FAQ
Answers to the most common GDPR and data protection questions.
These are the questions we hear most often. The answers are general information only — for advice specific to your situation, contact us directly.
Basics
- When does GDPR apply to my company?
- GDPR applies to every organization that processes personal data of people in the EU — regardless of company size. There is no exemption for small businesses or sole proprietors.
- What is personal data?
- Personal data is any information relating to an identified or identifiable natural person — name, email address, phone number, IP address, location data, customer number, and much more.
- What are the penalties for GDPR violations?
- Fines of up to €20 million or 4% of global annual turnover (whichever is higher). In practice, fines for SMEs are usually in the low-to-mid five-figure range. Reputational damage and compensation claims from affected individuals may also follow.
Data Protection Officer
- When do I need a Data Protection Officer?
- In Germany, appointing a DPO is mandatory if at least 20 people are regularly involved in automated processing of personal data (§ 38 BDSG). Regardless of that threshold, a DPO is also required when processing special categories of data (e.g. health data), when data transfer is a core business activity, or when extensive profiling takes place.
- Can the DPO be internal, or does it have to be external?
- Both are possible. An internal DPO must be professionally qualified and independent of instructions — which is often difficult to achieve in small companies. An external DPO brings expertise, is independent by nature, and is liable for their advisory services.
- What does an external Data Protection Officer cost?
- For a small company with manageable processing activities, costs typically start at €100–300 per month. More complex structures (many processing activities, sensitive data, multiple locations) cost more accordingly. We will give you a concrete price during the free initial consultation.
Documentation
- What is the Records of Processing Activities, and do I need one?
- The Records of Processing Activities (RoPA) under Art. 30 GDPR is mandatory for all companies with 250 or more employees — and for smaller companies where processing is not merely occasional or poses a risk to individuals. In practice, almost every company needs one.
- How often does data protection documentation need to be updated?
- Whenever something changes: new software, new processes, new service providers, changed retention periods. A full review should take place at least once a year.
- Do I need a DPA for every service provider?
- Yes, for every service provider that processes personal data on your behalf. This includes tax advisors (who run payroll), cloud providers, email services, HR software providers, and many more. Not included: service providers who act under their own responsibility (e.g. lawyers, independent transport companies).
Website & Online
- What must be included in the privacy policy?
- All processing activities on your website: hosting, contact form, embedded videos, analytics tools, social media plugins, newsletter, shop functions, booking systems. Also: details of the controller, legal bases, retention periods, data subjects' rights, and the right to lodge a complaint.
- Do I need a cookie banner?
- For cookies and tracking technologies that are not technically necessary (e.g. Google Analytics, Facebook Pixel), you need prior consent. Technically necessary cookies (session cookie, shopping cart) do not require consent but must still be mentioned in the privacy policy.
- Is Google Analytics allowed under GDPR?
- Google Analytics (GA4) can generally be used with the right measures in place: correct configuration (no full IP addresses, server-side tracking), a DPA with Google, and prior consent via a cookie consent tool. Some European supervisory authorities have objected to earlier versions — the discussion continues to evolve.
Employees
- Am I allowed to read my employees' emails?
- Generally no, if private use is permitted. Where use is strictly business-only, it is possible but subject to strict conditions (necessity, proportionality, informing employees in advance). A clear IT usage policy is essential here.
- Are employees allowed to use company devices privately?
- That is your decision as the employer. If you allow it, data protection consequences follow (access to private data, BYOD issues). If you prohibit it, you must communicate that clearly and put an IT usage policy in place.
- How long can I keep applicant data?
- After a rejection, applicant data may generally be kept for up to 6 months — to defend against potential discrimination claims (under German law, the AGG). After that, it must be deleted unless the applicant has consented to longer retention.
Have a question that is not answered here?
We are happy to answer specific questions about your organization — free and without obligation.
Ask your question