 GDPR)
  • Audit and inspection rights

Supervisory authorities scrutinise DPAs very intensively both in proceedings and in routine inspections.

Services of Reef Rechtsanwälte: Drafting and revision of DPAs, review of cloud, SaaS and outsourcing contracts, implementation of practical audit and inspection concepts, support with electronic contract conclusion (Art. 28 para. 9 GDPR).

3. Inadequate Technical and Organisational Measures (TOMs, Art. 32 GDPR)

Art. 32 GDPR requires the controller and processor to implement appropriate TOMs to ensure confidentiality, integrity, availability, and resilience of systems.

Typical deficiencies:

  • Missing encryption and pseudonymisation
  • Inadequate access rights and access management
  • No emergency and backup concept
  • Low level of employee awareness and training

TOMs must be aligned with the state of the art, the risk and the scope of processing – and must be comprehensibly documented.

Services of Reef Rechtsanwälte: Legal assessment of TOMs, support with technical implementation together with IT partners, preparation of TOM annexes (e.g. to DPAs) and documentation materials, strategic advice on risk documentation for authorities and courts.

4. Missing Data Protection Impact Assessment (Art. 35 GDPR)

For processing operations likely to result in high risk (e.g. biometric procedures, profiling, large-scale monitoring), a data protection impact assessment (DPIA) is mandatory.

The DPIA comprises:

  • Description of processing operations and purposes
  • Assessment of necessity and proportionality
  • Risk assessment for the rights and freedoms of data subjects
  • Measures for risk mitigation

Supervisory authorities maintain lists of when a DPIA is mandatory; missing DPIAs are regularly the subject of regulatory criticism.

Services of Reef Rechtsanwälte: Identification of DPIA-obligatory processes, structured conduct and documentation of the DPIA, involvement of the data protection officer, support in dialogue with supervisory authorities.

5. Inadequate Transparency and Information Obligations

Missing or unclear privacy notices, non-transparent cookie banners, and imprecise information on the purposes and recipients of data processing are among the standard findings of supervisory authorities and courts.

Services of Reef Rechtsanwälte: Drafting and revision of privacy policies (web, app, offline), design of legally compliant consent banners, harmonisation of information obligations in sales, HR and IT.

6. Deficient Deletion and Retention Concepts

The GDPR enshrines the data minimisation and storage limitation principles. Companies must determine, document and implement deletion periods; violations have already been the subject of fine proceedings (inter alia in connection with extensive data archives).

Services of Reef Rechtsanwälte: Preparation of deletion and retention concepts, coordination with HGB and tax retention obligations, procedural implementation together with IT and specialist departments.

7. Data Breaches and Reporting Obligations (Art. 33, 34 GDPR)

Reporting obligation for data breaches: 72-hour deadline under Art. 33 GDPR

Art. 33 GDPR requires notification of personal data breaches to the supervisory authority “without undue delay and, where feasible, not later than 72 hours”; Art. 34 GDPR requires communication to data subjects in the event of high risk.

Common errors:

  • Unclear internal reporting channels (“nobody feels responsible”)
  • Missing documentation even where no reporting obligation exists (Art. 33 para. 5 GDPR)
  • Inadequate or late notifications, which increase the risk of a fine

Services of Reef Rechtsanwälte: Establishment of incident response processes, preparation of notification templates, 24/7 emergency advice in the event of data breaches, strategic support with supervisory authorities.

Office | Reef Rechtsanwälte Düsseldorf
Data Protection & Data Security

Proactive Data Protection Audits and Certifications

The 6 core areas of a professional data protection audit

1. Data Protection Audit as a Compliance Building Block

A structured data protection audit is the most effective measure for identifying risks at an early stage and, in the event of a case, being able to demonstrate grounds for fine mitigation.

Reef Rechtsanwälte reviews, inter alia:

  • Legal assessment & records of processing activities (Art. 30 GDPR)
    • Completeness and currency of the records
    • Reconciliation with actual processes
  • Contract drafting (Art. 28 GDPR)
    • DPAs with service providers, in particular cloud and SaaS providers
    • Provisions on sub-processors, TOM annexes, audit rights
  • TOMs pursuant to Art. 32 GDPR
    • Technical security measures, access concepts, backup strategies
  • DPIA (Art. 35 GDPR)
    • Review of DPIA obligation
    • Quality and completeness of existing DPIAs
  • Training and awareness programmes
    • Training status of employees
    • Processes for recurring awareness measures
  • Deletion and retention concepts
    • Workable deletion concepts
    • Coordination with statutory retention periods

2. Certification and Proof of Compliance (Art. 42 GDPR)

The GDPR provides, via Art. 42, a system of certifications that can serve as evidence of an adequate level of data protection. Certifications by bodies such as TÜV or other accredited organisations are increasingly perceived by business partners and authorities as a compliance indicator.

Reef Rechtsanwälte accompanies companies on the path to certification:

  • Preparation of the audit scope
  • Closing of identified gaps
  • Compilation of evidence
  • Support and communication with the certification body
Zertifizierung | Reef Rechtsanwälte Düsseldorf
Data Protection & Data Security

Fine Risk, Damages and Economic Consequences

GDPR Fines: Maximum Sanctions under Art. 83 GDPR

1. Fine Amount under Art. 83 GDPR

The fine practice of supervisory authorities is increasingly guided by the EDPB Guidelines 04/2022 and the decisions of the CJEU and national courts.

Key factors:

  • Nature, gravity and duration of the violation
  • Number of data subjects affected and volume of data
  • Intent or negligence
  • Degree of cooperation with the authority
  • Existence of an effective compliance system

The CJEU requires that fines must be effective, proportionate and dissuasive, while being calibrated to the economic capacity of the corporate group.

2. GDPR Damages (Art. 82 GDPR)

Art. 82 GDPR grants data subjects a claim for material and non-material damages. The CJEU and national courts have clarified that:

  • a violation alone is not sufficient – an individual damage must have occurred,
  • non-material damages may consist inter alia of loss of control, fear, stigmatisation or other impairments,
  • the threshold is not trivial, but no “significance threshold” is required.

Current case law on access rights, profiling, data leaks and direct marketing shows a dynamic field in which the scope of liability and the assessment of non-material damages continue to evolve.

Reef Rechtsanwälte supports companies both in defending against unwarranted mass damages claims and in the strategic resolution of legitimate claims.

| Reef Rechtsanwälte Düsseldorf
Data Protection & Data Security

How REEF Rechtsanwälte Provides Concrete Support

Reef Rechtsanwälte offers, inter alia:

  • Ongoing support in implementing a data protection compliance system
  • Legal assessment of data processing operations, drafting and review of DPAs and privacy notices
  • Conducting data protection audits with a prioritised action plan
  • Advice on data protection impact assessments, DPIA documentation and communication with supervisory authorities
  • Emergency and crisis advice in the event of data breaches, including assessment of notification and communication obligations
  • Defence in administrative offence proceedings and court proceedings before local courts, regional courts and higher courts
  • Support in damages and competition law proceedings with a GDPR dimension

Team Data Protection

  • Urs Breitsprecher

    Attorney-at-Law & Solicitor

    Specialist Lawyer for Tax Law Specialist Lawyer for Commercial & Corporate Law

  • Urs Breitsprecher
  • Henrik Behnke

    Attorney-at-Law

    Specialist Lawyer for Employment Law, Data Protection and IT Law

  • Henrik Behnke
Logo Anfrage starten
Logo
Kanzlei-Assistent
Online