Data protection law firm Hamburg · GDPR advice for businesses

Data protection, reviewed by lawyers.

We advise businesses on data protection law: reviewing existing processing operations, supporting new projects and dealing with the supervisory authorities. Lawyers at the law firm cogito.legal in Hamburg, since 2017.

About us

We support you in achieving data protection compliance

cogito.legal Rechtsanwälte — data protection law firm

The data protection law firm cogito.legal in Hamburg is a commercial practice specialising in particular in comprehensive advice on data protection. We provide legal advice tailored to your organisation. Our expertise extends in particular to data protection, IT, media and copyright law.

At every level of advice, our lawyers and legal staff bring many years of experience, both as external consultants and in-house. We have TÜV-certified data protection officers and data protection auditors available for external appointments and for training.

Services in data protection law

Examples from our advisory practice

Data protection audit

We record which personal data are processed in your organisation and measure that inventory against the requirements of the GDPR — department by department, system by system.

  • Record of processing activities
  • Gap report with prioritisation
  • Remediation plan

Data protection impact assessment

Where processing is likely to result in a high risk, Article 35 GDPR requires an impact assessment. We carry it out and document it so that it withstands scrutiny.

  • Threshold analysis
  • Risk assessment and mitigating measures
  • Prior consultation with the supervisory authority

Data processing agreements

We review and draft the agreements with your service providers — from cloud platforms and payroll bureaus through to document destruction.

  • Review of existing agreements
  • Templates for recurring cases
  • Negotiation with providers

International data transfers

We examine on what basis your data leave the territory of the European Union, and we close the gaps.

  • Transfer impact assessment
  • Standard contractual clauses
  • Alternatives to third-country services

AI compliance under the EU AI Act

We classify your AI systems into the risk categories of the AI Act and align its requirements with those of the GDPR. What also matters is whether you provide a system or deploy it.

  • Classification of the systems in use
  • Obligations by risk category
  • Usage policies and works agreements

Personal data breaches and notification to the supervisory authority

The deadline is 72 hours. We assess the incident, draft the notification to the supervisory authority and take over the subsequent correspondence.

  • Initial assessment of the notification duty
  • Notification under Article 33 GDPR
  • Communication to the data subjects

Administrative fine proceedings and dealings with authorities

If a supervisory authority opens proceedings, we represent you — in writing, at the hearing and before the courts.

  • Access to the file and written submissions
  • Representation in the hearing procedure
  • Appeals

Training and webinars

We train your staff on the work they actually do, not on the wording of the statute.

  • On site, webinar or recording
  • Separately for HR, sales and IT
  • Evidence for your documentation

Whistleblower reporting channel

We operate the internal reporting channel under the German Whistleblower Protection Act (HinSchG) on your behalf — as an independent body outside your organisation.

  • Receipt of reports and observance of deadlines
  • Confidential handling
  • Legal professional privilege

The “Datenschutz geprüft” certification mark

Once the review is complete, we issue a certificate of examination. The seal displays it on your website, together with the scope of the review and the period of validity.

  • Review of website and contracts
  • Certificate with a reference number
  • Annual re-examination

Sectors

  • Healthcare
  • Energy
  • Public sector & authorities
  • Artificial intelligence
  • Retail & eCommerce
  • Industry & manufacturing
  • Financial services
  • Education & research
  • Housing sector

Our track record

Our experience — selected examples
  • Supporting the legal departments of international media groups on data protection matters.
  • Supporting the legal department of a leading German energy supplier in implementing the GDPR.
  • Advising the legal department of a cable network operator on data protection across a wide range of projects.
  • Advising national and international software and media companies on data protection.
  • Conducting data protection audits and inventories.
  • Specialist presentations, training sessions, webinars and workshops for companies and associations.
  • Data protection due diligence in M&A processes, from assessing legacy issues through to integration after closing.
  • Supporting certification and attestation procedures, from preliminary review to sign-off by the certification body.
  • Advising companies in the health and healthcare sector on implementing the GDPR.
  • Legal review of a wide range of projects and business models from a data protection perspective.
  • Advising companies in the hospitality and hotel sector in the field of data protection.
  • Advising IT companies and cyber security providers in the field of data protection.
  • Advising data analytics companies on data protection.
  • Drafting and reviewing contracts and contract templates in the field of data protection.
  • Advising on the lawful implementation of AI systems, from risk classification through to the works agreement.
  • Preparing companies for customer and group audits in the field of data protection.

Your contacts

We value a personal and trusted working relationship

Behind every mandate stands the firm's data protection team — lawyers and legal staff with many years of experience, both as external consultants and in-house. Your contacts for data protection at cogito.legal are:

Yannik Wiehl, attorney-at-law and certified data protection officer, cogito.legal Hamburg
Malte Rheingans, attorney-at-law and certified data protection auditor, cogito.legal Hamburg
Member of the Hamburg Bar Association (Hamburgischer Anwaltverein e. V.) davit — IT Law Working Group of the German Bar Association German Bar Association certificate of continuing professional development Member of the German Society for Law and Informatics (DGRI e. V.) TÜV Rheinland certified — certified qualification, test mark ID 0217466718 Member of the German Association of Data Protection Officers (BvD e. V.)

How we work

Consistent points of contact

You are looked after throughout by the lawyers who know your organisation and its processing operations. Changing responsibilities and repeated briefing do not arise.

Advice from qualified lawyers

Experienced lawyers and certified specialist lawyers are at your side — in project implementation, in contract management and in all other matters of data protection.

At the interface with IT

Together with our partner companies we have worked at the interface with IT for years and know the technology behind the processing operations that have to be assessed in law. That shortens the coordination with your IT.

Representation in court where required

We represent you before the supervisory authorities and, where necessary, before the courts — in administrative fine proceedings as well as in civil disputes over access and damages.

Questions from practice

Questions businesses ask us

Which data protection risks does due diligence uncover?

Before and during M&A processes we examine the target company's data holdings for legacy issues: missing legal bases, ineffective processing agreements, unresolved third-country transfers. We assess the exposure to administrative fines, draft warranties and indemnities and support the integration after closing.

How do we prepare a certification or attestation?

We examine in advance whether your documentation and your processes will withstand the criteria applied by the certification body, close the gaps and support the procedure through to sign-off. The same applies to customer and group audits in which your level of data protection has to be demonstrated — from the questionnaire to the on-site visit.

How can AI be implemented in compliance with the law?

The EU AI Act and the GDPR interlock. We establish the legal basis for training and input data, classify the system into its risk category, examine the obligations of provider and deployer and draft usage policies and works agreements that make deployment within the organisation sustainable. Where a system is procured, the provider's documentation is reviewed as well.

The certification mark

Evidence that sits on the client's own website

The seal states what was reviewed, for whom, how long the review remains valid and the reference under which it is recorded. It claims no accreditation; it evidences a review carried out by lawyers.

clientname.com

Placement in the footer of the client's website, from 133 px wide

Arrange an initial
consultation

Tell us what the matter concerns and when it suits you. We will come back to you with a confirmation or an alternative proposal.

+49 40 232 053 000
I am not a robot
+49 40 232 053 000 We process your details in accordance with our privacy policy.